4 ms·
They already went through requirering 2FA for the most popular packages: https://blog.pypi.org/posts/2023-05-25-securing-pypi-with-2fa/ https://blog.pypi.org/po
by gklitz 2y ago
They already went through requirering 2FA for the most popular packages: https://blog.pypi.org/posts/2023-05-25-securing-pypi-with-2fa/ https://blog.pypi.org/posts/2023-05-25-securing-pypi-with-2f...
This is just another step in increasing security. And of cause that is something you want to preferably do prior to breaches not only as a reaction.
- the_mitsuhiko 2y agoBecause publishing goes with GitHub actions for the most part for attestations the attack vector is getting access to GitHub which might be easier at this point.