PyPI blocks file uploads to releases older than 14 days to curb supply chain risk
PyPI has introduced a rule preventing new file uploads to any package release that is more than 14 days old, as a preventative measure against supply chain attacks. The policy targets a scenario where a stolen publishing credential is used to graft malicious files onto an established, trusted package version without changing its version number. PyPI reviewed its own data before implementing the change and found that only a very small share of popular packages had legitimately added files to a release after the two-week window. Existing files, metadata, and version numbers are unaffected; only the addition of new files to older releases is blocked. The restriction complements, but does not replace, existing safeguards such as scoped tokens, OIDC-based trusted publishers, and Sigstore-backed attestations, since a compromised credential can still publish an entirely new release.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in