home.social

#pypi — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pypi, aggregated by home.social.

  1. It's the first day back to school!! 🎒📖🪀🐛

    2nd seasonal reminder to update your packages 🚲🌻🍂🌳

    • pip list --outdated
    • python -m pip install --upgrade pip

    📝🥞🍁 @pypi.org (pypi.org/project/pip/)

  2. It's the first day back to school!! 🎒📖🪀🐛

    2nd seasonal reminder to update your #Python packages 🚲🌻🍂🌳

    • pip list --outdated
    • python -m pip install --upgrade pip

    📝🥞🍁 @pypi.org (pypi.org/project/pip/)

    #PythonPackageIndex #PyPi

  3. I wrote up a incident report for some install-time issues experienced a few of weeks ago by some users, and what was changed.

    blog.pypi.org/posts/2026-09-08

  4. I wrote up a #PyPI incident report for some install-time issues experienced a few of weeks ago by some users, and what was changed.

    blog.pypi.org/posts/2026-09-08

  5. WTF is pypi.org/project/backports.lzm - seems to be a copy of my archived pypi.org/project/backports.lzma but why... made by pypi.org/user/moinonin/ who seems to have a bunch of possible typo-swatting packages all described as packages for predicting buy and sell signals going back years. Something fishy here! #PyPI #Python

  6. WTF is pypi.org/project/backports.lzm - seems to be a copy of my archived pypi.org/project/backports.lzma but why... made by pypi.org/user/moinonin/ who seems to have a bunch of possible typo-swatting packages all described as packages for predicting buy and sell signals going back years. Something fishy here! #PyPI #Python

  7. WTF is pypi.org/project/backports.lzm - seems to be a copy of my archived pypi.org/project/backports.lzma but why... made by pypi.org/user/moinonin/ who seems to have a bunch of possible typo-swatting packages all described as packages for predicting buy and sell signals going back years. Something fishy here! #PyPI #Python

  8. WTF is pypi.org/project/backports.lzm - seems to be a copy of my archived pypi.org/project/backports.lzma but why... made by pypi.org/user/moinonin/ who seems to have a bunch of possible typo-swatting packages all described as packages for predicting buy and sell signals going back years. Something fishy here! #PyPI #Python

  9. WTF is pypi.org/project/backports.lzm - seems to be a copy of my archived pypi.org/project/backports.lzma but why... made by pypi.org/user/moinonin/ who seems to have a bunch of possible typo-swatting packages all described as packages for predicting buy and sell signals going back years. Something fishy here! #PyPI #Python

  10. PyPI Packages Poisoned in Hades Supply Chain Attack

    Malicious actors have launched a supply-chain attack on the Python Package Index (PyPI), infecting 19 packages with 37 tainted versions that can download and execute a hidden JavaScript payload. This sneaky Hades campaign uses poisoned Python packages to spread its reach, putting developers and users at risk.

    osintsights.com/pypi-packages-

    #SupplyChain #Pypi #Hades #Python #EmergingThreats

  11. Python Package Guru by Fabrizio Damicelli

    pypkg.guru

    search over #PyPI #python #packages
    faster than on pypi.org and interactively

    discover packages based on their capabilities (eg, try out "fast dataframe")

    #neurodon #neuroscience #compsci #scipy