home.social

#pypi — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pypi, aggregated by home.social.

  1. It's the first day back to school!! 🎒📖🪀🐛

    2nd seasonal reminder to update your packages 🚲🌻🍂🌳

    • pip list --outdated
    • python -m pip install --upgrade pip

    📝🥞🍁 @pypi.org (pypi.org/project/pip/)

  2. It's the first day back to school!! 🎒📖🪀🐛

    2nd seasonal reminder to update your #Python packages 🚲🌻🍂🌳

    • pip list --outdated
    • python -m pip install --upgrade pip

    📝🥞🍁 @pypi.org (pypi.org/project/pip/)

    #PythonPackageIndex #PyPi

  3. I wrote up a incident report for some install-time issues experienced a few of weeks ago by some users, and what was changed.

    blog.pypi.org/posts/2026-09-08

  4. I wrote up a #PyPI incident report for some install-time issues experienced a few of weeks ago by some users, and what was changed.

    blog.pypi.org/posts/2026-09-08

  5. WTF is pypi.org/project/backports.lzm - seems to be a copy of my archived pypi.org/project/backports.lzma but why... made by pypi.org/user/moinonin/ who seems to have a bunch of possible typo-swatting packages all described as packages for predicting buy and sell signals going back years. Something fishy here! #PyPI #Python

  6. WTF is pypi.org/project/backports.lzm - seems to be a copy of my archived pypi.org/project/backports.lzma but why... made by pypi.org/user/moinonin/ who seems to have a bunch of possible typo-swatting packages all described as packages for predicting buy and sell signals going back years. Something fishy here! #PyPI #Python

  7. WTF is pypi.org/project/backports.lzm - seems to be a copy of my archived pypi.org/project/backports.lzma but why... made by pypi.org/user/moinonin/ who seems to have a bunch of possible typo-swatting packages all described as packages for predicting buy and sell signals going back years. Something fishy here! #PyPI #Python

  8. WTF is pypi.org/project/backports.lzm - seems to be a copy of my archived pypi.org/project/backports.lzma but why... made by pypi.org/user/moinonin/ who seems to have a bunch of possible typo-swatting packages all described as packages for predicting buy and sell signals going back years. Something fishy here! #PyPI #Python

  9. WTF is pypi.org/project/backports.lzm - seems to be a copy of my archived pypi.org/project/backports.lzma but why... made by pypi.org/user/moinonin/ who seems to have a bunch of possible typo-swatting packages all described as packages for predicting buy and sell signals going back years. Something fishy here! #PyPI #Python

  10. Восемь аниме-плееров рунета изнутри: шифр Цезаря, пустой параметр и домен, который увели

    Я взял за основу популярную опенсорсную библиотеку парсеров аниме-плееров, запустил её — и получил от Kodik 500 Internal Server Error . Не «токен протух», не «IP заблокирован», а именно 500 на каждый запрос. Разбор занял вечер, а причина оказалась в одном символе: библиотека отправляла параметр ref пустым, а сервер требует его заполненным и раскодированным . Дальше выяснилось, что это не единичная поломка, а норма жанра. Один плеер полгода назад переехал на другой формат страницы. Другой отвечает бесконечным редиректом на самого себя. У третьего домен просто увели — сейчас там индонезийский интернет-магазин, а не аниме. Четвёртый прячет ссылки в WebSocket из обфусцированного бандла на 600 КБ, и его я честно не осилил. Под катом — разбор восьми плееров: как каждый отдаёт видео, где именно ломаются существующие парсеры и что из этого следует, если вы пишете что-то похожее. Библиотека получилась побочным продуктом и лежит в открытом доступе.

    habr.com/ru/articles/1079156/

    #python #парсинг #реверсинжиниринг #hls #m3u8 #аниме #pypi #github_actions #websocket

  11. Latest PyPi Compromise

    A supply chain attack targeting the Microsoft DurableTask Python client compromised versions 1.4.1, 1.4.2, and 1.4.3 on PyPi. The threat actor gained access through a compromised GitHub account previously linked to attacks, using stolen credentials to dump GitHub secrets containing PyPi tokens. The evolved payload targets Linux systems, stealing credentials from AWS, Azure, GCP, Kubernetes, Vault, and password managers like Bitwarden and 1Password. It propagates via AWS SSM and Kubernetes lateral movement, limited to 5 targets per infected host. The payload scrapes shell history, bruteforces password managers, and establishes persistence through infection markers. Compromised packages were quarantined following analysis.

    Pulse ID: 6a0ce3b0ad791179648c47b0
    Pulse Link: otx.alienvault.com/pulse/6a0ce
    Pulse Author: AlienVault
    Created: 2026-05-19 22:26:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #BruteForce #CyberSecurity #GitHub #InfoSec #Linux #Microsoft #OTX #OpenThreatExchange #Password #PyPI #Python #RCE #SupplyChain #Word #bot #AlienVault

  12. #PyPI: PyTorch Lightning and Intercom-client Packages Hit in Supply Chain Attacks to Steal Credentials.

    This attack is linked with Mini Shai-Hulud supply chain attack that targeted SAP-related npm packages on Wednesday.

    #SoftwareSupplyChainSecurity
    👇
    thehackernews.com/2026/04/pyto

  13. Important alert for cybersecurity enthusiasts! The Python Package Index (PyPI) has just added Grid-STIX 2.1, an Electrical Grid Cybersecurity Ontology STIX extension for critical infrastructure. While this might seem like a minor update, it highlights the growing concern of cyber threats in our power grids.

    As we rely more heavily on digital systems to manage and monitor our energy infrastructure, the potential consequences of a successful attack become increasingly dire. The addition of Grid-STIX to PyPI underscores the need for robust cybersecurity measures to protect our critical infrastructure.

    What do you think is the most pressing cybersecurity issue facing our modern society? Should we prioritize individual privacy or collective security? Share your thoughts and let's start a conversation! #cybersecurity #gridsecurity #PyPI

    Read more: short.steelefortress.com/94wxo5

    #Security #Privacy #DataPrivacy

  14. #TreeTime #Trees #MindMap #Editor #OpenSource #FreeSoftware

    In reaction to several turns of recent events, TreeTime is starting to move away from #GitHub to #Codeberg: codeberg.org/jkanev/treetime#r

    There will be a transition period in which both repositories will receive updates in parallel.

    The installable packages in #Pypi, the webpage on tree-time.info, and the documentation in #readthedocs will stay unaffected.

  15. From the abstract:

    ›We introduce #AutoCal, a new #InstanceMatcher which does not require #LabelledData and runs out of the box for a wide range of domains without tuning method-specific parameters.

    AutoCal achieves results competitive to recently proposed unsupervised matchers from the field of #MachineLearning.‹

    2/4

    🌺

    🏷️ #InstanceMatching #RecordLinkage #OntologyMatching #ArtificialIntelligence #MatChain #PyPI #WorldAvatar #DigitalTwin #Python #WebSem #LinkedData #KnowledgeGraph