The Hallway Track
Governance & Policy

Quoting Seth Larson

Simon Willison · Jul 23, 2026 · Governance & Policy

PyPI now blocks file uploads to releases older than 14 days to prevent supply chain poisoning.

“there is no technical reason beyond that attackers weren't aware it was possible”

PyPI implemented a proactive security policy rejecting new file uploads to releases older than 14 days, closing a supply chain attack vector where compromised publishing tokens could poison stable, widely-trusted packages. No known abuse has occurred, making this a rare preemptive hardening move by a major package registry. Relevant to AI developers given Python's dominance in ML tooling, but not a direct AI industry signal.

supply-chain python pypi packaging security

Watch / read the original source →