Sponsor of the Day:
Jerkmate
https://blog.pypi.org/author/woodruffw/
William Woodruff - The Python Package Index Blog
The official blog of the Python Package Index
python package indexwilliamwoodruffblog
https://blog.pypi.org/posts/2024-06-16-prohibiting-msn-emails/
Prohibiting Outlook email domains - The Python Package Index Blog
We have prohibited new registrations of accounts using Outlook email domains.
python package indexoutlook emailprohibitingdomainsblog
https://psf-warehouse-private--28.com.readthedocs.build/author/di/
Dustin Ingram - The Python Package Index Blog
The official blog of the Python Package Index
python package indexdustin ingramblog
https://blog.pypi.org/posts/2023-12-13-2fa-enforcement/
2FA Requirement for PyPI begins 2024-01-01 - The Python Package Index Blog
PyPI will require 2FA for all users on Jan 1, 2024.
python package index2024 012farequirementpypi
https://blog.pypi.org/posts/2026-04-16-pypi-completes-second-audit/
PyPI has completed its second audit - The Python Package Index Blog
We are proud to announce PyPI's second external security audit.
python package indexpypicompletedsecondaudit
https://blog.pypi.org/posts/2024-01-01-2fa-enforced/
2FA Required for PyPI - The Python Package Index Blog
PyPI now requires 2FA for all users.
python package index2farequiredpypiblog
https://blog.pypi.org/author/facutuesca/
Facundo Tuesca - The Python Package Index Blog
The official blog of the Python Package Index
python package indexfacundoblog
https://blog.pypi.org/posts/2025-04-14-incident-report-organization-team-privileges/
Incident Report: Organizations Team privileges - The Python Package Index Blog
We responded to an incident related to privileges persisting via Organization Teams after Members are removed from Organizations.
python package indexincident reportorganizationsteamprivileges
https://blend2d.com/blog/index.html
Index - Blog - Blend2D
2D Vector Graphics Engine
index blogblend2d
https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/
Preventing Domain Resurrection Attacks - The Python Package Index Blog
PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to...
python package indexpreventingdomainresurrectionattacks
https://blog.pypi.org/posts/2026-04-02-incident-report-litellm-telnyx-supply-chain-attack/
Incident Report: LiteLLM/Telnyx supply-chain attacks, with guidance - The Python Package Index Blog
Python Package Index shares insights and provides guidance following LiteLLM/Telnyx supply-chain attacks
supply chain attackspython package indexincident reportlitellmtelnyx
https://blog.pypi.org/archive/2023/
2023 - The Python Package Index Blog
The official blog of the Python Package Index
python package index2023blog
https://blog.pypi.org/posts/2023-11-14-1-pypi-completes-first-security-audit/
PyPI has completed its first security audit - The Python Package Index Blog
We are proud to announce PyPI's first external security audit.
python package indexfirst securitypypicompletedaudit
https://blog.pypi.org/posts/2025-11-14-login-verification/
New Login Verification for TOTP-based Logins - The Python Package Index Blog
PyPI has added email verification for TOTP-based logins
python package indexnewverificationtotpbased
https://blog.pypi.org/posts/2025-08-07-wheel-archive-confusion-attacks/
Preventing ZIP parser confusion attacks on Python package installers - The Python Package Index Blog
PyPI will begin warning and will later reject wheels that contain differentiable ZIP features or incorrect RECORD files.
python packageindex blogpreventingzipparser
https://blog.pypi.org/posts/2025-07-28-pypi-phishing-attack/
PyPI Users Email Phishing Attack - The Python Package Index Blog
PyPI Users are receiving emails detailing them to log in to a fake PyPI site.
python package indexusers emailphishing attackpypiblog
https://blog.pypi.org/posts/2025-09-23-plenty-of-phish-in-the-sea/
Phishing attacks with new domains likely to continue - The Python Package Index Blog
A new phishing campaign targeting PyPI users using similar tactics to previous campaigns.
python package indexphishing attacksnew domainslikelycontinue
https://blog.pypi.org/posts/2023-06-22-malware-detection-project/
Announcing the launch of PyPI Malware Reporting and Response project - The Python Package Index Blog
The official blog of the Python Package Index
python package indexpypi malwareannouncinglaunchreporting
https://www.rapid7.com/blog/post/2025/01/07/rapid7-recognized-with-top-score-of-100-in-2025-corporate-equality-index/
Rapid7 Recognized with Score of 100 in 2025 Corporate Equality Index | Rapid7 Blog
On January 7, the Human Rights Campaign Foundation released their 2025 Corporate Equality Index (CEI), where Rapid7 earned a top score of 100.
corporate equality indexrapid7recognizedscore100
https://blog.pypi.org/posts/2023-05-26-reducing-stored-ip-data/
Reducing Stored IP Data in PyPI - The Python Package Index Blog
PyPI has stopped using IP data when possible, and is continuing to reduce the amount of IP data stored overall.
python package indexip datareducingstoredpypi
https://blog.pypi.org/posts/2025-06-15-prohibiting-inbox-ru-emails/
Prohibiting inbox.ru email domain registrations - The Python Package Index Blog
We have prohibited new registrations of accounts using inbox.ru email domains.
python package indexinbox ruemail domainprohibitingregistrations
https://blog.pypi.org/author/s-mm/
Shamika Monahan - The Python Package Index Blog
The official blog of the Python Package Index
python package indexshamikamonahanblog
https://blog.pypi.org/posts/2023-08-17-github-token-scanning-for-public-repos/
GitHub now scans public issues for PyPI secrets - The Python Package Index Blog
GitHub will now scan public repositories' issues for PyPI API tokens, and will notify repository owners when they are found.
python package indexpublic issuesgithubscanspypi
https://blog.pypi.org/archive/2026/
2026 - The Python Package Index Blog
The official blog of the Python Package Index
python package index2026blog
https://blog.pypi.org/posts/2024-03-06-malware-reporting-evolved/
Malware Reporting Evolved - The Python Package Index Blog
PyPI now has a new, improved way to report malware.
python package indexmalwarereportingevolvedblog
https://blog.pypi.org/tags/
Tags - The Python Package Index Blog
The official blog of the Python Package Index
python package indextagsblog
https://blog.pypi.org/posts/2023-08-04-pypi-hires-safety-engineer/
PyPI hires a Safety & Security Engineer - The Python Package Index Blog
python package indexsafety securitypypihiresengineer
https://blog.pypi.org/posts/2025-01-30-archival/
PyPI Now Supports Project Archival - The Python Package Index Blog
Projects on PyPI can now be marked as archived.
python package indexpypisupportsprojectarchival
https://blog.pypi.org/posts/2024-11-25-aiocpa-attack-analysis/
Malware Package Analysis: aiocpa - The Python Package Index Blog
Analysis of a package uploaded to PyPI with malware, and the steps taken to quarantine and investigate.
index blogmalwarepackageanalysispython
https://blog.pypi.org/posts/2023-06-01-2fa-enforcement-for-upload/
Enforcement of 2FA for upload.pypi.org begins today - The Python Package Index Blog
PyPI now requires all uploads from accounts with 2FA enabled to use an API token or Trusted Publisher configuration.
python package indexbegins todayenforcement2faupload
https://blog.pypi.org/posts/2024-04-03-user-account-access/
Incident Report: Unauthorized User Accounts Access - The Python Package Index Blog
An attack on PyPI user accounts starting on March 31st, 2024.
python package indexincident reportuser accountsunauthorizedaccess
https://bikeindex.org/news
Bike Index Blog
Read Bike Index news. Also, periodically, learn magic spells.
bike indexblog
https://blog.pypi.org/posts/2023-09-18-inbound-malware-reporting/
Inbound Malware Volume Report - The Python Package Index Blog
Analysis of inbound malware reporting volume and response times from PyPI administrators.
python package indexvolume reportinboundmalwareblog
https://blog.pypi.org/posts/2025-09-16-github-actions-token-exfiltration/
Token Exfiltration Campaign via GitHub Actions Workflows - The Python Package Index Blog
Incident report of a recent attack campaign targeting GitHub Actions workflows to exfiltrate PyPI tokens, our response, and steps to protect your projects.
via github actionspython package indextokenexfiltrationcampaign
https://blog.pypi.org/author/dstufft/
Donald Stufft - The Python Package Index Blog
The official blog of the Python Package Index
python package indexdonaldblog
https://blog.pypi.org/posts/2023-12-06-2fa-enforcement-on-testpypi/
2FA Enforcement for TestPyPI - The Python Package Index Blog
PyPI requires 2FA for all management actions on TestPyPI.
python package index2faenforcementtestpypiblog
https://blog.pypi.org/author/ewdurbin/
Ee Durbin - The Python Package Index Blog
The official blog of the Python Package Index
python package indexeedurbinblog
https://blog.pypi.org/posts/2023-05-25-securing-pypi-with-2fa/
Securing PyPI accounts via Two-Factor Authentication - The Python Package Index Blog
PyPI will require all users who maintain projects or organizations to enable one or more forms of two-factor authentication (2FA) by the end of 2023.
two factor authenticationpython package indexaccounts viasecuringpypi
https://blog.pypi.org/posts/2024-07-08-incident-report-leaked-admin-personal-access-token/
Incident Report: Leaked GitHub Personal Access Token - The Python Package Index Blog
We responded to an incident related to a leaked GitHub Personal Access Token for a PyPI administrator.
python package indexincident reportpersonal accessleakedgithub
https://my.blogdrip.com/login/external?language=nl
Index - BLOG DRIP
index blogdrip
https://blog.pypi.org/posts/2024-12-30-quarantine/
Project Quarantine - The Python Package Index Blog
Handling project quarantine lifecycle status for suspected malware
python package indexprojectquarantineblog
https://blog.pypi.org/author/Thespi-Brain/
Maria Ashna - The Python Package Index Blog
The official blog of the Python Package Index
python package indexmariaashnablog
https://blog.pypi.org/author/miketheman/pages/3/
Mike Fiedler - The Python Package Index Blog
The official blog of the Python Package Index
python package indexmikefiedlerblog
https://bikeindex.org/news?locale=nl%2C1713082121
Bike Index Blog
Read Bike Index news. Also, periodically, learn magic spells.
bike indexblog
https://www.indexexchange.com/blog/
Index Exchange Ad Technology and Marketplace Blog
Apr 27, 2026 - Stay up to date with the latest advertising news, trends, and expert opinions with the Index Exchange ad technology and marketplace blog.
index exchangead technologymarketplaceblog