Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Samsung launches Z Fold7 and Z Flip7 and adds a cheap Z Flip7 Fe ​​to its collapsible lineup

EDF confirms 12.5% ​​shares in Sizewell c

North Korea Andariel Hacker Behind US Sanctions Fraudulent IT Worker Scheme

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » PYPI introduces an archive status that warns users about minor Python packages.
Identity

PYPI introduces an archive status that warns users about minor Python packages.

userBy userFebruary 3, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

LingeringFebruary 3, 2025LingeringRavy LakshmananOpen source /software security

Python Package Index (PYPI) registry maintainers have announced new features that allow package developers to archive projects as part of an effort to improve supply chain security.

Facundo Tuesca, a senior engineer of Trail of Bits, states:

Doing so will clearly show the developers that the Python library will not be actively maintained, and that future security corrections and product updates will not be expected.

Cyber ​​security

Nevertheless, the archive and labeled projects will continue to be available in PYPI, and users can continue to install without any problems.

In another blog post in detail, Tuesca stated that Menteners are considering additional status of maintainer control to convey the project status to downstream consumers.

PYPI also recommends the package developer to release the final version before Archival by updating the project explanation, warning the user, and including the replacement as an exchange.

This development occurs shortly after PYPI develops the ability to quarantine the project, and the administrator marks the project as a potential suspicious thing, and other users can install it to prevent further harm.

In November 2024, the Pypi administrator found that a new update contained a malicious code designed to remove private keys via Telegram, and then isolated Python Library Aiocpa. 。

Cyber ​​security

Since last August, about 140 projects have been quarantined, and have been removed from the registry.

“By having this brokerage stage, Pypi administrators can enhance the safety of the end user, and the PYPI administrators will enable further investigations and delete suspicion packages, so that they protect the end users more quickly. I will do it “

“Deleting projects from PYPI is a destructive action, so if you create a quarantine state, it can be restored if it is considered an incorrect positive report without destroying the history and metadata of the project. Masu.”

Did you find this article interesting? Follow on Twitter and Linkedin and read the exclusive content to post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleElmos in Spain says he has no consent to kissing the World Cup in Rubi Restless | Soccer News
Next Article Samsung’s Chief Jay Y. Lee has wiped out all accusations in the 2015 merger case.
user
  • Website

Related Posts

North Korea Andariel Hacker Behind US Sanctions Fraudulent IT Worker Scheme

July 9, 2025

How to automate ticket creation, device identification, and threat triage with tines

July 9, 2025

Chinese hacker Xu Zewei has been arrested for linking between silk typhoon groups and US cyberattacks

July 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Samsung launches Z Fold7 and Z Flip7 and adds a cheap Z Flip7 Fe ​​to its collapsible lineup

EDF confirms 12.5% ​​shares in Sizewell c

North Korea Andariel Hacker Behind US Sanctions Fraudulent IT Worker Scheme

How to automate ticket creation, device identification, and threat triage with tines

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Robots Play Football in Beijing: A Glimpse into China’s Ambitious AI Future

TwinH: A New Frontier in the Pursuit of Immortality?

Meta’s Secret Weapon: The Superintelligence Unit That Could Change Everything 

Unlocking the Power of Prediction: The Rise of Digital Twins in the IoT World

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.