Hacker Newsnew | past | comments | ask | show | jobs | submit | miketheman's submissionslogin
1.PyPI has completed its second audit (pypi.org)
6 points by miketheman 51 days ago | past
2.Anthropic Invests $1.5M in the Python Software Foundation and OSS Security (pyfound.blogspot.com)
7 points by miketheman 4 months ago | past | 1 comment
3.PyPI in 2025: A Year in Review (pypi.org)
79 points by miketheman 5 months ago | past | 42 comments
4.PyPI and Shai-Hulud: Staying Secure Amid Emerging Threats (pypi.org)
3 points by miketheman 6 months ago | past
5.PyPI: Trusted Publishing Growth, Now for GitLab Self-Managed and Organizations (pypi.org)
2 points by miketheman 6 months ago | past
6.White Paper: Slippery Zips and Sticky Tar-Pits: Security and Archives (alpha-omega.dev)
2 points by miketheman 7 months ago | past | 1 comment
7.Open Infrastructure Is Not Free: PyPI, the PSF, and Sustainability (pyfound.blogspot.com)
8 points by miketheman 7 months ago | past
8.Datadog supports PyPI and the Python community through observability (datadoghq.com)
1 point by miketheman 7 months ago | past
9.PyPI Blog: Token Exfiltration Campaign via GitHub Actions Workflows (pypi.org)
76 points by miketheman 8 months ago | past | 20 comments
10.PyPI: Preventing Domain Resurrection Attacks (pypi.org)
5 points by miketheman 9 months ago | past | 2 comments
11.PyPI now serves project status markers in API responses (pypi.org)
2 points by miketheman 9 months ago | past
12.Preventing ZIP parser confusion attacks on Python package installers (pypi.org)
48 points by miketheman 10 months ago | past | 17 comments
13.PyPI Phishing Attack: Incident Report (pypi.org)
8 points by miketheman 10 months ago | past | 1 comment
14.PyPI Users Email Phishing Attack (pypi.org)
2 points by miketheman 10 months ago | past | 2 comments
15.PyPI Prohibits inbox.ru email domain registrations (pypi.org)
131 points by miketheman 10 months ago | past | 105 comments
16.AWS Lambda standardizes billing for INIT Phase (amazon.com)
7 points by miketheman on April 29, 2025 | past | 1 comment
17.PyPI Blog: Project Quarantine (pypi.org)
92 points by miketheman on Jan 2, 2025 | past | 60 comments
18.PyPI now supports digital attestations (pypi.org)
218 points by miketheman on Nov 14, 2024 | past | 186 comments
19.PyPI Safety and Security Engineer: First Year in Review (pypi.org)
3 points by miketheman on Aug 16, 2024 | past
20.PyPI Blog: Malware Distribution and Domain Abuse (pypi.org)
1 point by miketheman on April 10, 2024 | past
21.2FA Required for PyPI (pypi.org)
4 points by miketheman on Jan 1, 2024 | past
22.2FA Requirement for PyPI begins 2024-01-01 (pypi.org)
2 points by miketheman on Dec 15, 2023 | past
23.Support Python in 2023 (fundraiser and membership drive) (python.org)
2 points by miketheman on Dec 13, 2023 | past
24.TestPyPI now requires 2FA in advance of PyPI 2024 requirement (pypi.org)
1 point by miketheman on Dec 6, 2023 | past
25.PyPI has completed its first security audit (pypi.org)
137 points by miketheman on Nov 14, 2023 | past | 22 comments
26.PyPI Reports on Inbound Malware Notices (pypi.org)
26 points by miketheman on Sept 18, 2023 | past
27.GitHub now scans public issues for PyPI secrets (pypi.org)
4 points by miketheman on Aug 17, 2023 | past
28.PyPI Requires 2FA for New User Registrations (pypi.org)
112 points by miketheman on Aug 8, 2023 | past | 73 comments
29.PSF Hires PyPI Safety and Security Engineer (pyfound.blogspot.com)
65 points by miketheman on Aug 4, 2023 | past | 34 comments
30.PyPI Enforces Token Use for Uploads from Users with 2FA (pypi.org)
8 points by miketheman on June 1, 2023 | past

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: