<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-07-15T17:57:50&#43;02:00</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by Python Package Index</title>
  <author>
    <name>Python Package Index</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1g52zm7t45x9srp48swy44hc03k2qzkckd63vyqfl0jvnvkzz8n0ql68fy6.rss" />
  <link href="https://nostr.ae/npub1g52zm7t45x9srp48swy44hc03k2qzkckd63vyqfl0jvnvkzz8n0ql68fy6" />
  <id>https://nostr.ae/npub1g52zm7t45x9srp48swy44hc03k2qzkckd63vyqfl0jvnvkzz8n0ql68fy6</id>
  <icon>https://cdn.fosstodon.org/accounts/avatars/110/460/563/228/175/137/original/3ae1e745c2f1e485.jpg</icon>
  <logo>https://cdn.fosstodon.org/accounts/avatars/110/460/563/228/175/137/original/3ae1e745c2f1e485.jpg</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsrlqgurdz9al7heq7ln662c8l03ggkztm0f3mj0c7k6ecugjw22vszypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7dua9dv5s</id>
    
      <title type="html">The Python Package Index now rejects new files published to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrlqgurdz9al7heq7ln662c8l03ggkztm0f3mj0c7k6ecugjw22vszypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7dua9dv5s" />
    <content type="html">
      The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days&#34;&gt;https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#python #security #supplychain #pypi
    </content>
    <updated>2026-07-22T16:26:28&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsts79cur532sdx3v9xz7000s998cmgnfezunhy4hwg3rw7f7cdejqzypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7du4ep5kq</id>
    
      <title type="html">🔎🔐 #PyPI has completed its second external #security audit! ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsts79cur532sdx3v9xz7000s998cmgnfezunhy4hwg3rw7f7cdejqzypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7du4ep5kq" />
    <content type="html">
      🔎🔐 #PyPI has completed its second external #security audit! Thanks to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1yng6dx32zrl2qhp2kq26al7uzkwqkugrkaxf4gsycs9r5snrkjdqlznhrk&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Sovereign Tech Agency&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1yng…nhrk&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; for funding, &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1rcsevfzqfj6xzk0rajfaftsnq4f4wewydfyxd9u46jch4sxta60qjz7sw8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Trail of Bits&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1rcs…7sw8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; for the audit, and Alpha-Omega for supporting rapid remediation. Find the full report on the Trail of Bits publication page. #Python&lt;br/&gt;&lt;a href=&#34;https://blog.pypi.org/posts/2026-04-16-pypi-completes-second-audit/&#34;&gt;https://blog.pypi.org/posts/2026-04-16-pypi-completes-second-audit/&lt;/a&gt;
    </content>
    <updated>2026-04-16T15:26:36&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswfx9a87cfrqxc9xhzl27wpee8an07zp579wvp2747fjajd29pkhqzypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7duqmm9vt</id>
    
      <title type="html">PSF Security developers have published incident reports on the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswfx9a87cfrqxc9xhzl27wpee8an07zp579wvp2747fjajd29pkhqzypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7duqmm9vt" />
    <content type="html">
      PSF Security developers have published incident reports on the LiteLLM &amp;amp; Telnyx #supplychain attacks. Read what happened, who&amp;#39;s affected, and what developers &amp;amp; maintainers can do to prepare and protect themselves from future incidents. #security #python&lt;br/&gt;&lt;a href=&#34;https://blog.pypi.org/posts/2026-04-02-incident-report-litellm-telnyx-supply-chain-attack/&#34;&gt;https://blog.pypi.org/posts/2026-04-02-incident-report-litellm-telnyx-supply-chain-attack/&lt;/a&gt;
    </content>
    <updated>2026-04-02T15:55:49&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsq6fhyzxkhu9h9leqda6sj9jrzcltjvyz6pag35d0twqjsspw5m5szypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7duap0j0r</id>
    
      <title type="html">RE: https://mastodon.social/@fastlydevs/116160789779498833 Huge ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsq6fhyzxkhu9h9leqda6sj9jrzcltjvyz6pag35d0twqjsspw5m5szypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7duap0j0r" />
    <content type="html">
      RE: &lt;a href=&#34;https://mastodon.social/@fastlydevs/116160789779498833&#34;&gt;https://mastodon.social/@fastlydevs/116160789779498833&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Huge thanks to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub14wasrg0yx5wfw2fkdjnmrkrhxndlsuqppzrn08eg6w8g2ddcssqsldj0zw&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Fastly Devs&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub14wa…j0zw&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; for 10&#43; years of keeping #PyPI up and running! PyPI serves 800K&#43; users at ~100K requests/sec. With a small team behind the service, that kind of scale is only possible because of infrastructure partners who invest in the sustainability of the #Python ecosystem.&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note1f6awxhxjcxrxt5s7xqk3wj66mltw0dpx453plq6pxpr0k5rlmausa9hxj4&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note1f6a…hxj4&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; For 10&#43; years, Fastly has supported the &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1vv848aca8vpv9lt2l2tj6wwehw7drwrs2e3ev9693rwz02jh448qcc6fhk&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Python Software Foundation&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1vv8…6fhk&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; in securing and scaling the Python Package Index (PyPI).&lt;br/&gt;&lt;br/&gt;~100K req/sec.&lt;br/&gt;500K&#43; projects.&lt;br/&gt;98–99% cache hit rate.&lt;br/&gt;Real-time purging in milliseconds.&lt;br/&gt;Adaptive WAF protection against bots &#43; account takeovers.&lt;br/&gt;&lt;br/&gt;Proud to help keep one of the world’s most critical open source ecosystems fast, fresh, and secure.&lt;br/&gt;&lt;br/&gt;Read more: &lt;a href=&#34;https://www.fastly.com/customers/psf&#34;&gt;https://www.fastly.com/customers/psf&lt;/a&gt; &lt;br/&gt;&lt;br/&gt;#Python #OpenSource #CyberSecurity&lt;br/&gt;&lt;video controls width=&#34;100%&#34; class=&#34;max-h-[90vh] bg-neutral-300 dark:bg-zinc-700&#34;&gt;&lt;source src=&#34;https://files.mastodon.social/media_attachments/files/116/160/787/762/104/134/original/5e6eb1bf00ab6018.mp4&#34;&gt;&lt;/video&gt;&lt;br/&gt; &lt;/blockquote&gt;
    </content>
    <updated>2026-03-03T16:07:17&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrnz34zphexyd4wumx5gsa7sjdcmgk306ta6tg7k689y9kfnlln9gzypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7duak6ax4</id>
    
      <title type="html">Over the past year (and a half!), our inaugural PyPI Support ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrnz34zphexyd4wumx5gsa7sjdcmgk306ta6tg7k689y9kfnlln9gzypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7duak6ax4" />
    <content type="html">
      Over the past year (and a half!), our inaugural PyPI Support Specialist, Maria Ashna, helped tackle backlogs, improve support processes, and keep #PyPI running smoothly for the #Python community.&lt;br/&gt;&lt;br/&gt;Read the full reflection on what that work looked like 👇&lt;br/&gt;&lt;a href=&#34;https://blog.pypi.org/posts/2026-01-26-a-year-and-a-half-as-inaugural-pypi-support-specialist/?utm_source=chatgpt.com&#34;&gt;https://blog.pypi.org/posts/2026-01-26-a-year-and-a-half-as-inaugural-pypi-support-specialist/?utm_source=chatgpt.com&lt;/a&gt;
    </content>
    <updated>2026-01-28T14:58:03&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr2emdsw8jr7r7h8re2vvcdkjs98up5xzykwaynscupkcezne5hhqzypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7due8c6em</id>
    
      <title type="html">2025 was another eventful year for PyPI! Critical security ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr2emdsw8jr7r7h8re2vvcdkjs98up5xzykwaynscupkcezne5hhqzypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7due8c6em" />
    <content type="html">
      2025 was another eventful year for PyPI! Critical security enhancements, powerful new org features, a better overall user experience, and transparent security incident response 🎉👏 Thank you, PyPI team &amp;amp; community! &lt;br/&gt;&lt;br/&gt;Learn more on our blog: &lt;a href=&#34;https://blog.pypi.org/posts/2025-12-31-pypi-2025-in-review/&#34;&gt;https://blog.pypi.org/posts/2025-12-31-pypi-2025-in-review/&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cdn.fosstodon.org/media_attachments/files/115/848/842/503/926/210/original/ae67bcf0b1260836.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-01-06T16:24:11&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9d02asgznaw5avj26nw04mwp09jlg56vmv7nzxuus0089avf5w8czypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7duxwp8aj</id>
    
      <title type="html">A campaign targeted GitHub Actions to steal PyPI tokens—PyPI ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9d02asgznaw5avj26nw04mwp09jlg56vmv7nzxuus0089avf5w8czypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7duxwp8aj" />
    <content type="html">
      A campaign targeted GitHub Actions to steal PyPI tokens—PyPI wasn’t compromised and no PyPI packages were published by the attackers. Stay safe: review your tokens, rotate any exposed ones, and use short-lived, scoped GitHub Actions tokens. Details:&lt;br/&gt;&lt;a href=&#34;https://blog.pypi.org/posts/2025-09-16-github-actions-token-exfiltration/&#34;&gt;https://blog.pypi.org/posts/2025-09-16-github-actions-token-exfiltration/&lt;/a&gt;
    </content>
    <updated>2025-09-26T14:45:39&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0ktxct2vzrnyc4yavl8nfwpj65xyn28ffzexdhpl467gads3l94czypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7dutck3ue</id>
    
      <title type="html">🚨 There is a new ongoing phishing campaign against PyPI users. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0ktxct2vzrnyc4yavl8nfwpj65xyn28ffzexdhpl467gads3l94czypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7dutck3ue" />
    <content type="html">
      🚨 There is a new ongoing phishing campaign against PyPI users. This campaign uses the same tactics as the previous campaign targeting PyPI users, but with a new domain.&lt;br/&gt;&lt;br/&gt;Read more about what steps we&amp;#39;re taking to protect PyPI users from future campaigns:&lt;br/&gt;&lt;a href=&#34;https://blog.pypi.org/posts/2025-09-23-plenty-of-phish-in-the-sea/&#34;&gt;https://blog.pypi.org/posts/2025-09-23-plenty-of-phish-in-the-sea/&lt;/a&gt;
    </content>
    <updated>2025-09-23T18:25:05&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqejyq07f4dennjye3j9x8cz2240e7kdrtuerqsnk660nscqqa2qszypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7dufdnqsn</id>
    
      <title type="html">PyPI now checks for expired domains to prevent domain ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqejyq07f4dennjye3j9x8cz2240e7kdrtuerqsnk660nscqqa2qszypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7dufdnqsn" />
    <content type="html">
      PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to take over #PyPI accounts through password resets. #Python #OpenSource #SupplyChain #Security&lt;br/&gt;&lt;a href=&#34;https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/&#34;&gt;https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/&lt;/a&gt;
    </content>
    <updated>2025-08-18T19:32:48&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqjrj7053uae0dcf57v3zvdtjckt58ek3t2rh2kj8urhcuheey44qzypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7dug8ug77</id>
    
      <title type="html">The Python Package Index is introducing new restrictions to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqjrj7053uae0dcf57v3zvdtjckt58ek3t2rh2kj8urhcuheey44qzypz3gt0ewksckqvx57pcjkklp7xegq2mzeh29ssp8a7fjdjcgg7dug8ug77" />
    <content type="html">
      The Python Package Index is introducing new restrictions to protect Python package installers and inspectors from ZIP confusion attacks. There is no evidence that this vulnerability has been exploited. Read the blog post for more information:&lt;br/&gt;&lt;a href=&#34;https://blog.pypi.org/posts/2025-08-07-wheel-archive-confusion-attacks/&#34;&gt;https://blog.pypi.org/posts/2025-08-07-wheel-archive-confusion-attacks/&lt;/a&gt;
    </content>
    <updated>2025-08-07T18:17:04&#43;02:00</updated>
  </entry>

</feed>