PyPI hardens package security with new upload restrictions
ID: 006615c9-4660-5069-924a-50c0067659bd
STIX ID: report--006615c9-4660-5069-924a-50c0067659bd
Feed Name: Help Net Security
Threat Score
PyPI now rejects uploads of new files to releases older than 14 days to reduce the risk of supply‑chain poisoning after March 2026 compromises of the LiteLLM and Telnyx packages; the change, proposed during Packaging/PEP discussions and merged on July 8, 2026, is intended to limit the impact of compromised publishing tokens or workflows while Upload 2.0 / PEP 694 work proceeds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
