Python Package Index

@pypi.org

The Python Package Index (PyPI) is the repository of software for the Python programming language. Pronounced 🥧 🫛 👁️

The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised. blog.pypi.org/posts/2026-0... #python #security #supplychain #pypi

Releases now reject new files after 14 days - The Python Package Index Blog

PyPI no longer allows publishing new files to releases older than 14 days.

blog.pypi.org

PSF Security developers have published incident reports on the LiteLLM & Telnyx #supplychain attacks. Read what happened, who's affected, and what developers & maintainers can do to prepare and protect themselves from future incidents. #security #python

Incident Report: LiteLLM/Telnyx supply-chain attacks, with guidance - The Python Package Index Blog

Python Package Index shares insights and provides guidance following LiteLLM/Telnyx supply-chain attacks

blog.pypi.org

Huge thanks to @fastly.com for 10+ years of keeping #PyPI up and running! PyPI serves 800K+ users at ~100K requests/sec. With a small team behind the service, that kind of scale is only possible because of infrastructure partners who invest in the sustainability of the #Python ecosystem.

Fastly@fastly.com · 5mo ago

For 10+ years, Fastly has supported the @python.org in securing & scaling the #Python Package Index (PyPI). Proud to help keep one of the world’s most critical open source ecosystems fast, fresh, & secure. www.fastly.com/customers/psf #OpenSource

Over the past year (and a half!), our inaugural PyPI Support Specialist, Maria Ashna, helped tackle backlogs, improve support processes, and keep #PyPI running smoothly for the #Python community. Read the full reflection on what that work looked like 👇 blog.pypi.org/posts/2026-0...

Dispatch from PyPI Land: A Year (and a Half!) as the Inaugural PyPI Support Specialist - The Python Package Index Blog

A look back on the first year and a half as the inaugural PyPI Support Specialist.

blog.pypi.org

A campaign targeted GitHub Actions to steal PyPI tokens—PyPI wasn’t compromised and no PyPI packages were published by the attackers. Stay safe: review your tokens, rotate any exposed ones, and use short-lived, scoped GitHub Actions tokens. Details:

Token Exfiltration Campaign via GitHub Actions Workflows - The Python Package Index Blog

Incident report of a recent attack campaign targeting GitHub Actions workflows to exfiltrate PyPI tokens, our response, and steps to protect your projects.

blog.pypi.org

The Python Package Index is introducing new restrictions to protect Python package installers and inspectors from ZIP confusion attacks. There is no evidence that this vulnerability has been exploited. Read the blog post for more information:

Preventing ZIP parser confusion attacks on Python package installers - The Python Package Index Blog

PyPI will begin warning and will later reject wheels that contain differentiable ZIP features or incorrect RECORD files.

blog.pypi.org

Heads Up, #Python Developers! There is an active phishing attack targeting PyPI users. • Threat: Emails from noreply@pypj.org (with a 'j') link to a fake login page. • Action: Do not click any links. If you already did, change your PyPI password ASAP. • Note: PyPI itself has not been breached.