URL has been copied successfully!
PyPI Blocks New File Uploads to Old Releases to Prevent Package Poisoning Attacks
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

PyPI Blocks New File Uploads to Old Releases to Prevent Package Poisoning Attacks

PyPI has introduced a new supply-chain security control that prevents publishers from uploading additional files to package releases older than 14 days, reducing the risk of attackers poisoning previously trusted versions after compromising project credentials, automation workflows, or publishing tokens. The Python Package Index (PyPI) has begun rejecting new distribution files uploaded to releases that […] The post PyPI Blocks New File Uploads to Old Releases to Prevent Package Poisoning Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

First seen on gbhackers.com

Jump to article: gbhackers.com/pypi-blocks-new-file-uploads-to-old-releases/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link