• Sources: PyPI blog, HN 49007291
  • Summary: PyPI announced on 2026-07-22 that it now rejects uploads of new files (wheels, sdists) to any release older than 14 days. The change (patch merged 2026-07-08) is a supply-chain measure to stop old, long-stable releases from being poisoned if a project's publishing token or CI workflow is later compromised, following the early-2026 LiteLLM and Telnyx package incidents. There is no opt-out, and PyPI cautions the behavior is not yet a stable contract: formal "closed release" semantics and a staged-preview upload flow are planned through PEP 694 and an Upload 2.0 API.
  • Why it matters: It narrows the window in which a stolen credential can backfill a malicious artifact into a trusted, widely pinned release, at the cost of breaking late additions to older releases.
  • Follow-up: Watch for the PEP 694 staged-preview flow and any packaging workflows that break on the 14-day cutoff.

send feedback on this story