logo

PyPI hardens package security with new upload restrictions

ID: 006615c9-4660-5069-924a-50c0067659bd

STIX ID: report--006615c9-4660-5069-924a-50c0067659bd

Feed Name: Help Net Security

Threat Score
30/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Anamarija Pogorelec

...
...

PyPI now rejects uploads of new files to releases older than 14 days to reduce the risk of supply‑chain poisoning after March 2026 compromises of the LiteLLM and Telnyx packages; the change, proposed during Packaging/PEP discussions and merged on July 8, 2026, is intended to limit the impact of compromised publishing tokens or workflows while Upload 2.0 / PEP 694 work proceeds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.