The Python Package Index (PyPI) is the repository of software for the Python programming language. Pronounced 🥧 🫛 👁️blog.pypi.org The CloudJoined September 2017
PSF Security developers have published incident reports on the LiteLLM & Telnyx #supplychain attacks. Read what happened, who's affected, and what developers & maintainers can do to prepare and protect themselves from future incidents. #security#pythonblog.pypi.org/posts/2026-04-…
Over the past year (and a half!), our inaugural PyPI Support Specialist, Maria Ashna, helped tackle backlogs, improve support processes, and keep #PyPI running smoothly for the #Python community.
Read the full reflection on what that work looked like 👇
blog.pypi.org/posts/2026-01-…
2025 was another eventful year for PyPI! Critical security enhancements, powerful new org features, a better overall user experience, and transparent security incident response 🎉👏 Thank you, PyPI team & community!
Learn more on our blog: blog.pypi.org/posts/2025-12-…
PyPI serves billions of requests daily- but sustaining it isn’t free. The PSF joined the OpenSSF & others in calling for organizations to invest in sustainable open infrastructure. Learn what this means for #PyPI, the PSF, & how our community can pitch in:
pyfound.blogspot.com/2025/10/open-i…
A campaign targeted GitHub Actions to steal PyPI tokens—PyPI wasn’t compromised and no PyPI packages were published by the attackers. Stay safe: review your tokens, rotate any exposed ones, and use short-lived, scoped GitHub Actions tokens. Details:
blog.pypi.org/posts/2025-09-…
🚨 There is a new ongoing phishing campaign against PyPI users. This campaign uses the same tactics as the previous campaign targeting PyPI users, but with a new domain.
Read more about what steps we're taking to protect PyPI users from future campaigns:
blog.pypi.org/posts/2025-09-…
The PSF has adopted pypistats.org, ensuring long-term stability while staying open source and community driven 🎉 Thank you to Christopher Flynn, for operating this community service for 6+ years- and for continuing to maintain the project 💪🐍 pyfound.blogspot.com/2025/08/pypist…
The Python Package Index is introducing new restrictions to protect Python package installers and inspectors from ZIP confusion attacks. There is no evidence that this vulnerability has been exploited. Read the blog post for more information:
blog.pypi.org/posts/2025-08-…
i'm late to the party but just started using trusted publishing on @pypi and it's such a nice experience!
just create a release.yml on github and add the repo name on the pypi project, that's it!
it's so good to not deal with creating api tokens and putting them on github
"In 2023, Google’s Open Source Security Team (GOSST) helped to fund the launch of Trusted Publishing for PyPI and supported the rollout of 2FA enforcement across PyPI" 👏👏👏
As we look to the future of open source, we're investing in improving security posture of open source projects and ecosystems.
💡 Learn more about our efforts to secure open source supply chains ⬇️ goo.gle/3X1QZKv
Astral is starting a fund to support open source projects and maintainers 💝 Thank you @astral_sh for your support of open source, the PSF, and the #python community, especially @pypi and CPython!
x.com/astral_sh/stat…
Announcing the Astral OSS Fund.
We're giving > $3,000 per Astral team member per year to open source projects, maintainers, and foundations, inspired by @getsentry's OSS Pledge.
astral.sh/blog/astral-os…
Enormous news! the Python Software Foundation now has a 5 year commitment with @fastly to deliver @pypi, us.pycon.org, and much more. We appreciate you and your continued investment in the #python community, Fastly! #PyConUS
84K Followers 278 FollowingCreator of @FastAPI, Typer, SQLModel, Asyncer, etc. 🚀
From 🇨🇴 in 🇩🇪 .
Open Source, APIs, and tools for data/ML. 🤖
Building @FastAPIcloud. ⚡️
182K Followers 1K FollowingA place for all things related to the #python #programming #coding #webdeveloper #webdevelopment #pythonprogramming #ai #ml #machinelearning #datascience ...
692K Followers 126 FollowingThe nonprofit organization behind the Python programming language. For help with Python code: https://t.co/XDHPttz2Xv
On Mastodon: @[email protected]
13K Followers 344 FollowingPython Steering Council and core developer. Python 3.10/3.11 release manager. @ThePSF Fellow. Deals with black holes and parsers. Attracts linker problems.
34K Followers 3K FollowingVamo embora dessa josta. Estou no mastodon e também no Blue Sky como https://t.co/GfhF4YqhFj. Isso aqui é controlado por um racista misógino assumido.
48K Followers 2K FollowingChief AI & Co-founder @AnacondaInc; invented @pyscript_dev, @PyData @Bokeh @Datashader. Former physicist. A student of the human condition. bsky: @wang.social
9K Followers 729 FollowingConstantly looking for simple ways to explain complex things You'll find: • Python • Narrative Technical Writing • Track & Field Athletics—Links in pinned post
21K Followers 571 FollowingFailed comedian, Python core developer, co-host of the https://t.co/7PoInheICG podcast. Python guy at Meta. Previously CPython Dev in Rez at the Python Software Foundation.
10K Followers 1K FollowingEngineering Coach https://t.co/ABlKqevhcW | Python • Rust • AI | Building the engineering judgment AI can’t replace. Co-founder of @Pybites.
692K Followers 126 FollowingThe nonprofit organization behind the Python programming language. For help with Python code: https://t.co/XDHPttz2Xv
On Mastodon: @[email protected]
2K Followers 698 FollowingElsewhere on the Internet
Wrangler of the Unusual. Roller Derby referee. AWS Hero. PyPI Maintainer. Pronouns: he/him
Working @ThePSF
@[email protected]
12.7M Followers 1.1M FollowingA forum of thoughts and perspectives designed to ignite conversations and actions leading to growth, and occasional self promotion. #NeverGiveUp #RiseAboveHate
3K Followers 581 Followingfuck all police. 🖥 snek. 🚲💨 @ewdurbin_bikes. signal: +1.216.217.8688. go hard and don’t fuck around. no work @/DM unless invited.
6K Followers 597 Followingpip // PyPI // Python // cryptography I am perpetually caremad. I care a lot about security. Agitator and profesional rabble rouser
@[email protected]