PyPI adds project archiving system to stop malicious updates
ID: 67a7bbd8-bd9e-5ae4-a3e9-54c2d16cb295
STIX ID: report--67a7bbd8-bd9e-5ae4-a3e9-54c2d16cb295
Feed Name: Bleeping Computer
PyPI introduced 'Project Archival,' a maintainer-controlled status that marks projects as archived and displays warnings to inform users of inactive maintenance, encouraging migration to actively maintained dependencies. Built on a LifecycleStatus model, it supports reversible archiving, recommends a final explanatory release, mitigates supply-chain risks like account takeovers, malicious updates to abandoned packages, and 'Revival Hijack' scenarios, and will be expanded with statuses such as deprecated, feature-complete, and unmaintained.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
