home.social

#pypi — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pypi, aggregated by home.social.

fetched live
  1. runs on ~zero AWS cost thanks to @fastlydevs caching 99% of traffic + AWS credits covering the rest. Huge thanks to both! But 2026 broke an 8-year streak: AWS spend is up 69% YoY as agents & CI runs surge.

    @Monorepo, PSF Director of Engineering, on what's changing: pyfound.blogspot.com/2026/08/h

  2. Зачем PyPI закреплять префиксы пакетов за организациями

    Имя пакета в реестре часто оказывается первым сигналом того, что компоненту можно доверять. Разработчик видит название вроде google-cloud-storage , opentelemetry-sdk или apache-airflow-providers-slack раньше, чем открывает исходный код, и ожидает, что знакомый префикс указывает на известный проект. В PyPI это ожидание пока ничем не подтверждено: реестр формально не связывает общее начало имени с его владельцем, поэтому любой свободный вариант может зарегистрировать посторонний пользователь. В конце июня 2026 года в Python-сообществе приняли PEP 752 (мы писали об этом здесь ). Он предлагает закреплять за организацией не отдельные имена, а префикс и все будущие проекты, которые ему соответствуют. Если PyPI реализует этот механизм, то пакет с именем вроде “google-cloud-new-service” сможет опубликовать только та организация, которой принадлежит право на этот префикс или которой разрешили пользоваться этим правом. На первый взгляд, решение очевидное. Однако общий префикс не всегда означает, что все пакеты принадлежат одному издателю. Иногда он обозначает семейство официальных библиотек, а иногда экосистему сторонних дополнений. Меня зовут Артем Максимов, я отвечаю за аналитику продуктов в CodeScoring. Вместе с дата-инженером Артемом Ивановым в этой статье мы разбираемся, какую проблему решает PEP 752, где проходит его граница и что нам показывает база данных CodeScoring.

    habr.com/ru/companies/codescor

    #pypi #python #pep_752 #пакетные_репозитории #безопасность_зависимостей #неймсквоттинг #пространства_имен #цепочка_поставки_по #пакеты_python #open_source

  3. Oof: pepy.tech/search?q=snakemake-e

    That would be > 500 k via #PyPI and > 100 k via #Conda (got the number with `condastats`)

    That, of course, includes all downloads over all versions and including CI usage.

    However, there are ~5,000 downloads per relevant version update for Conda alone. This fills me with pride and gives some ammunition for the "for admins" part of my #Snakemake #HPC tutorial. 😉

    #SLURM

  4. For the sake of an argument, I wanted to retrieve the cumulative download stats of a package on both Conda and PyPI. Both sites do not display this figure (any more?). For Conda, you now have to download `condastats`. At least, it is easy to use.

    For PyPI, there are apparently tools. All of which require getting a token from Google. Seriously?

    Does anyone know a straight forward approach to retrieve PyPI download stats over the lifetime of a package?

    #Conda #pypi

  5. I need to think about how I'm voting the Packaging Council election. So many great nominees, but a lot that I don't recognize because they're dealing with a different part of the ecosystem and not the core where I know the most people. I feel like I want the inaugural council to be core people who were already setting a good direction, but "who I know" also feels like the wrong way to vote. And there's still too many people who I know! 😅 python.org/nominations/electio #Python #PyPI

  6. I've published my todo-linter to PyPI, so you can install it without needing to use pre-commit: pypi.org/project/todo-linter/

    Tomorrow I'll make a Sublime Linter plugin so you can use it from within Sublime Text.

    H/T to @ehmatthes looking at my pytest issue earlier. 🍻

    #python #pypi #linter #CodeQuality

  7. I mentioned last week, while releasing other #Python packages with artistic names (cf. warhol), that I had a long-neglected web-gallery tool called emin...

    Neglected no longer! Now on #pypi emin 0.7.0 (which, tbh, should probably be a 1.x by now): pypi.org/project/emin/

    - super-simple command-line for building web image galleries
    - bitmap and PDF + EPS formats all supported with thumbnails
    - integrated standalone or CDN Lightbox3 display
    - optional zip archive
    - Cheetah3 page templating

  8. has moved the data column to the other side of the page and I'm not prepared for such a huge change in my world! O_o

  9. eeEhello #python users of #pypi, or rather, devs!
    i have a question.
    could someone help me with the captcha?
    i'm trying to upload a project, github.com/averlice/mclient to the directory.
    problem is, when i go to register, it wants a stupid #captcha using #hcaptcha and i need help!
    if anyone could do this, that would be great!

  10. I've finally found a valid use case for #PyPI attestations: the provenance check lets me find wrong case in #GitHub URLs. Like, if the user is "FooBar", GitHub just lets me use "foobar" in the URL and doesn't correct it in any way, but provenance check will fail!

  11. Weeeee !
    I'm done refactoring my plugin for @pelican `HTML to PDF`, which is now clean enough to be publicly released. I used #Forgejo Actions for the fist time on #Codeberg and published it as my very first #PyPI package, thanks to @justin's `autopub`.
    And I finally can showcase it on matt.marcha.pro/ !

    I know that might sound like it's no big deal, but that's quite something for me as I'm not used to publish and share my work. Plus it's a lot of first time !

    Current mood : happy 😃

  12. I don't develop using #npm, and I guess this happens with #pypi and #nuget as well.
    What's the answer? Only install stuff completely manually? Don't store credentials on your dev PCs, only in your e.g. smartphone and enter them manually? Let humans manually verify each upload to package registries? /s

  13. У нас есть для вас пакет! Как LLM придумывают несуществующие зависимости

    Что произойдет, если большая языковая модель (LLM) добавит в код пакет, которого никогда не существовало? Разработчик может принять рекомендацию за корректную, а злоумышленник – опубликовать под придуманным именем вредоносный пакет. Тогда ошибка модели превращается в возможность атаки на цепочку поставки. Перед вами обзор исследования We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs . Авторы проверили 16 моделей, сгенерировали 576 000 образцов кода на Python и JavaScript и изучили, как часто в ответах появляются несуществующие пакеты. Их работу отметили наградой “Distinguished Paper Award” на конференции USENIX Security 2025.

    habr.com/ru/companies/codescor

    #галлюцинации_пакетов #llm #генерация_кода #цепочка_поставки_по #подмена_пакетов #package_confusion #pypi #npm #безопасность_зависимостей #usenix_security

  14. zaojun 1.7.3
    - Moved the project repository from Codeberg to our own Forgejo instance at forge.marvin8.zone, seeking a home that welcomes AI-assisted development.

    #Python #PyPI #CLI #OpenSource

  15. Anthropic says Claude models gained unauthorized access to 3 real-world organizations after a cybersecurity test environment was mistakenly left connected to the internet. In one case, Claude uploaded a malicious package to #PyPI.

    Listen/Read: hackread.com/anthropic-claude-

    #Anthropic #Claude #PyPI #Cybersecurity #InfoSec #AI