PyPI begins rejecting new file uploads to releases older than 14 days to mitigate supply-chain risk
The Python Package Index now blocks uploads to aged releases, a change intended to reduce the risk of supply-chain attacks via compromised publishing credentials.
2 sources · cross-referenced
- PyPI now rejects new file uploads to releases older than 14 days to prevent supply-chain attacks.
- The change aims to mitigate the risk of attackers poisoning long-stable releases if project tokens or workflows are compromised.
- As of the announcement, PyPI has not observed evidence of abuse of this attack path.
The Python Package Index (PyPI) now rejects new file uploads to releases that are older than 14 days, a change intended to reduce the risk of supply-chain attacks. According to a statement from PyPI maintainer Seth Larson, the restriction was implemented to prevent attackers from poisoning long-stable releases if project publishing tokens or workflows are compromised. The policy change was announced in a PyPI blog post on July 22, 2026.
As of the announcement, PyPI reported it had not observed evidence that this attack path had been abused. Larson noted there was no technical barrier preventing abuse other than the apparent lack of attacker awareness of the possibility.
The restriction applies to new file uploads to existing releases, not to new releases themselves. This targets scenarios where an attacker might obtain valid publishing credentials after a release has stabilized and inject malicious files into an otherwise trusted version.
- Jul 25, 2026 · MIT Technology Review — AI
AstraZeneca details AI’s expanding role in biologics drug discovery and R&D acceleration
Trust78 - Jul 23, 2026 · The Verge — AI
Patreon lays off 20% of workforce amid AI-driven industry shifts
Trust74 - Jul 23, 2026 · The Verge — AI
AMD to invest up to $5 billion in Anthropic and supply up to 2 GW of AI GPUs
Trust79