Python Software Foundation security developer-in-residence Seth
Larson has (PyPI) will now reject new files that
are uploaded to releases older than 14 days. The restriction is to
prevent the poisoning of old releases if publishing tokens or
workflows of PyPI projects are compromised.
The after the popular packages " in these projects' usage of the Trivy GitHub Action.
Originally the discussion stalled due to some projects depending on this behavior
to add support for new Python versions to already-published releases. To quantify how
disruptive this change would be to existing workflows, the PyPI database was queried
for had published a 3.14-compatible wheel more than 14 days
after a release was available.
LWN covered the LiteLLM compromise
in March.
SOCIAL SHARE CARD GENERATOR