#pypi — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pypi, aggregated by home.social.
-
Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.
Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.
https://gitweb.gentoo.org/proj/mgorny-dev-scripts.git/tree/bin/get-latest-upstream-version
-
Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.
Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.
https://gitweb.gentoo.org/proj/mgorny-dev-scripts.git/tree/bin/get-latest-upstream-version
-
Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.
Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.
https://gitweb.gentoo.org/proj/mgorny-dev-scripts.git/tree/bin/get-latest-upstream-version
-
Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.
Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.
https://gitweb.gentoo.org/proj/mgorny-dev-scripts.git/tree/bin/get-latest-upstream-version
-
Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.
Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.
https://gitweb.gentoo.org/proj/mgorny-dev-scripts.git/tree/bin/get-latest-upstream-version
-
I've published my todo-linter to PyPI, so you can install it without needing to use pre-commit: https://pypi.org/project/todo-linter/
Tomorrow I'll make a Sublime Linter plugin so you can use it from within Sublime Text.
H/T to @ehmatthes looking at my pytest issue earlier. 🍻
-
https://winbuzzer.com/2026/06/21/pypi-malware-wave-exposes-weak-ai-scanner-boundary-xcxwbn/
PyPI Malware Wave Exposes Weak AI Malware Scanner Boundary
#AI #PyPI #Malware #AISecurity #Cybersecurity #Javascript #AISafety #AntiMalware #SecurityResearch #CyberThreats
-
This Week in Security: AI Generated Reports, More AI Generated Reports, GitHub Chaos, and More Linux Vulnerabilities
-
Released v1.3.3. of #Yaralyzer, my surprisingly popular tool for visualizing YARA rule matches with colors (a lot of colors).
1. --export-png images lets you export images of the analysis
2. almost all command line options (including multi argument ones like --yara-rules-dir) can be permanently set via environment variables or .yaralyzer file
3. couple of small bug fixes and debugging related command line options
You can try it on the web here: https://yaratoolkit.securitybreak.io/
(I didn't build this website, Thomas Roccia from Microsoft just integrated Yaralyzer into his existing site)- Github: https://github.com/michelcrypt4d4mus/yaralyzer
- Pypi: https://pypi.org/project/yaralyzer/
- on macOS you can also get it with #Homebrew by installing Pdfalyzer: brew install pdfalyzer#ascii #asciiArt #blueteam #cybersecurity #detectionEngineering #DFIR #forensics #FOSS #GPL #hacking #infosec #KaliLinux #maldoc #malware #malwareAnalysis #malwareDetection #openSource #pypi #python #redteam #reverseEngineering #reversing #Threatassessment #threathunting #YARA #YARArule #YARArules
-
#Python : Malicious #PyPI Package called 'sympy-dev' Impersonates #SymPy, Deploys XMRig Miner on Linux Hosts:
#SoftwareSupplyChainSecurity
👇
https://thehackernews.com/2026/01/malicious-pypi-package-impersonates.html -
China-Linked AI Pentest Tool ‘Villager’ Raises Concern After 10K Downloads https://hackread.com/china-ai-pentest-tool-villager-10k-downloads/ #Cybersecurity #CobaltStrike #Cyberspike #Security #AsyncRAT #Straiker #Villager #HSCSEC #China #PyPI #CTF
-
GhostAction Attack Steals 3,325 Secrets from GitHub Projects – Source:hackread.com https://ciso2ciso.com/ghostaction-attack-steals-3325-secrets-from-github-projects-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #CyberAttack #GhostAction #GitGuardian #SupplyChain #DockerHub #FastUUID #Hackread #security #GitHub #Python #CI/CD #PyPI
-
GhostAction Attack Steals 3,325 Secrets from GitHub Projects https://hackread.com/ghostaction-attack-steals-github-projects-secrets/ #Cybersecurity #CyberAttack #GhostAction #GitGuardian #SupplyChain #DockerHub #Security #FastUUID #GitHub #Python #CI/CD #PyPI
-
Just released version 1.16.8 of The Pdfalyzer with a bunch of new and updated #YARA rules to scan #PDF files for malicious content. Links in the quoted toot below.
https://universeodon.com/@cryptadamist/114768170683991686
#ascii #asciiArt #blueteam #cybersecurity #detectionEngineering #DFIR #forensics #FOSS #hacking #homebrew #infosec #KaliLinux #malware #malwareDetection #malwareAnalysis #openSource #pdf #pdfs #pdfalyzer #pypi #python #redteam #reverseEngineering #reversing #Threatassessment #threathunting #yaralyze #yaralyzer #YARA #YARArule #YARArules
-
I have just published shaclgen 3.0.0b1, please test: 💾 https://pypi.org/project/shaclgen/3.0.0b1/
There was no release of #shaclgen since almost 5 years. There were many changes in between including major #rdflib releases. A changelog can be retrieved from the commit history.
-
🐍 Ny supply-chain attack mot programspråket pythons pakethanterare pypi: https://kryptera.se/falsk-python-infrastruktur-levererade-skadlig-kod/
#supplychain #supplychainattack #attack #cyberattack #cyber #hackers #python #pypi #itsäkerhet #cybersäkerhet