Mechanism◆Article
This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised.
The 14-day restriction is a supply-chain security measure designed to prevent attackers who compromise publishing tokens from injecting malicious files into long-stable releases. ✦ AI generated
Seth Larson · Simon Willison's Weblog · 2026-07-23 · original ↗
This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised.
Read full article ↗excerpt · fair-use quotation
- ·Blocks attackers from poisoning long-stable PyPI releases
- ·Applies when publishing tokens or workflows are compromised
- ·Prevents injection of malicious files into old releases
- ·Compromised tokens are the assumed attack vector
- ·Stable releases are the target — high trust, low scrutiny
- ·Restriction limits the window for post-compromise tampering
Around this claim
This moment responds to
explains mechanism → The Python Package Index (PyPI) now rejects new files being uploaded to releases that are older than 14 days.Seth Larson · Simon Willison's Weblogexplains mechanism → As far as we are aware this has not yet been abused, but there is no technical reason beyond that attackers weren't aware it was possible.Seth Larson · Simon Willison's Weblog