home.social

#pypi — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pypi, aggregated by home.social.

  1. Exhibit N: #pypi apparently only now limiting package file uploads to "only" two weeks after the release itself.

  2. Exhibit N: #pypi apparently only now limiting package file uploads to "only" two weeks after the release itself.

  3. If you use the `setup-uv` #GitHub #Action in your workflows, consider upgrading to version 9.0.0 soon.

    This version changes the default behavior to store the downloaded #Python wheels from #PyPI in GHA Cache, shedding load from PyPI, especially relevant for frequent CI/CD runs.

    The maintainers considered this a breaking change, hence the version bump, probably because it flips existing expectations.

    If you expected that the Action was caching downloads before, now it actually does, so it's a logical fix in that regard.
    Read more: github.com/astral-sh/setup-uv/

  4. If you use the `setup-uv` #GitHub #Action in your workflows, consider upgrading to version 9.0.0 soon.

    This version changes the default behavior to store the downloaded #Python wheels from #PyPI in GHA Cache, shedding load from PyPI, especially relevant for frequent CI/CD runs.

    The maintainers considered this a breaking change, hence the version bump, probably because it flips existing expectations.

    If you expected that the Action was caching downloads before, now it actually does, so it's a logical fix in that regard.
    Read more: github.com/astral-sh/setup-uv/

  5. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

  6. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

  7. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

    #python #security #supplychain #pypi

  8. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

    #python #security #supplychain #pypi

  9. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

    #python #security #supplychain #pypi

  10. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

    #python #security #supplychain #pypi

  11. #PyPI now displays the #Codeberg logo on links pointing there! Looks way better than the generic "external link" icon :BlobCatHeart:

  12. #PyPI now displays the #Codeberg logo on links pointing there! Looks way better than the generic "external link" icon :BlobCatHeart:

  13. Just released multipart-2.0.0 to #pypi.

    This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.

    changelog: multipart.readthedocs.io/en/la

    pypi: pypi.org/project/multipart/

    And when I say 'fast' I mean it: defnull.de/2026/python-multipa

    #SansIO

  14. Just released multipart-2.0.0 to #pypi.

    This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.

    changelog: multipart.readthedocs.io/en/la

    pypi: pypi.org/project/multipart/

    And when I say 'fast' I mean it: defnull.de/2026/python-multipa

    #SansIO

  15. Just released multipart-2.0.0 to #pypi.

    This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.

    changelog: multipart.readthedocs.io/en/la

    pypi: pypi.org/project/multipart/

    And when I say 'fast' I mean it: defnull.de/2026/python-multipa

    #SansIO

  16. Just released multipart-2.0.0 to #pypi.

    This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.

    changelog: multipart.readthedocs.io/en/la

    pypi: pypi.org/project/multipart/

    And when I say 'fast' I mean it: defnull.de/2026/python-multipa

    #SansIO

  17. Just released multipart-2.0.0 to #pypi.

    This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.

    changelog: multipart.readthedocs.io/en/la

    pypi: pypi.org/project/multipart/

    And when I say 'fast' I mean it: defnull.de/2026/python-multipa

    #SansIO

  18. Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.

    ep2026.europython.eu/session/a

    #EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security

  19. Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.

    ep2026.europython.eu/session/a

    #EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security

  20. Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.

    ep2026.europython.eu/session/a

    #EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security

  21. Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for around this time last year.

    ep2026.europython.eu/session/a

  22. Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.

    ep2026.europython.eu/session/a

    #EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security

  23. Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader

    Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.

    Pulse ID: 6a5665a177561cba872b779e
    Pulse Link: otx.alienvault.com/pulse/6a566
    Pulse Author: AlienVault
    Created: 2026-07-14 16:36:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #InfoSec #Linux #NPM #Nodejs #OTX #OpenThreatExchange #PyPI #RAT #RCE #Rust #bot #botnet #AlienVault

  24. Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader

    Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.

    Pulse ID: 6a5665a177561cba872b779e
    Pulse Link: otx.alienvault.com/pulse/6a566
    Pulse Author: AlienVault
    Created: 2026-07-14 16:36:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #InfoSec #Linux #NPM #Nodejs #OTX #OpenThreatExchange #PyPI #RAT #RCE #Rust #bot #botnet #AlienVault

  25. Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader

    Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.

    Pulse ID: 6a5665a177561cba872b779e
    Pulse Link: otx.alienvault.com/pulse/6a566
    Pulse Author: AlienVault
    Created: 2026-07-14 16:36:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #InfoSec #Linux #NPM #Nodejs #OTX #OpenThreatExchange #PyPI #RAT #RCE #Rust #bot #botnet #AlienVault

  26. Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader

    Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.

    Pulse ID: 6a5665a177561cba872b779e
    Pulse Link: otx.alienvault.com/pulse/6a566
    Pulse Author: AlienVault
    Created: 2026-07-14 16:36:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #InfoSec #Linux #NPM #Nodejs #OTX #OpenThreatExchange #PyPI #RAT #RCE #Rust #bot #botnet #AlienVault

  27. Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader

    Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.

    Pulse ID: 6a5665a177561cba872b779e
    Pulse Link: otx.alienvault.com/pulse/6a566
    Pulse Author: AlienVault
    Created: 2026-07-14 16:36:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #InfoSec #Linux #NPM #Nodejs #OTX #OpenThreatExchange #PyPI #RAT #RCE #Rust #bot #botnet #AlienVault

  28. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    Pulse ID: 6a546e33879dc2bce62e418f
    Pulse Link: otx.alienvault.com/pulse/6a546
    Pulse Author: Tr1sa111
    Created: 2026-07-13 04:48:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #bot #Tr1sa111

  29. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    Pulse ID: 6a546e33879dc2bce62e418f
    Pulse Link: otx.alienvault.com/pulse/6a546
    Pulse Author: Tr1sa111
    Created: 2026-07-13 04:48:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #bot #Tr1sa111

  30. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    Pulse ID: 6a546e33879dc2bce62e418f
    Pulse Link: otx.alienvault.com/pulse/6a546
    Pulse Author: Tr1sa111
    Created: 2026-07-13 04:48:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #bot #Tr1sa111

  31. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    Pulse ID: 6a546e33879dc2bce62e418f
    Pulse Link: otx.alienvault.com/pulse/6a546
    Pulse Author: Tr1sa111
    Created: 2026-07-13 04:48:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #bot #Tr1sa111

  32. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    Pulse ID: 6a546e33879dc2bce62e418f
    Pulse Link: otx.alienvault.com/pulse/6a546
    Pulse Author: Tr1sa111
    Created: 2026-07-13 04:48:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #bot #Tr1sa111

  33. rainlog 1.1.0

    - New **Comparison** chart mode: press `m` in monthly or yearly grouping to see year-over-year bars side by side.

    #Python #PyPI #Rain #Weather #OpenSource

  34. quicktipp #117: Bootstrapping a portable Python bundle on MS Windows using the `pywinbundle` tool.

    github.com/christian-korneck/p

    A bundle is a bit like a venv, but self-contained and can get moved/renamed to any path or copied to any Windows machine. The bundle will continue to work, even if there is no existing Python installation.

    #python #windows #pip #venv #virtualenv #uv #jupyter #pypi

  35. quicktipp #117: Bootstrapping a portable Python bundle on MS Windows using the `pywinbundle` tool.

    github.com/christian-korneck/p

    A bundle is a bit like a venv, but self-contained and can get moved/renamed to any path or copied to any Windows machine. The bundle will continue to work, even if there is no existing Python installation.

    #python #windows #pip #venv #virtualenv #uv #jupyter #pypi

  36. quicktipp #117: Bootstrapping a portable Python bundle on MS Windows using the `pywinbundle` tool.

    github.com/christian-korneck/p

    A bundle is a bit like a venv, but self-contained and can get moved/renamed to any path or copied to any Windows machine. The bundle will continue to work, even if there is no existing Python installation.

    #python #windows #pip #venv #virtualenv #uv #jupyter #pypi

  37. quicktipp #117: Bootstrapping a portable Python bundle on MS Windows using the `pywinbundle` tool.

    github.com/christian-korneck/p

    A bundle is a bit like a venv, but self-contained and can get moved/renamed to any path or copied to any Windows machine. The bundle will continue to work, even if there is no existing Python installation.

    #python #windows #pip #venv #virtualenv #uv #jupyter #pypi

  38. Один комментарий на Хабре — и ещё один пакет для Django Admin

    Недавно я опубликовал на Хабре статью о небольшом пакете django-scroll-to-top , который добавляет кнопку «Наверх» в проекты на Django. Сам пакет решает довольно локальную задачу, но обсуждение под статьёй оказалось интереснее, чем я ожидал. В комментариях возник вполне закономерный вопрос: насколько вообще подобным интерфейсным дополнениям место в стандартной Django Admin? Ведь каждое установленное приложение добавляет свои пункты в боковое меню, и со временем административная панель действительно может начать выглядеть перегруженной. Один из комментариев заставил меня посмотреть на эту проблему немного под другим углом. В результате вместо долгого спора появился ещё один небольшой open-source-пакет — теперь уже для сворачивания групп приложений в боковой панели Django Admin.

    habr.com/ru/articles/1057784/

    #Django #Django_Admin #Python #open_source #PyPI #UX #cookie #плагины_Django #административная_панель #django_admin_collapse_apps

  39. Один комментарий на Хабре — и ещё один пакет для Django Admin

    Недавно я опубликовал на Хабре статью о небольшом пакете django-scroll-to-top , который добавляет кнопку «Наверх» в проекты на Django. Сам пакет решает довольно локальную задачу, но обсуждение под статьёй оказалось интереснее, чем я ожидал. В комментариях возник вполне закономерный вопрос: насколько вообще подобным интерфейсным дополнениям место в стандартной Django Admin? Ведь каждое установленное приложение добавляет свои пункты в боковое меню, и со временем административная панель действительно может начать выглядеть перегруженной. Один из комментариев заставил меня посмотреть на эту проблему немного под другим углом. В результате вместо долгого спора появился ещё один небольшой open-source-пакет — теперь уже для сворачивания групп приложений в боковой панели Django Admin.

    habr.com/ru/articles/1057784/

    #Django #Django_Admin #Python #open_source #PyPI #UX #cookie #плагины_Django #административная_панель #django_admin_collapse_apps

  40. Один комментарий на Хабре — и ещё один пакет для Django Admin

    Недавно я опубликовал на Хабре статью о небольшом пакете django-scroll-to-top , который добавляет кнопку «Наверх» в проекты на Django. Сам пакет решает довольно локальную задачу, но обсуждение под статьёй оказалось интереснее, чем я ожидал. В комментариях возник вполне закономерный вопрос: насколько вообще подобным интерфейсным дополнениям место в стандартной Django Admin? Ведь каждое установленное приложение добавляет свои пункты в боковое меню, и со временем административная панель действительно может начать выглядеть перегруженной. Один из комментариев заставил меня посмотреть на эту проблему немного под другим углом. В результате вместо долгого спора появился ещё один небольшой open-source-пакет — теперь уже для сворачивания групп приложений в боковой панели Django Admin.

    habr.com/ru/articles/1057784/

    #Django #Django_Admin #Python #open_source #PyPI #UX #cookie #плагины_Django #административная_панель #django_admin_collapse_apps

  41. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    A cluster of npm and PyPI packages typosquatting popular payment applications has been detected by Socket's AI scanner, which automatically blocks malicious packages in your code, as well as preventing them from being published.

    Pulse ID: 6a50a4bc4687b8b6b035b1a5
    Pulse Link: otx.alienvault.com/pulse/6a50a
    Pulse Author: CyberHunter_NL
    Created: 2026-07-10 07:52:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #TypoSquatting #bot #CyberHunter_NL

  42. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    A cluster of npm and PyPI packages typosquatting popular payment applications has been detected by Socket's AI scanner, which automatically blocks malicious packages in your code, as well as preventing them from being published.

    Pulse ID: 6a50a4bc4687b8b6b035b1a5
    Pulse Link: otx.alienvault.com/pulse/6a50a
    Pulse Author: CyberHunter_NL
    Created: 2026-07-10 07:52:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #TypoSquatting #bot #CyberHunter_NL

  43. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    A cluster of npm and PyPI packages typosquatting popular payment applications has been detected by Socket's AI scanner, which automatically blocks malicious packages in your code, as well as preventing them from being published.

    Pulse ID: 6a50a4bc4687b8b6b035b1a5
    Pulse Link: otx.alienvault.com/pulse/6a50a
    Pulse Author: CyberHunter_NL
    Created: 2026-07-10 07:52:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #TypoSquatting #bot #CyberHunter_NL

  44. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    A cluster of npm and PyPI packages typosquatting popular payment applications has been detected by Socket's AI scanner, which automatically blocks malicious packages in your code, as well as preventing them from being published.

    Pulse ID: 6a50a4bc4687b8b6b035b1a5
    Pulse Link: otx.alienvault.com/pulse/6a50a
    Pulse Author: CyberHunter_NL
    Created: 2026-07-10 07:52:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #TypoSquatting #bot #CyberHunter_NL

  45. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    A cluster of npm and PyPI packages typosquatting popular payment applications has been detected by Socket's AI scanner, which automatically blocks malicious packages in your code, as well as preventing them from being published.

    Pulse ID: 6a50a4bc4687b8b6b035b1a5
    Pulse Link: otx.alienvault.com/pulse/6a50a
    Pulse Author: CyberHunter_NL
    Created: 2026-07-10 07:52:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #TypoSquatting #bot #CyberHunter_NL