Python Package Index Profile
Python Package Index

@pypi

20,674
Followers
11
Following
42
Media
357
Statuses

The Python Package Index (PyPI) is the repository of software for the Python programming language. Pronounced 🥧 🫛 👁️

The Cloud
Joined September 2017
Don't wanna be here? Send us removal request.
@pypi
Python Package Index
1 year
Python 3.11 delivers.
Tweet media one
32
495
3K
@pypi
Python Package Index
2 years
Today we received reports of a phishing campaign targeting PyPI users. This is the first known phishing attack against PyPI. We’re publishing the details here to raise awareness of what is likely an ongoing threat.
18
518
788
@pypi
Python Package Index
2 years
We’ve begun rolling out a 2FA requirement: soon, maintainers of critical projects must have 2FA enabled to publish, update, or modify them. To ensure that these maintainers can use strong 2FA methods, we're also distributing 4000 hardware security keys!
16
209
687
@pypi
Python Package Index
2 years
Incident report on malicious takeover of ctx package on PyPI has been published. Read details, mitigation, analysis, and more at
8
124
219
@pypi
Python Package Index
6 years
Welcome to the home of on twitter! You can follow here for announcements about the package index as well as interesting things going on in the Python packaging ecosystem.
0
111
181
@pypi
Python Package Index
1 year
New user and new project registrations on PyPI are temporarily suspended. See details at
4
56
160
@pypi
Python Package Index
6 months
We are proud to announce that we have completed PyPI's first external security audit.
1
34
164
@pypi
Python Package Index
6 years
PyPI will no longer accept passwords that have been published in data breaches. For background you can take a look at . For high level overview see Finally if you have any trouble, please file an issue at
1
90
164
@pypi
Python Package Index
2 years
In total PyPI served 324.1 petabytes in 2021, that's an average bandwidth of 82.2 Gbps for the entire year. We and the entire Python community owe @fastly immense gratitude for providing this CDN service, their support makes PyPI as you know it possible.
@pypi
Python Package Index
2 years
Second question! How much bandwidth does it take to serve 126,545,477,066 downloads in a year?
8
12
58
4
29
153
@pypi
Python Package Index
2 years
Thank you @IBMDeveloper for supporting PyPI. Through sponsorships and grants, @thePSF raised over $300,000 for PyPI’s use. Let’s keep that momentum going!
7
22
133
@pypi
Python Package Index
2 years
The answer is: One hundred twenty-six billion five hundred forty-five million seven hundred seventy thousand and sixty-six downloads accounted for in 2021. 126,545,477,066 Thanks @googlecloud BigQuery for making it possible for us to track this scale.
@pypi
Python Package Index
2 years
Without phoning a friend (or querying the world wide web)... How many downloads do you think PyPI served in 2021?
23
10
71
7
35
124
@pypi
Python Package Index
1 year
The PSF was subpoenaed for the first time in March/April 2023 for for PyPI user data. Read our transparency blog post here:
5
56
112
@pypi
Python Package Index
2 years
With one week left in our security key giveaway, we've decided to open up eligibility to any existing PyPI user. Get yours while supplies last, and before the giveaway ends when the codes expire on Oct 1st.
13
74
109
@pypi
Python Package Index
1 year
Starting today, PyPI package maintainers can adopt a new, more secure publishing method that does not require long-lived passwords or API tokens to be shared with external systems.
2
34
104
@pypi
Python Package Index
3 years
We want to thank @ryotkak for identifying and responsibly disclosing three PyPI security vulnerabilities per . You can read our analysis and mitigation here: 1️⃣ 2️⃣ 3️⃣
2
27
97
@pypi
Python Package Index
3 years
Thanks to @Ewjoachim , we are now integrated with the @github Secret Scanning service. When users make a mistake and publish PyPI API tokens to GitHub they will automatically be revoked with notification. You can read more at and
Tweet media one
1
35
101
@pypi
Python Package Index
2 years
The PSF conducted three surveys to gather community requirements that would drive future development. The feedback summary is available on @ThePSF 's blog:
1
31
93
@pypi
Python Package Index
1 year
Today, we are rolling out the first step in our plan to build financial support and long-term sustainability, while simultaneously giving our users one of our most requested features: organization accounts.
4
40
91
@pypi
Python Package Index
3 years
We are seeking some additional quick feedback after an initial round of outreach to teams using PyPI! If you use PyPI as a team, please respond to the poll linked from
2
47
84
@pypi
Python Package Index
2 years
We have additionally determined that some maintainers of legitimate projects have been compromised, and malware published as the latest release for those projects. These releases have been removed from PyPI and the maintainer accounts have been temporarily frozen.
2
28
83
@pypi
Python Package Index
3 years
Our CDN is currently experiencing a major outage, we've confirmed that our backends are up and healthy, and will update when we have more information.
11
22
84
@pypi
Python Package Index
2 years
Background: the phishing message claims that there is a mandatory ‘validation’ process being implemented, and invites users to follow a link to validate a package, or otherwise risk the package being removed from PyPI.
Tweet media one
4
19
78
@pypi
Python Package Index
1 year
PEP 658 has finally landed on PyPI! Wheels uploaded as of about 15 minutes ago now have the appropriate information served from the simple APIs, and METADATA files available on .
2
15
75
@pypi
Python Package Index
1 year
Thanks to @awscloud , @ThePSF is hiring for a Safety and Security Engineer focused on PyPI! Read about how the role will be funded, what will be worked on, and how to apply at
0
31
72
@pypi
Python Package Index
2 years
Without phoning a friend (or querying the world wide web)... How many downloads do you think PyPI served in 2021?
23
10
71
@pypi
Python Package Index
2 years
Note that PyPI will NEVER remove a valid project from the index. PyPI only removes projects which violate our TOS or are in some way determined to be harmful (e.g., malware).
1
6
69
@pypi
Python Package Index
2 years
We're grateful that @fastly has served PyPI with free services since May 2013 and are excited to be part of their new initiative Fast Forward ⏩ which aims to empower everyone to build the good, open internet. Read more here:
@FastlyDevs
Fastly Devs
2 years
📣Announcing Fast Forward ⏩ the next phase in our commitment to making the internet a better place. 🧵
1
5
22
4
19
69
@pypi
Python Package Index
2 years
Second question! How much bandwidth does it take to serve 126,545,477,066 downloads in a year?
@pypi
Python Package Index
2 years
The answer is: One hundred twenty-six billion five hundred forty-five million seven hundred seventy thousand and sixty-six downloads accounted for in 2021. 126,545,477,066 Thanks @googlecloud BigQuery for making it possible for us to track this scale.
7
35
124
8
12
58
@pypi
Python Package Index
3 years
We truly appreciate @Google for demonstrating their support of PyPI by becoming a Visionary sponsor this year. Their generosity ensures that we can improve and sustain PyPI for many generations to come.
Tweet media one
0
8
66
@pypi
Python Package Index
2 years
In light of yesterday’s phishing attack, we have updated the eligibility requirements for our security key giveaway. Any maintainer of a critical project, regardless of whether they already have TOTP-based 2FA enabled, is now eligible:
3
29
65
@pypi
Python Package Index
3 years
We want to hear from companies and community projects using PyPI as a team! If your team wants to contribute to helping us set a course for new features, read and register your interest!
6
31
61
@pypi
Python Package Index
8 months
We’ve been behind @fastly for ten and a half years! Thanks for a decade of support and for having us at #altitude2023 !
0
15
62
@pypi
Python Package Index
2 years
Big thanks and a shoutout to @AWSOpen for providing credits to operate our backends on @awscloud since the re-launch on the warehouse codebase in 2018.
2
11
55
@pypi
Python Package Index
2 years
The link takes the user to a phishing site mimicking PyPI’s login page, which steals any credentials entered. We are unable to determine whether the phishing site was designed to relay TOTP-based two-factor codes. Accounts protected by hardware security keys are not vulnerable.
Tweet media one
2
9
55
@pypi
Python Package Index
2 years
We've published an incident report for the JSON API redirect loop outage today: We understand the frustration, but are excited that on the other side of this outage PyPI is more cachable, performant, and reliable; dropping ~25rps from our backends.
Tweet media one
3
7
55
@pypi
Python Package Index
1 year
now enforces that users with 2FA enabled must use an API token or Trusted Publisher configuration in place of their passwords. Read the announcement and details at:
2
23
53
@pypi
Python Package Index
2 years
The malicious releases follow a similar pattern, again using linkedopports[dot]com. At this time, the malicious releases that we are aware of are: - exotel==0.1.6 - spam==2.0.2 and ==4.0.2 We’ve additionally taken down several hundred typosquats that fit the same pattern.
Tweet media one
4
11
52
@pypi
Python Package Index
1 year
Happy Friday! It has been a busy week on our blog, but we're wrapping it up with an update on some of the work that's been going on in the background lately to ensure the privacy and security of PyPI users:
3
13
51
@pypi
Python Package Index
7 months
🔉 Python for your ears alert! Our PyPI Safety & Security Engineer @mikefiedler sat down with @ @mkennedy last month for a fun conversation on the Talk Python podcast. Listen in to what he had to say at or wherever you get your podcasts :)
3
17
45
@pypi
Python Package Index
1 year
Just one day left to apply for the posted PyPI Safety and Security Engineer role! Read our post announcing it at: Apply here:
1
19
45
@pypi
Python Package Index
5 years
PyPI has now supports internationalization thanks to @OpenTechFund ! We’re ready for translations to begin at and appreciate @WeblateOrg for providing their service. Run into issues or have questions, head over to and let us know.
1
26
46
@pypi
Python Package Index
2 years
Finally, if you believe you’ve received a phishing email, please contact security @pypi .org with details about the sender email address and URL of the malicious site to help us respond to this issue. And thanks to everyone who reported this attempt!
1
9
45
@pypi
Python Package Index
2 years
In order to prevent phishing attacks from succeeding, enable 2FA, ideally using hardware security keys or WebAuthn two-factor authentication: PyPI is currently offering free hardware keys for maintainers of the top 1% of projects:
1
4
44
@pypi
Python Package Index
2 years
We are grateful for @anacondainc 's support of PyPI as a Contributing sponsor of @thePSF . Sponsorship funds not only help us maintain what we have but will also help us with future improvements!
Tweet media one
3
8
45
@pypi
Python Package Index
2 years
Who's eligible? Project eligibility is based on downloads: any project in the top 1% of downloads over the prior 6 months is designated as critical (as well as PyPI's own dependencies). Today, we’ve notified maintainers of those projects via email. But that's not all!
2
6
43
@pypi
Python Package Index
2 years
We truly appreciate @Google for demonstrating their support of PyPI by becoming a Visionary sponsor. Their generosity ensures that we can improve and sustain PyPI for many generations to come!
Tweet media one
0
5
42
@pypi
Python Package Index
2 years
PS: If you're trying to redeem your code and getting 'Promo code doesn't apply', increase your quantity in the cart from 1 key to 2 keys! Our intention is for everyone to be able to have a secondary backup key in addition to their primary key.
1
6
39
@pypi
Python Package Index
2 years
To verify that you’re not entering credentials in a phishing site, confirm that the URL in the address bar is and that the site’s TLS certificate is issued to . Additionally, consider using a browser-integrated password manager.
Tweet media one
1
6
37
@pypi
Python Package Index
2 years
How to protect yourself: If you believe you may have entered credentials on a phishing site: - reset your password - reset your 2FA recovery codes - review and for suspicious activity
1
8
36
@pypi
Python Package Index
2 years
What we’re doing: We’re actively reviewing reports of new malicious releases, and ensuring that they are removed and the maintainer accounts restored. We’re also working to provide security features like 2FA more prevalent across projects on PyPI.
3
2
35
@pypi
Python Package Index
2 months
PyPI now has an improved way to report #malware , via #PyPI itself! Available on web and preview beta API. Learn more and sign up to help test:
5
12
35
@pypi
Python Package Index
2 years
Ensuring that the most widely used projects have these protections against account takeover is one step towards our wider efforts to improve the general security of the Python ecosystem for all PyPI users. You can track our progress on our dashboard:
1
5
35
@pypi
Python Package Index
6 years
First order of business! If you haven't verified your email on PyPI, head over to to complete the process!
1
25
33
@pypi
Python Package Index
2 years
🐍📦✨Python people! We want *your* feedback on Python Packaging! Please help us by responding to our survey @ Please RT for reach! 🐍📦✨
0
21
36
@pypi
Python Package Index
2 years
We've finally resolved the issues with our data pipeline that feeds our public dataset documented at Note: If you are currently consuming from the `the-psf` dataset, you should migrate to the `bigquery-public-data` dataset and reprocess 2021-11-23 onward
1
7
33
@pypi
Python Package Index
2 years
We've also enabled a feature that will allow any project to opt-in to a 2FA requirement for its maintainers: this can be enabled in the settings for each individual project. This can be enabled/disabled for non-critical projects at any time.
2
3
33
@pypi
Python Package Index
1 year
Today's a wonderful day to remind you that we are not two π in a trench coat, but a Pie Pea Eye. Please sign this petition to bring our dreams of the pea emoji to life so we can fully emojify our name.
@mariatta
Mariatta 🤦
2 years
🙊 Did you just say "pie-pie"? 🤔 Did you mean to say "pie-pea-eye" instead? ℹ️ PyPI 🗣 Pie - pea - eye 📖 The Python Packaging Index 🔗 ℹ️ PyPy 🗣 Pie - Pie 📖 An alternative Python implementation 🔗 👋 kthxbai
13
44
173
2
3
33
@pypi
Python Package Index
1 year
In support of The PSF's mission, we are hiring for an engineering role that will focus on improving the safety and security of the Python Package index. This role will have shared ownership of key security & safety features with senior maintainers.
1
16
31
@pypi
Python Package Index
2 years
When credentials are entered on the phishing site sites[dot]google[dot]com/view/pypivalidate, the data is sent to a URL on the domain linkedopports[dot]com.
2
1
30
@pypi
Python Package Index
5 years
This excellent tip from @oscar_mcm is now reliably implemented. Classifiers beginning with “Private ::” are now disallowed from even existing in PyPI’s database.
0
19
31
@pypi
Python Package Index
3 months
Looking back at 2023 @mikefiedler discovered some impressive metrics that we want to share! @fastly #PyPI #pytho
Tweet media one
2
10
31
@pypi
Python Package Index
3 years
Come help improve the Python packaging ecosystem! This is a *paid* full-time role with @ThePSF that will include project management on PyPI!
@ThePSF
Python Software Foundation
3 years
With the support of our newest Visionary sponsor, @TechAtBloomberg , we are excited to be hiring a Project Manager for the Python packaging ecosystem. Read more about position, it's goals, and how it came to fruition at
4
58
140
0
25
30
@pypi
Python Package Index
2 years
Our security key giveaway has concluded, and as a result: >400 unique projects chose to require 2FA >1600 hardware keys were distributed >3000 new users turned on 2FA And as of today, more than 31,000 users on PyPI have 2FA enabled, up from 28K when we started. 🎉
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
4
29
@pypi
Python Package Index
2 years
You can now include mathematical expressions in your rST or Markdown project description on @pypi . Example here: Thanks to @pypi contributor @mikefiedler for implementing this!
Tweet media one
Tweet media two
0
8
30
@pypi
Python Package Index
3 years
We truly appreciate @RedHat for demonstrating their support of PyPI by becoming a Contributing sponsor. Their generosity ensures that we can improve and sustain PyPI for many generations to come.
Tweet media one
0
3
28
@pypi
Python Package Index
3 years
Support for non-SNI clients will end the week of May 3rd. As that date approaches, in order to ensure users are aware and have time to upgrade/fix/test non-SNI clients will experience rolling brownouts starting today. See the timetable and details at
0
12
27
@pypi
Python Package Index
3 years
Support from organizations like @PrefectIO help keep PyPI running and allow us to continually keep improving it. Thank you!
0
2
27
@pypi
Python Package Index
4 years
Does your company rely on PyPI? This new sponsorship program from @ThePSF will build a more sustainable PyPI for the whole community and fund improvements to the entire packaging ecosystem. Read the full announcement at
0
33
27
@pypi
Python Package Index
2 years
We're so grateful to @AWSOpen for their support of PyPI as a Sustainability sponsor of @ThePSF ! Sponsors like you help us build a more sustainable PyPI for the whole community and fund improvements to the entire packaging ecosystem. Thank you!
Tweet media one
0
2
27
@pypi
Python Package Index
2 years
We have additionally determined that the 'deep-translator' project was compromised and deep-translator==1.8.5 was a malicious release.
@pypi
Python Package Index
2 years
The malicious releases follow a similar pattern, again using linkedopports[dot]com. At this time, the malicious releases that we are aware of are: - exotel==0.1.6 - spam==2.0.2 and ==4.0.2 We’ve additionally taken down several hundred typosquats that fit the same pattern.
Tweet media one
4
11
52
1
12
26
@pypi
Python Package Index
8 months
🎉
Tweet media one
0
4
24
@pypi
Python Package Index
2 years
We truly appreciate @linode for demonstrating their support of PyPI by becoming a Supporting sponsor. Their generosity ensures that we can improve and sustain PyPI for many generations to come!
0
1
27
@pypi
Python Package Index
5 years
Thanks to the @OpenTechFund , in addition to TOTP we now support Two-Factor Authentication via the WebAuthn standard! If you have a U2F compatible security key, you can use the feature in beta starting today! Read more about this and what's to come at
1
13
24
@pypi
Python Package Index
6 years
It's easy to miss important announcements in the whirlwind of social media! If you want to be sure to see important announcements regarding changes to PyPI, we recommend subscribing to our low-volume announcement list at
0
19
25
@pypi
Python Package Index
1 year
Thanks to @AWSOpen !
@AWSOpen
AWS Open Source
1 year
We are pleased to announce that @awscloud is the first Python Package Index (PyPI) Security Sponsor for @ThePSF . AWS is providing funding to the Python Software Foundation to hire a full-time Safety and Security Engineer for PyPI. #PyConUS #PyConUS2023
Tweet media one
0
66
289
0
2
24
@pypi
Python Package Index
2 years
Get paid to work on PyPI! One week left to submit your proposal!
@ThePSF
Python Software Foundation
2 years
We are hiring two contract developers to build organization accounts for @PyPI . This is a unique opportunity to flex your skills and develop next-gen features for PyPI. More details at
4
103
183
1
22
25
@pypi
Python Package Index
2 years
Another oddball stat to kick your weekend off. The PyPI service was deployed 342 times, our quietest year for deploys since 2018 relaunch, there have been 2714 deploys of the "new" codebase total.
2
4
24
@pypi
Python Package Index
2 years
We are grateful for @TechAtBloomberg 's support of PyPI as a Visionary sponsor of @thePSF . Sponsorship funds not only help us maintain what we have but will also help us with future improvements! #thankyou
Tweet media one
0
2
21
@pypi
Python Package Index
2 years
Thank you @realpython for supporting PyPI. Through sponsorships and grants, @thePSF raised over $300,000 for PyPI’s use. Let’s keep that momentum going!
0
0
19
@pypi
Python Package Index
2 years
We are grateful for @nvidia 's support of PyPI as a Sustainability sponsor of @thePSF . Sponsorship funds not only help us maintain what we have but will also help us with future improvements!
Tweet media one
0
2
20
@pypi
Python Package Index
2 years
Thank you @Docker for supporting PyPI. Through sponsorships and grants, @thePSF raised over $300,000 for PyPI’s use. Let’s keep that momentum going!
0
4
18
@pypi
Python Package Index
5 months
TestPyPI () now requires 2FA for all users to perform management actions. This comes ahead of January 1, 2024 when the same requirement will be applied to all users of PyPI (). Read more at
4
3
16
@pypi
Python Package Index
2 years
We truly appreciate @RedHat for demonstrating their support of PyPI as a Contributing sponsor. Their generosity ensures that we can improve and sustain PyPI for many generations to come!
Tweet media one
0
4
16
@pypi
Python Package Index
3 years
Thank you to @realpython for financially supporting PyPI through @thePSF ’s sponsorship program. Every sponsorship has an impact on PyPI’s sustainability and maintenance. Considering being a sponsor? Email sponsors @python .org
1
0
17
@pypi
Python Package Index
3 years
Support from organizations like @elastic help keep PyPI running and allow us to keep improving it continually. Thank you!
0
4
17
@pypi
Python Package Index
2 years
Only one day left to get your keys:
@ucodery
μCodery
2 years
Whoo! Thanks for the keys @pypi time to change my packages’ security
Tweet media one
0
2
7
0
3
16
@pypi
Python Package Index
2 years
Huge thank you to @pythonanywhere for sponsoring PyPI! Does your company rely on PyPI? @thePSF ’s sponsorship program aims to build a more sustainable PyPI for the whole community and fund improvements to the entire packaging ecosystem
0
3
15
@pypi
Python Package Index
11 months
PEP 715, deprecating bdist_egg/.egg uploads to PyPI has been accepted. We'll begin the process of implementing this today.
1
1
16
@pypi
Python Package Index
2 years
@pypi
Python Package Index
2 years
The answer is: One hundred twenty-six billion five hundred forty-five million seven hundred seventy thousand and sixty-six downloads accounted for in 2021. 126,545,477,066 Thanks @googlecloud BigQuery for making it possible for us to track this scale.
7
35
124
1
0
14
@pypi
Python Package Index
4 years
Have you built something interesting using the PyPI Big Query public dataset? Drop us a line at bigquery-feedback @pypi .org. We'd like to preview some upcoming changes and maybe feature your project in the announcement.
0
11
15
@pypi
Python Package Index
2 years
And yeah, we deploy on Fridays.
2
2
15
@pypi
Python Package Index
3 years
Our CDN provider has opened an incident and we are following along with their updates.
3
1
15
@pypi
Python Package Index
3 years
We truly appreciate @techatbloomberg for demonstrating their support of PyPI by becoming a Visionary sponsor of @thePSF . Their generosity ensures that we can improve and sustain PyPI for many generations to come.
Tweet media one
0
3
15
@pypi
Python Package Index
1 year
Thanks to @AWSOpen for providing the funding to support this role as our first Security Sponsor, including a continued investment in long-term credits and support for PyPI infrastructure! #PyConUS2023
Tweet media one
0
3
14
@pypi
Python Package Index
1 year
If our tweet yesterday was a little sparse on detail... Dawn has you covered.
@BajoranEngineer
mastodon.online/@bajoranengineer
1 year
So @PyPI has upgraded to 3.11 and we all get to benefit from the performance bump! 🚀 I talked about it on my *first* #techtok from vacation 🏝 🐍 #snaketok
4
15
26
0
7
15