PyPI has implemented a new security measure that rejects uploads to release files older than 14 days to prevent supply chain poisoning attacks. This change aims to mitigate risks associated with compromised publishing tokens or workflows for long-stable projects.
Background
The Python Package Index (PyPI) is the primary repository for software in the Python programming language, making its security critical for the global developer community.
- Source
- Simon Willison
- Published
- Jul 23, 2026 at 12:50 PM
- Score
- 7.0 / 10