3 ms·
Though this has been true for a while, it's not what this announcement is about. This is specifically announcing automated scanning and reporting of PyPI keys,
by JosephRedfern 6y ago
Though this has been true for a while, it's not what this announcement is about. This is specifically announcing automated scanning and reporting of PyPI keys, which if exposed, could allow a bad actor to distribute compromised Python packages via PyPi (e.g. pip)
- russfink 6y agoAnd this is a potentially huge security issue. Think about all the systems software that relies on Python packages.