![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIPn9dzeZZJsJenlWbgzw_jVzJaCKHWZybX0ZAqRGgQCqS90ovtydLRjTKkFSV8fWlnh6rS9FmS16wpM1QgHqFtOtBtWgNhYuckfCVLYfjYMnWPNPFu0Ihek8Tyu7AH6_uzBep4GQOhP_J1BgW-imfO2cJrp6-Smb75_GP9wE5fIsvrtdaLi0WeJrSb_B2/s728-rw-e365/python.png)
Python Package Index (PYPI) registry maintainers have announced new features that allow package developers to archive projects as part of an effort to improve supply chain security.
Facundo Tuesca, a senior engineer of Trail of Bits, states:
Doing so will clearly show the developers that the Python library will not be actively maintained, and that future security corrections and product updates will not be expected.
![Cyber security](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6e4c8i_pkXRCFnrtqVIygOrARiVnU3_KUgU5mhPl5V4uj8R1KcQOxRLdZ0xm1Rf5AX_cviUAeiiRkTJCe8HXzOeB363590NBXAMv92N9e7zr4m7aKtDq-Q_gpP9QFWecL0oxcVtmqSg9qrGEGqlDbzwNNFKGJe2nlup4tuL7AZzTm0U501YxPGodOc2Fq/s728-rw-e100/zz-d.jpg)
Nevertheless, the archive and labeled projects will continue to be available in PYPI, and users can continue to install without any problems.
In another blog post in detail, Tuesca stated that Menteners are considering additional status of maintainer control to convey the project status to downstream consumers.
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6pXCGnRGchud7dy0Js-Nk2WVHEkMQoQuAXgwbDM220g8SVf8xNz42KSDgn0hnE-URHYBQRpYx40HMfS6c3RlkHpJYTJgjxLFEEzsWEV3Crgt8CekifFDoGY44eW9bra9ZaSJsFwB2YW8aIiBE0EhRTvMNJyq9QtUkuF4E4HEHpYIFWeN-LMNoPSyTzAGS/s728-rw-e365/status.jpg)
PYPI also recommends the package developer to release the final version before Archival by updating the project explanation, warning the user, and including the replacement as an exchange.
This development occurs shortly after PYPI develops the ability to quarantine the project, and the administrator marks the project as a potential suspicious thing, and other users can install it to prevent further harm.
In November 2024, the Pypi administrator found that a new update contained a malicious code designed to remove private keys via Telegram, and then isolated Python Library Aiocpa. 。
![Cyber security](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhT2OnXk97z-adL5WBKzz6wsA7vAhygg3Px0VPmqpH5hH4AErnYajTCpDN7SLy43ejD_T4Skv8OMOdG9qpzMfihrj8o7qSznLKA8zg7jW8L4hY8-umwTNZSpAj0JvtG3VGMFGw9n7hMyea1NpVSXp6yTaClLUQ3GujxwlEuLmQFSsVH28WQy6vp-cOGG0p_/s728-rw-e100/saas-security-v2-d.png)
Since last August, about 140 projects have been quarantined, and have been removed from the registry.
“By having this brokerage stage, Pypi administrators can enhance the safety of the end user, and the PYPI administrators will enable further investigations and delete suspicion packages, so that they protect the end users more quickly. I will do it “
“Deleting projects from PYPI is a destructive action, so if you create a quarantine state, it can be restored if it is considered an incorrect positive report without destroying the history and metadata of the project. Masu.”
Source link