Quoting Seth Larson
· Source: Simon Willison
The Python Package Index (PyPI) has introduced a new restriction to enhance the security of its releases. As of now, uploads of new files to releases older than 14 days will no longer be permitted. This measure aims to prevent the possibility of older, stable releases being compromised if publication tokens or project workflows on PyPI are compromised. Although no instances of such abuse have been detected to date, the restriction has been implemented as a precautionary step. This decision underscores the importance of supply chain security in software and the need to safeguard projects from potential attacks. In today’s landscape, supply chain security is paramount, and measures like this help prevent potential vulnerabilities that could impact the developer community and end-users.
Read the original article on Simon Willison
This summary is an informational synthesis produced by dataqbs.com. All rights to the original content belong to its author and the cited media outlet. We act solely as curators of technology news and claim no authorship.