Anže on Nostr: With recent Python supply chain attacks (Trivy/LiteLLM), it’s worth mentioning ...
With recent Python supply chain attacks (Trivy/LiteLLM), it’s worth mentioning uv’s `exclude-newer = "x days"` config.
It forces uv to only installs packages published more than x days ago, reducing risks since problematic packages should be yanked by then.
https://docs.astral.sh/uv/reference/settings/#exclude-newerPublished at
2026-03-25 15:11:50 UTCEvent JSON
{
"id": "a28e36d6c0bc6f3772326c84214c487e617b0a3d9bc32baab354cd4cdcb03f9f",
"pubkey": "a39a91945320863e63212c3b4f06a13aa380f33aa231788cf172e6701ba657f4",
"created_at": 1774451510,
"kind": 1,
"tags": [
[
"proxy",
"https://fosstodon.org/@anze3db/116290454166696484",
"web"
],
[
"proxy",
"https://fosstodon.org/users/anze3db/statuses/116290454166696484",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://fosstodon.org/users/anze3db/statuses/116290454166696484",
"pink.momostr"
],
[
"-"
]
],
"content": "With recent Python supply chain attacks (Trivy/LiteLLM), it’s worth mentioning uv’s `exclude-newer = \"x days\"` config.\n\nIt forces uv to only installs packages published more than x days ago, reducing risks since problematic packages should be yanked by then.\n\nhttps://docs.astral.sh/uv/reference/settings/#exclude-newer",
"sig": "e41d0c6fad22ed9bc871f0aa378750b3573a8b418ec4775b308a1d40a18a0e47ff41bec10b1e45538215dd5072865fe8ea46b82fa4dfa5da1ea77151908f0390"
}