Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

PyPI hardens package security with new upload restrictions

Дата публикации: 23-07-2026 09:31:19

The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users and reduce the amount of “cleanup” work associated with project compromises for PyPI admins. This restriction also means that compromises don’t put releases into an indeterminate and confusing state of both “compromised” and “not compromised”, … More →
The post PyPI hardens package security with new upload restrictions appeared first on Help Net Security.


Основное содержимое страницы с новостью.

The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised.

PyPI secures package releases

“This change will protect Python users and reduce the amount of “cleanup” work associated with project compromises for PyPI admins. This restriction also means that compromises don’t put releases into an indeterminate and confusing state of both “compromised” and “not compromised”, where only a subset of files could be poisoned with malware,” Seth Larson, Security Developer-in-Residence at Python Software Foundation, explained.

PyPI has not defined semantics for releases that stop accepting new files and does not provide an API to determine a release’s status, so users should not rely on either. The project plans to define them after standardizing the Upload 2.0 API and Staged Previews under PEP 694, which proposes an extensible API for uploading files to a Python package index.

Community backed the change

The proposal originated during discussions around PEP 740 (Digital Attestations) in January 2024 and resumed after the March 2026 compromise of the LiteLLM and Telnyx packages due to a mutable reference in those projects’ use of the Trivy GitHub Action.

It was initially postponed because some projects uploaded new files to older releases to add support for newer Python versions. PyPI analyzed the practice and found it was rare. Within the top 15,000 packages, only 56 uploaded a Python 3.14-compatible wheel more than 14 days after the original release, indicating the restriction will affect few projects.

PyPI Safety & Security Engineer Mike Fiedler proposed the change, which gained support during discussions at the 2026 Packaging Summit. Participants reached a rough consensus that projects should publish a new package version when adding support for newer Python releases instead of updating an existing release. Larson later implemented the change, and the patch was merged on July 8, 2026.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1GitHub revamps bug bounty program with new VIP tier, payout changes013.3823-07-2026
2Брешь в инфраструктуре Python, позволявшая подменить ссылки на релизы на сайте python.org-2827-06-2026
3Атака клонов: разработчикам Telegram-ботов угрожают троянизированные библиотеки в PyPI-2703-07-2026
4Ransomware in 2026: More groups, more victims, no slowdown012.1424-07-2026
5Google gives developers an AI bug hunter that also writes patches07.8824-07-2026
6security/py-badkeys - 0.0.190112-07-2026
7SUSE Python-lxml Moderate Info Disclosure Update Advisory 2026-2729-10503-07-2026
8Rocky Linux 8 RLSA-2026-32992 Python3.12 Urllib3 Important DoS Issue0501-07-2026
9Innersource security advisories are generally available0508-07-2026
10GitHub adjusts bounty program, adds VIP program to filter AI submissions011.2524-07-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 9.58. Источник: www.helpnetsecurity.com.