PyPI Blocks New File Uploads on 14-Day-Old Releases to Prevent Package Poisoning Attacks

PyPI has introduced a new security measure that prevents users from uploading new files to package releases that are more than 14 days old. This change aims to stop attackers from adding malicious files to trusted Python package versions after compromising a maintainer’s publishing token or release workflow. The Python Package Index (PyPI) has begun […]

The post PyPI Blocks New File Uploads on 14-Day-Old Releases to Prevent Package Poisoning Attacks appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: