corpus.blog
Most cited
Talked about
Blogs
41554 blogs · [ { "id": "01a0d5b0-a43c-718b-ae95-cf18a4bbaad2", "title": "Incident Report: User Account Takeover", "url": "https://blog.pypi.org/posts/2023-12-04-account-takeover/", "published_at": "2026-09-09T14:04:14+00:00" }, { "id": "01a0d5b0-a43c-718b-ae95-cf18a5ba17bf", "title": "2FA Enforcement for TestPyPI", "url": "https://blog.pypi.org/posts/2023-12-06-2fa-enforcement-on-testpypi/", "published_at": "2026-09-09T14:04:14+00:00" }, { "id": "01a08215-4d00-717d-a985-59a6fad8038b", "title": "Incident Report: File Hosting Errors", "url": "https://blog.pypi.org/posts/2026-09-08-file-hosting-errors/", "published_at": "2026-09-08T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f219a513", "title": "Metadata requests no longer tracked in PyPI download counts", "url": "https://blog.pypi.org/posts/2026-08-31-download-counts/", "published_at": "2026-08-31T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7fa1dd253", "title": "Welcome to the PyPI Blog", "url": "https://blog.pypi.org/posts/2023-03-21-welcome-to-the-pypi-blog/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7fa653a4a", "title": "Introducing 'Trusted Publishers'", "url": "https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7fa848400", "title": "Introducing PyPI Organizations", "url": "https://blog.pypi.org/posts/2023-04-23-introducing-pypi-organizations/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7facffd6c", "title": "Announcing the PyPI Safety & Security Engineer role", "url": "https://blog.pypi.org/posts/2023-05-09-announcing-pypi-safety-and-security-engr-role/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7fb66b8db", "title": "Removing PGP from PyPI", "url": "https://blog.pypi.org/posts/2023-05-23-removing-pgp/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7fc5cd3b2", "title": "PyPI was subpoenaed", "url": "https://blog.pypi.org/posts/2023-05-24-pypi-was-subpoenaed/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7fd3c1ba5", "title": "Securing PyPI accounts via Two-Factor Authentication", "url": "https://blog.pypi.org/posts/2023-05-25-securing-pypi-with-2fa/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7fd9b8697", "title": "Reducing Stored IP Data in PyPI", "url": "https://blog.pypi.org/posts/2023-05-26-reducing-stored-ip-data/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7fe077184", "title": "Enforcement of 2FA for upload.pypi.org begins today", "url": "https://blog.pypi.org/posts/2023-06-01-2fa-enforcement-for-upload/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7fe410bda", "title": "Announcing the launch of PyPI Malware Reporting and Response project", "url": "https://blog.pypi.org/posts/2023-06-22-malware-detection-project/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7fecd6a59", "title": "Deprecation of bdist_egg uploads to PyPI", "url": "https://blog.pypi.org/posts/2023-06-26-deprecate-egg-uploads/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7ffaf1ed9", "title": "PyPI hires a Safety & Security Engineer", "url": "https://blog.pypi.org/posts/2023-08-04-pypi-hires-safety-engineer/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7ffd37b2e", "title": "2FA Enforcement for New User Registrations", "url": "https://blog.pypi.org/posts/2023-08-08-2fa-enforcement-for-new-users/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb800408dd8", "title": "GitHub now scans public issues for PyPI secrets", "url": "https://blog.pypi.org/posts/2023-08-17-github-token-scanning-for-public-repos/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb8006af2f6", "title": "Inbound Malware Volume Report", "url": "https://blog.pypi.org/posts/2023-09-18-inbound-malware-reporting/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb800bbb04c", "title": "PyPI has completed its first security audit", "url": "https://blog.pypi.org/posts/2023-11-14-1-pypi-completes-first-security-audit/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb801561076", "title": "Security Audit Remediation: Warehouse", "url": "https://blog.pypi.org/posts/2023-11-14-2-security-audit-remediation-warehouse/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb8017df027", "title": "Security Audit Remediation: cabotage", "url": "https://blog.pypi.org/posts/2023-11-14-3-security-audit-remediation-cabotage/", "published_at": "2026-08-19T14:04:05+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f2be5682", "title": "How AWS Powers PyPI and the PSF", "url": "https://blog.pypi.org/posts/2026-08-14-how-aws-powers-pypi-and-the-psf/", "published_at": "2026-08-14T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f2e8bfee", "title": "The HTML representation of the index API is now frozen", "url": "https://blog.pypi.org/posts/2026-08-11-html-index-is-frozen/", "published_at": "2026-08-11T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f385ef21", "title": "Releases now reject new files after 14 days", "url": "https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/", "published_at": "2026-07-22T12:00:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f3d255f1", "title": "Planned Updates to the PyPI User Interface", "url": "https://blog.pypi.org/posts/2026-07-22-ui-updates/", "published_at": "2026-07-22T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f3f497f1", "title": "PyPI has completed its second audit", "url": "https://blog.pypi.org/posts/2026-04-16-pypi-completes-second-audit/", "published_at": "2026-04-16T14:00:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f41ac0eb", "title": "Incident Report: LiteLLM/Telnyx supply-chain attacks, with guidance", "url": "https://blog.pypi.org/posts/2026-04-02-incident-report-litellm-telnyx-supply-chain-attack/", "published_at": "2026-04-02T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f44f4fe6", "title": "Dispatch from PyPI Land: A Year (and a Half!) as the Inaugural PyPI Support Specialist", "url": "https://blog.pypi.org/posts/2026-01-26-a-year-and-a-half-as-inaugural-pypi-support-specialist/", "published_at": "2026-01-26T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f4ad5d2e", "title": "PyPI in 2025: A Year in Review", "url": "https://blog.pypi.org/posts/2025-12-31-pypi-2025-in-review/", "published_at": "2025-12-31T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f5145afb", "title": "PyPI and Shai-Hulud: Staying Secure Amid Emerging Threats", "url": "https://blog.pypi.org/posts/2025-11-26-pypi-and-shai-hulud/", "published_at": "2025-11-26T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f5ab0664", "title": "New Login Verification for TOTP-based Logins", "url": "https://blog.pypi.org/posts/2025-11-14-login-verification/", "published_at": "2025-11-14T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f64bf144", "title": "Trusted Publishing is popular, now for GitLab Self-Managed and Organizations", "url": "https://blog.pypi.org/posts/2025-11-10-trusted-publishers-coming-to-orgs/", "published_at": "2025-11-10T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f64db12c", "title": "Phishing attacks with new domains likely to continue", "url": "https://blog.pypi.org/posts/2025-09-23-plenty-of-phish-in-the-sea/", "published_at": "2025-09-23T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f6873b19", "title": "Token Exfiltration Campaign via GitHub Actions Workflows", "url": "https://blog.pypi.org/posts/2025-09-16-github-actions-token-exfiltration/", "published_at": "2025-09-16T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f752cf70", "title": "Preventing Domain Resurrection Attacks", "url": "https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/", "published_at": "2025-08-18T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f7d7271f", "title": "PyPI now serves project status markers in API responses", "url": "https://blog.pypi.org/posts/2025-08-14-project-status-markers/", "published_at": "2025-08-14T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f803541c", "title": "Preventing ZIP parser confusion attacks on Python package installers", "url": "https://blog.pypi.org/posts/2025-08-07-wheel-archive-confusion-attacks/", "published_at": "2025-08-07T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f81e6017", "title": "PyPI Phishing Attack: Incident Report", "url": "https://blog.pypi.org/posts/2025-07-31-incident-report-phishing-attack/", "published_at": "2025-07-31T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f911d875", "title": "PyPI Users Email Phishing Attack", "url": "https://blog.pypi.org/posts/2025-07-28-pypi-phishing-attack/", "published_at": "2025-07-28T06:09:00+00:00" }, { "id": "01a07df1-ef52-7079-bdf6-ecb7f9ecb78e", "title": "inbox.ru Domain Prohibition Follow-up", "url": "https://blog.pypi.org/posts/2025-07-25-inbox-ru-follow-up/", "published_at": "2025-07-25T06:09:00+00:00" } ] posts
Claim your blog
Back to PyPI Blog
Blog · corpus.blog/blogs/blog.pypi.org/posts
PyPI Blog
blog.pypi.org
2026
Incident Report: User Account Takeover
original ↗
9 Sept 2026
2FA Enforcement for TestPyPI
original ↗
9 Sept 2026
Incident Report: File Hosting Errors
original ↗
8 Sept 2026
Metadata requests no longer tracked in PyPI download counts
original ↗
31 Aug 2026
Welcome to the PyPI Blog
original ↗
19 Aug 2026
Introducing 'Trusted Publishers'
original ↗
19 Aug 2026
Introducing PyPI Organizations
original ↗
19 Aug 2026
Announcing the PyPI Safety & Security Engineer role
original ↗
19 Aug 2026
Removing PGP from PyPI
original ↗
19 Aug 2026
PyPI was subpoenaed
original ↗
19 Aug 2026
Securing PyPI accounts via Two-Factor Authentication
original ↗
19 Aug 2026
Reducing Stored IP Data in PyPI
original ↗
19 Aug 2026
Enforcement of 2FA for upload.pypi.org begins today
original ↗
19 Aug 2026
Announcing the launch of PyPI Malware Reporting and Response project
original ↗
19 Aug 2026
Deprecation of bdist_egg uploads to PyPI
original ↗
19 Aug 2026
PyPI hires a Safety & Security Engineer
original ↗
19 Aug 2026
2FA Enforcement for New User Registrations
original ↗
19 Aug 2026
GitHub now scans public issues for PyPI secrets
original ↗
19 Aug 2026
Inbound Malware Volume Report
original ↗
19 Aug 2026
PyPI has completed its first security audit
original ↗
19 Aug 2026
Security Audit Remediation: Warehouse
original ↗
19 Aug 2026
Security Audit Remediation: cabotage
original ↗
19 Aug 2026
How AWS Powers PyPI and the PSF
original ↗
14 Aug 2026
The HTML representation of the index API is now frozen
original ↗
11 Aug 2026
Releases now reject new files after 14 days
original ↗
22 Jul 2026
Planned Updates to the PyPI User Interface
original ↗
22 Jul 2026
PyPI has completed its second audit
original ↗
16 Apr 2026
Incident Report: LiteLLM/Telnyx supply-chain attacks, with guidance
original ↗
2 Apr 2026
Dispatch from PyPI Land: A Year (and a Half!) as the Inaugural PyPI Support Specialist
original ↗
26 Jan 2026
2025
PyPI in 2025: A Year in Review
original ↗
31 Dec 2025
PyPI and Shai-Hulud: Staying Secure Amid Emerging Threats
original ↗
26 Nov 2025
New Login Verification for TOTP-based Logins
original ↗
14 Nov 2025
Trusted Publishing is popular, now for GitLab Self-Managed and Organizations
original ↗
10 Nov 2025
Phishing attacks with new domains likely to continue
original ↗
23 Sept 2025
Token Exfiltration Campaign via GitHub Actions Workflows
original ↗
16 Sept 2025
Preventing Domain Resurrection Attacks
original ↗
18 Aug 2025
PyPI now serves project status markers in API responses
original ↗
14 Aug 2025
Preventing ZIP parser confusion attacks on Python package installers
original ↗
7 Aug 2025
PyPI Phishing Attack: Incident Report
original ↗
31 Jul 2025
PyPI Users Email Phishing Attack
original ↗
28 Jul 2025
inbox.ru Domain Prohibition Follow-up
original ↗
25 Jul 2025