Robuta

https://blog.pypi.org/posts/2024-12-30-quarantine/
Handling project quarantine lifecycle status for suspected malware
python package indexprojectquarantineblog
https://blog.pypi.org/tags/
The official blog of the Python Package Index
python package indextagsblog
https://blog.pypi.org/archive/2024/
The official blog of the Python Package Index
python package indexblog
https://github.com/pypi/warehouse
The Python Package Index. Contribute to pypi/warehouse development by creating an account on GitHub.
python package indexgithubpypiwarehouse
https://blog.pypi.org/
The official blog of the Python Package Index
python package indexblog
https://blog.pypi.org/pages/3/
The official blog of the Python Package Index
python package indexpypiblog
https://blog.pypi.org/posts/2025-08-07-wheel-archive-confusion-attacks/
PyPI will begin warning and will later reject wheels that contain differentiable ZIP features or incorrect RECORD files.
preventingzipparserconfusionattacks
https://blog.pypi.org/pages/2/
The official blog of the Python Package Index
python package indexpypiblog
https://www.pythonpodcast.com/episodepage/pypi-improvements-episode-225
<div class="wp-block-jetpack-markdown"><h3>Summary</h3> <p>PyPI is a core component of the Python ecosystem that most...
python package indexsecurityuxsustainability
https://blog.pypi.org/posts/2025-07-31-incident-report-phishing-attack/
Follow-up on the recent phishing attack targeting PyPI users.
python package indexphishing attackincident reportpypiblog
https://pypi.org/
The Python Package Index (PyPI) is a repository of software for the Python programming language.
python package indexpypi
https://blog.pypi.org/posts/2025-01-30-archival/
Projects on PyPI can now be marked as archived.
python package indexpypisupportsprojectarchival
https://peps.python.org/pep-0541/
This PEP proposes an extension to the Terms of Use 1 of the Package Index 2, clarifying expectations of package owners regarding ownership of a package name on...
package indexpepnameretentionpython
https://blog.pypi.org/posts/2025-12-31-pypi-2025-in-review/
A look back at the major changes to PyPI in 2025 and related statistics.
pypiyearreviewpythonpackage
https://blog.pypi.org/posts/2025-11-14-login-verification/
PyPI has added email verification for TOTP-based logins
newloginverificationtotpbased
https://blog.pypi.org/posts/2025-09-16-github-actions-token-exfiltration/
Incident report of a recent attack campaign targeting GitHub Actions workflows to exfiltrate PyPI tokens, our response, and steps to protect your projects.
github actionstokenexfiltrationcampaignvia
https://blog.pypi.org/posts/2025-11-26-pypi-and-shai-hulud/?utm_campaign=Django%2BNewsletter&utm_medium=web&utm_source=Django_Newsletter_313
Shai-Hulud is a great worm, not yet a snake. Attack on npm ecosystem may have implications for PyPI.
emerging threatspypishaistayingsecure
https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/
Announcing a new, more secure way to publish to PyPI
python package indexintroducingtrustedpublishersblog
https://packaging.python.org/en/latest/guides/index-mirrors-and-caches/
package indexuser guidemirrorscachespython
https://blog.pypi.org/posts/2024-11-14-pypi-now-supports-digital-attestations/
Announcing support for PEP 740 on the Python Package Index
python package indexpypisupportsdigitalattestations
https://fosstodon.org/@pypi
19 Posts, 0 Following, 516 Followers · The Python Package Index (PyPI) is the repository of software for the Python programming language. Pronounced 🥧 🫛 👁️
python package indexpypifosstodonorg
https://blog.pypi.org/posts/2025-09-23-plenty-of-phish-in-the-sea/
A new phishing campaign targeting PyPI users using similar tactics to previous campaigns.
phishing attacksnewdomainslikelycontinue
https://blog.pypi.org/posts/2025-08-14-project-status-markers/
PyPI has implemented PEP 792, and is now serving project status markers in its standard HTML and JSON APIs.
project statuspypiservesmarkersapi
https://blog.pypi.org/posts/2025-07-28-pypi-phishing-attack/
PyPI Users are receiving emails detailing them to log in to a fake PyPI site.
python package indexemail phishingpypiusersattack
https://developer.android.com/reference/packages
package indexapi referenceandroid developers
https://blog.pypi.org/pages/5/
The official blog of the Python Package Index
python package indexpypiblog
https://blog.pypi.org/archive/2026/
The official blog of the Python Package Index
python package indexblog
https://blog.pypi.org/archive/2025/
The official blog of the Python Package Index
python package indexblog
https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/
PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to...
python package indexpreventingdomainresurrectionattacks