Quoting Seth Larson
Summary
PyPI now rejects uploads of new files to releases older than 14 days to prevent supply-chain attacks, a proactive security measure announced by Seth Larson.
View Cached Full Text
Cached at: 07/24/26, 05:15 AM
Similar Articles
PyPI releases now reject new files after 14 days
PyPI now rejects new file uploads to releases older than 14 days, a security measure to prevent supply chain attacks by compromising old releases. The change was driven by incidents like the LiteLLM and Telnyx compromises.
@github: Dependabot now waits three days before non-security version update pull requests, giving scanners time to catch a poiso…
GitHub's Dependabot now implements a three-day cooldown for non-security version updates to give security scanners time to detect poisoned releases, helping mitigate supply chain attacks.
@RhysSullivan: just enabled a minimum age on npm package installs for my machine, should've done this sooner but if you haven't either…
A developer shares a tip to configure a minimum release age for package installs to mitigate supply-chain attacks.
@altryne: PSA: If you are un-aware of the latest supply-chain attacks, or aware but complacent and didn't do anything, especially…
A PSA about a series of supply-chain attacks targeting AI developer tools (Hermes, OpenClaw) via npm and PyPI, specifically the 'Mini-Shai Hulud' worm that self-replicates and steals credentials, API keys, and browser sessions. The post advises sandboxed execution and restricting package age to mitigate risks.
The npm/Docker/PyPI supply chain security pattern is repeating with MCP, and we are at the 2015 moment
The article warns that the MCP ecosystem is repeating the same supply chain security pattern seen in npm, Docker, and PyPI, with minimal vetting and growing risks. It highlights that a scan of 500 Smithery servers found 18.8% with security issues and that existing security tooling cannot handle malicious agent instructions, and introduces a new static scanner called bawbel.