Sign in

Python Package Index

@pypi.org
1.7K followers 0 following 23 posts

The Python Package Index (PyPI) is the repository of software for the Python programming language. Pronounced 🥧 🫛 👁️

PostsRepliesMedia
Reposted by Python Package Index
Mike Fiedler @miketheman.com · 08/09/2026
I wrote up a #PyPI incident report for some install-time issues experienced a few of weeks ago by some users, and what was changed. blog.pypi.org/posts/2026-0...
blog.pypi.org
Incident Report: File Hosting Errors - The Python Package Index Blog
For two weeks in August 2026, some PyPI users hit intermittent 502 and 503 errors downloading files. Here's what was happening, and what we changed.
095
Reposted by Python Package Index
Python Software Foundation @python.org · 19/08/2026
#PyPI runs on ~zero AWS cost thanks to @fastly.com caching 99% of traffic + @awscloud.bsky.social credits covering the rest. Huge thanks to both! But 2026 broke an 8-year streak: AWS spend is up 69% YoY as agents & CI runs surge. Jacob Coffee on what's changing: pyfound.blogspot.com/2026/08/how-...
pyfound.blogspot.com
How AWS Powers PyPI and the PSF
0117
Python Package Index @pypi.org · 22/07/2026
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised. blog.pypi.org/posts/2026-0... #python #security #supplychain #pypi
blog.pypi.org
Releases now reject new files after 14 days - The Python Package Index Blog
PyPI no longer allows publishing new files to releases older than 14 days.
04517
Reposted by Python Package Index
Python Software Foundation @python.org · 25/06/2026
Great coverage from @lwndotnet.bsky.social of the PSF PyPI Safety & Security Engineer @miketheman.com's talk on Trusted Publishing at Open Source Summit. 36% of PyPI uploads now use Trusted Publishing. Is yours one of them? lwn.net/Articles/107... #Python #PyPI #OSSumit #Security
lwn.net
Eliminating long-lived credentials with trusted publishing
Trusted publishing is an authentication mechanism that relies on short-lived credentials to red [...]
083
Reposted by Python Package Index
Python Software Foundation @python.org · 22/06/2026
Watch PSF PyPI Safety & Security Engineer @miketheman.com's talk from Open Source Summit NA 2026: Trusted Publishing uses OIDC to generate short-lived tokens from CI/CD. No passwords. No tokens to rotate. No secrets in repos. www.youtube.com/watch?v=i0BW... #Python #PyPI #OSSummit #Security
youtube.com
Trusted Publishing: Eliminating Credentials From Your Release Workflow - Mike Fiedler
YouTube video by The Linux Foundation
0148
Reposted by Python Package Index
Python Software Foundation @python.org · 09/06/2026
Hear from PSF's @pypi.org Support Specialist Maria Ashna on what her day-to-day looks like, how she cleared multiple months-long backlogs, and the future of PyPI Orgs in this Behind the Commit episode from @clytaemnestra.bsky.social. ▶️ www.youtube.com/watch?v=OGIz... #Python #PyPI #OpenSource
youtube.com
Inside PyPI: Maria Ashna on Supporting Python's Package Index [Full Episode]
YouTube video by Behind the Commit
1113
Reposted by Python Package Index
Python Software Foundation @python.org · 16/04/2026
The PSF is looking for a PyPI Sustainability Engineer to join the team! This is a full time, 1-year contract (with the possibility of renewal), globally remote position. If you love #Python, care about open source, and want your work to matter at infrastructure scale–consider applying! #PyPI #Python
pythonsoftwarefoundation.applytojob.com
Sustainability Engineer, PyPI - Career Page
Apply to Sustainability Engineer, PyPI in Remote.
01210
Python Package Index @pypi.org · 16/04/2026
🔎🔐 PyPI has completed its second external #security audit! Thanks to @sovereign.tech for funding, Trail of Bits for the audit, and Alpha-Omega for supporting rapid remediation. Find the full report on the Trail of Bits publication page. #Python #PyPI
blog.pypi.org
PyPI has completed its second audit - The Python Package Index Blog
We are proud to announce PyPI's second external security audit.
02412
Python Package Index @pypi.org · 02/04/2026
PSF Security developers have published incident reports on the LiteLLM & Telnyx #supplychain attacks. Read what happened, who's affected, and what developers & maintainers can do to prepare and protect themselves from future incidents. #security #python
blog.pypi.org
Incident Report: LiteLLM/Telnyx supply-chain attacks, with guidance - The Python Package Index Blog
Python Package Index shares insights and provides guidance following LiteLLM/Telnyx supply-chain attacks
01910
Python Package Index @pypi.org · 03/03/2026
Huge thanks to @fastly.com for 10+ years of keeping #PyPI up and running! PyPI serves 800K+ users at ~100K requests/sec. With a small team behind the service, that kind of scale is only possible because of infrastructure partners who invest in the sustainability of the #Python ecosystem.
13813
Python Package Index @pypi.org · 28/01/2026
Over the past year (and a half!), our inaugural PyPI Support Specialist, Maria Ashna, helped tackle backlogs, improve support processes, and keep #PyPI running smoothly for the #Python community. Read the full reflection on what that work looked like 👇 blog.pypi.org/posts/2026-0...
blog.pypi.org
Dispatch from PyPI Land: A Year (and a Half!) as the Inaugural PyPI Support Specialist - The Python Package Index Blog
A look back on the first year and a half as the inaugural PyPI Support Specialist.
0103
Reposted by Python Package Index
Fastly @fastly.com · 13/01/2026
Proud to support the Python Software Foundation (@python.org) as a Fast Forward member! PyPI’s 2025 Year in Review shows the scale of the Python ecosystem: • 3.9M+ new files • 130K+ new projects Honored to help power infrastructure behind the global Python community. blog.pypi.org/posts/2025-1...
0145
Python Package Index @pypi.org · 06/01/2026
2025 was another eventful year for PyPI! Critical security enhancements, powerful new org features, a better overall user experience, and transparent security incident response 🎉👏 Thank you, PyPI team & community! Learn more on our blog: blog.pypi.org/posts/2025-1...
Infographic of PyPI statistics, with a yellow background, blue and grey text, and blue rectangles to highlight each statistic. Title states "PyPI in 2025". Underneath are 5 statistics: 
    3.9 million+ new files published
    130,000+ new projects created
    1.92 exabytes of total data transferred
    2.56 trillion total requests served
    81,000 requests per second on average
At the bottom is the PyPI logo, "Python package index" with blocks in the shape of the Python logo.
14317
Reposted by Python Package Index
Mike Fiedler @miketheman.com · 10/11/2025
New @pypi.org blog TL, DR: - Trusted Publishing used for 25% of all files uploaded in Oct 2025 - @gitlab.com Self-Managed now in beta - Pending Publishers can be added for Organizations, too! #Python #SupplyChain #Security Read it here: blog.pypi.org/posts/2025-1...
blog.pypi.org
Trusted Publishing is popular, now for GitLab Self-Managed and Organizations - The Python Package Index Blog
Expansion of Trusted Publishers feature for more impact
11710
Reposted by Python Package Index
Python Software Foundation @python.org · 29/10/2025
PyPI serves billions of requests daily- but sustaining it isn’t free. The PSF joined the OpenSSF & others in calling for organizations to invest in sustainable open infrastructure. Learn what this means for #PyPI, the PSF, & how our community can pitch in:
pyfound.blogspot.com
Open Infrastructure is Not Free: PyPI, the Python Software Foundation, and Sustainability
In September, the Python Software Foundation (PSF) co-signed the Open Infrastructure is Not Free: A Joint Statement on Sustainable Stewardship Letter published by the Open Source Security Foundation (OpenSSF) as a steward of the Python Package Index (PyPI). As a follow up, I would like to share a bit more about the concerns expressed in this letter as they relate to our community and the PSF.
05113
Python Package Index @pypi.org · 26/09/2025
A campaign targeted GitHub Actions to steal PyPI tokens—PyPI wasn’t compromised and no PyPI packages were published by the attackers. Stay safe: review your tokens, rotate any exposed ones, and use short-lived, scoped GitHub Actions tokens. Details:
blog.pypi.org
Token Exfiltration Campaign via GitHub Actions Workflows - The Python Package Index Blog
Incident report of a recent attack campaign targeting GitHub Actions workflows to exfiltrate PyPI tokens, our response, and steps to protect your projects.
0104
Python Package Index @pypi.org · 23/09/2025
🚨 There is a new ongoing phishing campaign against PyPI users. This campaign uses the same tactics as the previous campaign targeting PyPI users, but with a new domain. Read more about what steps we're taking to protect PyPI users from future campaigns:
blog.pypi.org
Phishing attacks with new domains likely to continue - The Python Package Index Blog
A new phishing campaign targeting PyPI users using similar tactics to previous campaigns.
01512
Reposted by Python Package Index
Python Software Foundation @python.org · 26/08/2025
The PSF has adopted pypistats.org, ensuring long-term stability while staying open source and community driven 🎉 Thank you to Christopher Flynn, for operating this awesome community service for 6+ years- and for continuing to maintain the project 💪🐍 pyfound.blogspot.com/2025/08/pypi...
13115
Python Package Index @pypi.org · 18/08/2025
PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to take over #PyPI accounts through password resets. #Python #OpenSource #SupplyChain #Security
blog.pypi.org
Preventing Domain Resurrection Attacks - The Python Package Index Blog
PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to take over PyPI accounts through password resets.
0187
Python Package Index @pypi.org · 07/08/2025
The Python Package Index is introducing new restrictions to protect Python package installers and inspectors from ZIP confusion attacks. There is no evidence that this vulnerability has been exploited. Read the blog post for more information:
blog.pypi.org
Preventing ZIP parser confusion attacks on Python package installers - The Python Package Index Blog
PyPI will begin warning and will later reject wheels that contain differentiable ZIP features or incorrect RECORD files.
0166
Reposted by Python Package Index
Mike Fiedler @miketheman.com · 28/07/2025
Always verify the domain is pypi.org before logging in. Read more: blog.pypi.org/posts/2025-0...
blog.pypi.org
PyPI Users Email Phishing Attack - The Python Package Index Blog
PyPI Users are receiving emails detailing them to log in to a fake PyPI site.
0106
Reposted by Python Package Index
Mike Fiedler @miketheman.com · 28/07/2025
Heads Up, #Python Developers! There is an active phishing attack targeting PyPI users. • Threat: Emails from noreply@pypj.org (with a 'j') link to a fake login page. • Action: Do not click any links. If you already did, change your PyPI password ASAP. • Note: PyPI itself has not been breached.
26040
Reposted by Python Package Index
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 01/05/2025
my colleague @darkamaul.bsky.social has a new blog post on the @trailofbits.bsky.social blog about how we worked with @pypi.org's maintainers to slash test times on PyPI by over 80%: blog.trailofbits.com/2025/05/01/m...
blog.trailofbits.com
Making PyPI's test suite 81% faster
See how we slashed PyPI’s test suite runtime from 163 to 30 seconds. The techniques we share can help you dramatically improve your own project’s testing performance without sacrificing coverage.
063
Python Package Index @pypi.org · 14/04/2025
Incident report! Thanks to our community for reporting, we take security seriously and work to address issues like these to suit. blog.pypi.org/posts/2025-0...
blog.pypi.org
Incident Report: Organizations Team privileges - The Python Package Index Blog
We responded to an incident related to privileges persisting via Organization Teams after Members are removed from Organizations.
122
Python Package Index @pypi.org · 21/02/2025
#PyPI takes security very seriously. If you ever run into malware or a security issue with PyPI itself, make sure to follow our reporting instructions carefully-- and thank you for your vigilance! pypi.org/security/ #python
pypi.org
Security
The Python Package Index (PyPI) is a repository of software for the Python programming language.
060
Python Package Index @pypi.org · 21/02/2025
Keep up to date and subscribe for updates on #PyPI infrastructure status, including requests, edge requests/errors, and traffic via our public dashboard: status.python.org #python
status.python.org
Python Infrastructure Status
Welcome to Python Infrastructure's home for real-time and historical data on system performance.
020
Python Package Index @pypi.org · 20/02/2025
Into stats? Find various first and third party #PyPI statistics on our website: pypi.org/stats/ #python
pypi.org
Statistics
The Python Package Index (PyPI) is a repository of software for the Python programming language.
010
Python Package Index @pypi.org · 20/02/2025
Want to add your #Python package to #PyPI? Check out our 'Packaging Python Projects' guide:
packaging.python.org
Packaging Python Projects - Python Packaging User Guide
This tutorial walks you through how to package a simple Python project. It will show you how to add the necessary files and structure to create the package, how to build the package, and how to upload it to the Python Package Index (PyPI).
155
Python Package Index @pypi.org · 20/02/2025
Learn about how to install and distribute #Python packages with the 'Python Packaging User Guide', a collection of tutorials and references, maintained by the Python Packaging Authority: packaging.python.org/ #pypi
packaging.python.org
Python Packaging User Guide
The Python Packaging User Guide (PyPUG) is a collection of tutorials and guides for packaging Python software.
020
Python Package Index @pypi.org · 19/02/2025
If you want to get in-depth updates on #PyPI news, updates, and incidents, make sure to regularly read up on our blog: blog.pypi.org/ #python
blog.pypi.org
The Python Package Index Blog
The official blog of the Python Package Index
074
Python Package Index @pypi.org · 19/02/2025
If you've got questions about the basics of #PyPI, your account, integration, project admin, troubleshooting, or what PyPI is all about, make sure to check our FAQ! pypi.org/help/ #python
pypi.org
Help
The Python Package Index (PyPI) is a repository of software for the Python programming language.
010
Python Package Index @pypi.org · 18/02/2025
@python.org raises and distributes funds to improve #Python's packaging ecosystem, including #PyPI. If your company depends on Python or PyPI, send our sponsorship page to those internal decision makers to help sustain Python for all, for free, forever: www.python.org/sponsors/app...
python.org
The official home of the Python Programming Language
050
Python Package Index @pypi.org · 18/02/2025
New to #PyPI? It's the home and central repository for #Python packages 🐍🏡 Use pip install to grab your favorite libraries!
packaging.python.org
Installing Packages - Python Packaging User Guide
It’s important to note that the term “package” in this context is being used to describe a bundle of software to be installed (i.e. as a synonym for a distribution). It does not refer to the kind of package that you import in your Python source code (i.e. a container of modules). It is common in the Python community to refer to a distribution using the term “package”. Using the term “distribution” is often not preferred, because it can easily be confused with a Linux distribution, or another larger software distribution like Python itself.
011
Python Package Index @pypi.org · 18/02/2025
Welcome to the official #PyPI Bluesky account 🦋🐍 Your trusted source for discovering, installing, and sharing #Python packages. Follow us for updates, security news, and incident reports!
pypi.org
The Python Package Index (PyPI) is a repository of software for the Python programming language.
0143
Reposted by Python Package Index
Brett Cannon @snarky.ca · 30/01/2025
I just went through and archived every project I'm the sole owner of that hasn't had a release in 4 years (although that date isn't special, it just happens to be the "youngest" release; oldest, latest release was over 14 years ago).
0101
Reposted by Python Package Index
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 30/01/2025
you can now archive projects on @pypi.org! this work was done by my teammate Facundo @trailofbits.bsky.social and is part of a larger multi-year arc of work dedicated to landing security and usability improvements on PyPI: blog.trailofbits.com/2025/01/30/p...
blog.trailofbits.com
PyPI now supports archiving projects
By Facundo Tuesca PyPI now supports marking projects as archived. Project owners can now archive their project to let users know that the project is not expected to receive any more updates. Projec…
0137
Python Package Index @pypi.org · 30/01/2025
PyPI Now Supports Project Archival: blog.pypi.org/posts/2025-0...
blog.pypi.org
PyPI Now Supports Project Archival - The Python Package Index Blog
Projects on PyPI can now be marked as archived.
0207
Reposted by Python Package Index
Mike Fiedler @miketheman.com · 02/01/2025
I recently wrote about how I added the ability to quarantine projects under investigation on @pypi.org Read here: blog.pypi.org/posts/2024-1... #Python #Packaging #OpenSource #Security #PyPI
blog.pypi.org
Project Quarantine - The Python Package Index Blog
Handling project quarantine lifecycle status for suspected malware
081
Reposted by Python Package Index
Seth Larson @sethmlarson.dev · 11/12/2024
Last week the Python package "Ultralytics" suffered a supply-chain attack on its build and release process. This is a review of the attack from @pypi.org's perspective. There's plenty of advice for how Python projects can increase their #security posture: blog.pypi.org/posts/2024-1...
blog.pypi.org
Supply-chain attack analysis: Ultralytics - The Python Package Index Blog
Analysis of a package targeted by a supply-chain attack to the build and release process
04018