PyPI has begun rejecting uploads of new files to package releases more than 14 days old, a security change designed to make it harder for attackers to poison long-stable versions after compromising a project's publishing token or CI workflow. The policy was driven in part by supply-chain incidents involving the LiteLLM and Telnyx packages, whose March 2026 compromises were tied to a mutable reference in the Trivy GitHub Action.
PyPI maintainers said the operational impact should be limited: analysis found that only 56 of the top 15,000 packages uploaded a Python 3.14-compatible wheel more than 14 days after the original release. The approach gained support during discussions around PEP 740 and at the 2026 Packaging Summit, where participants favored publishing a new package version instead of modifying an older release; the implementation by Seth Larson was merged on July 8.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
At the 2026 Packaging Summit at PyCon US 2026, PyPI maintainers and community participants concluded it was acceptable to require projects to publish a new version rather than add files to older releases. The discussion built support for a 14-day cutoff on new file uploads.
PyPI announced that it now rejects uploads of new files to package releases older than 14 days to reduce the risk of attackers poisoning long-stable releases after a compromise. Maintainers said analysis suggested the operational impact would be limited.
A patch implementing PyPI's new rule to reject uploads of new files to releases older than 14 days was merged on July 8, 2026. Seth Larson implemented the change.
In March 2026, the LiteLLM and Telnyx package compromises highlighted a supply-chain risk tied to a mutable reference in those projects' use of the Trivy GitHub Action. PyPI later cited these incidents as a motivator for tightening release upload rules.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.