Skip to content

Security

Python’s package index has been the target of supply chain attacks for years. The handbook covers the modern defenses: Trusted Publishing, digital attestations, dependency cooldowns, hash pinning, vulnerability scanning, and lint rules that catch unsafe code patterns. Start with what a Python supply chain attack is if the vocabulary is new.

Supply chain defense

Control what gets installed

Scan and lint

More Security pages

Everything else tagged security, grouped by section. Pages featured above are not repeated here.

From the blog

Posts tagged security.

Last updated on