TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

PyPI has completed its first security audit

137 pointsby mikethemanover 1 year ago

5 comments

lyu07282over 1 year ago
Link to the report: <a href="https:&#x2F;&#x2F;github.com&#x2F;trailofbits&#x2F;publications&#x2F;blob&#x2F;master&#x2F;reviews&#x2F;2023-09-pypi-warehouse-securityreview.pdf">https:&#x2F;&#x2F;github.com&#x2F;trailofbits&#x2F;publications&#x2F;blob&#x2F;master&#x2F;revi...</a><p>They seem to not have analysed client-side of PIP itself, but I suppose there isn&#x27;t anything you could say that isn&#x27;t already obvious to everyone.
评论 #38266780 未加载
mrbonnerover 1 year ago
My understanding reading the report is that the audit is for PyPI code and infrastructure itself and not the packages it hosts. Am I right?
评论 #38270691 未加载
thenerdheadover 1 year ago
Congrats! Thanks for trailblazing and being transparent to help other central registries follow.
the_common_manover 1 year ago
How much does an audit cost?
评论 #38267305 未加载
评论 #38267297 未加载
easylionover 1 year ago
Good to know. But how often are they going to do it ? Is it going to be an annual event from now on ?
评论 #38279813 未加载