I’ve been building out a PyPi proxy to try and protect against these use-cases: https://artifiction.io
Explicit allow-lists and policies such as requiring "greater than X downloads per week" go a pretty long way to filtering out malicious packages.
Explicit allow-lists and policies such as requiring "greater than X downloads per week" go a pretty long way to filtering out malicious packages.
No comments yet.