Bottom line: PyPI now prevents retroactive uploads to older releases to make supply-chain attacks via compromised publishing tokens more difficult.
The Python Package Index (PyPI) henceforth rejects file uploads to releases older than 14 days. The measure is intended to prevent compromised publishing tokens or workflows from retroactively poisoning older, stable versions.
PyPI has introduced a new upload restriction: files can no longer be uploaded to existing releases if they are older than 14 days. This protects older and stable version states in case the publishing credentials or CI/CD workflows of a project maintainer are compromised.
According to Seth Larson from the PyPI team, such an attack has not been documented to date. However, there is no technical reason preventing attackers from exploiting these attack vectors – it has rather been a matter of awareness and capability.
For CTOs and supply-chain managers, this represents an additional security layer in the Python ecosystem. Older dependencies are thus protected from retroactive tampering, even if access credentials are stolen in the short term. The measure addresses a fundamental supply-chain risk in the open packaging system.
Source: simonwillison.net · Published 23 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.