Always verify the domain is pypi.org before logging in.
Read more: blog.pypi.org/posts/2025-0...
@pypi.org.bsky.social
The Python Package Index (PyPI) is the repository of software for the Python programming language. Pronounced π₯§ π« ποΈ
Always verify the domain is pypi.org before logging in.
Read more: blog.pypi.org/posts/2025-0...
Heads Up, #Python Developers!
There is an active phishing attack targeting PyPI users.
β’ Threat: Emails from noreply@pypj.org (with a 'j') link to a fake login page.
β’ Action: Do not click any links. If you already did, change your PyPI password ASAP.
β’ Note: PyPI itself has not been breached.
my colleague @darkamaul.bsky.social has a new blog post on the @trailofbits.bsky.social blog about how we worked with @pypi.org's maintainers to slash test times on PyPI by over 80%:
blog.trailofbits.com/2025/05/01/m...
This wasnβt just blather! bsky.app/profile/pypi...
14.04.2025 22:12 β π 1 π 0 π¬ 0 π 0Incident report! Thanks to our community for reporting, we take security seriously and work to address issues like these to suit.
blog.pypi.org/posts/2025-0...
#PyPI takes security very seriously. If you ever run into malware or a security issue with PyPI itself, make sure to follow our reporting instructions carefully-- and thank you for your vigilance! pypi.org/security/ #python
21.02.2025 15:51 β π 7 π 0 π¬ 0 π 1Keep up to date and subscribe for updates on #PyPI infrastructure status, including requests, edge requests/errors, and traffic via our public dashboard: status.python.org #python
21.02.2025 12:05 β π 2 π 0 π¬ 0 π 0Into stats? Find various first and third party #PyPI statistics on our website: pypi.org/stats/ #python
20.02.2025 19:31 β π 0 π 0 π¬ 0 π 0Want to add your #Python package to #PyPI? Check out our 'Packaging Python Projects' guide:
20.02.2025 15:32 β π 5 π 5 π¬ 1 π 0Learn about how to install and distribute #Python packages with the 'Python Packaging User Guide', a collection of tutorials and references, maintained by the Python Packaging Authority: packaging.python.org/ #pypi
20.02.2025 11:48 β π 2 π 0 π¬ 0 π 0If you want to get in-depth updates on #PyPI news, updates, and incidents, make sure to regularly read up on our blog: blog.pypi.org/ #python
19.02.2025 16:38 β π 7 π 4 π¬ 0 π 0If you've got questions about the basics of #PyPI, your account, integration, project admin, troubleshooting, or what PyPI is all about, make sure to check our FAQ! pypi.org/help/ #python
19.02.2025 13:13 β π 1 π 0 π¬ 0 π 0@python.org raises and distributes funds to improve #Python's packaging ecosystem, including #PyPI. If your company depends on Python or PyPI, send our sponsorship page to those internal decision makers to help sustain Python for all, for free, forever: www.python.org/sponsors/app...
18.02.2025 16:46 β π 5 π 0 π¬ 0 π 0New to #PyPI? It's the home and central repository for #Python packages ππ‘ Use pip install to grab your favorite libraries!
18.02.2025 14:37 β π 1 π 1 π¬ 0 π 1Welcome to the official #PyPI Bluesky account π¦π Your trusted source for discovering, installing, and sharing #Python packages. Follow us for updates, security news, and incident reports!
18.02.2025 11:26 β π 15 π 3 π¬ 0 π 0I just went through and archived every project I'm the sole owner of that hasn't had a release in 4 years (although that date isn't special, it just happens to be the "youngest" release; oldest, latest release was over 14 years ago).
30.01.2025 21:03 β π 10 π 1 π¬ 0 π 0you can now archive projects on @pypi.org!
this work was done by my teammate Facundo @trailofbits.bsky.social and is part of a larger multi-year arc of work dedicated to landing security and usability improvements on PyPI:
blog.trailofbits.com/2025/01/30/p...
PyPI Now Supports Project Archival: blog.pypi.org/posts/2025-0...
30.01.2025 14:46 β π 20 π 7 π¬ 0 π 1I recently wrote about how I added the ability to quarantine projects under investigation on @pypi.org
Read here: blog.pypi.org/posts/2024-1...
#Python #Packaging #OpenSource #Security #PyPI
Last week the Python package "Ultralytics" suffered a supply-chain attack on its build and release process. This is a review of the attack from @pypi.org's perspective.
There's plenty of advice for how Python projects can increase their #security posture:
blog.pypi.org/posts/2024-1...