https://blog.pypi.org/posts/2025-08-07-wheel-archive-confusion-attacks/
PyPI will begin warning and will later reject wheels that contain differentiable ZIP features or incorrect RECORD files.
preventingzipparserconfusionattacks
https://www.pythonpodcast.com/episodepage/pypi-improvements-episode-225
<div class="wp-block-jetpack-markdown"><h3>Summary</h3>
<p>PyPI is a core component of the Python ecosystem that most...
python package indexsecurityuxsustainability
https://pypi.org/
The Python Package Index (PyPI) is a repository of software for the Python programming language.
python package indexpypi
https://peps.python.org/pep-0541/
This PEP proposes an extension to the Terms of Use 1 of the Package Index 2, clarifying expectations of package owners regarding ownership of a package name on...
package indexpepnameretentionpython
https://blog.pypi.org/posts/2025-12-31-pypi-2025-in-review/
A look back at the major changes to PyPI in 2025 and related statistics.
pypiyearreviewpythonpackage
https://blog.pypi.org/posts/2025-09-16-github-actions-token-exfiltration/
Incident report of a recent attack campaign targeting GitHub Actions workflows to exfiltrate PyPI tokens, our response, and steps to protect your projects.
github actionstokenexfiltrationcampaignvia
https://blog.pypi.org/posts/2025-11-26-pypi-and-shai-hulud/?utm_campaign=Django%2BNewsletter&utm_medium=web&utm_source=Django_Newsletter_313
Shai-Hulud is a great worm, not yet a snake. Attack on npm ecosystem may have implications for PyPI.
emerging threatspypishaistayingsecure
https://fosstodon.org/@pypi
19 Posts, 0 Following, 516 Followers · The Python Package Index (PyPI) is the repository of software for the Python programming language. Pronounced 🥧 🫛 👁️
python package indexpypifosstodonorg
https://blog.pypi.org/posts/2025-08-14-project-status-markers/
PyPI has implemented PEP 792, and is now serving project status markers in its standard HTML and JSON APIs.
project statuspypiservesmarkersapi
https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/
PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to...
python package indexpreventingdomainresurrectionattacks