Elektrine lite

← Feed

@miketheman@hachyderm.io

Post #3017151

2026-05-26 14:48 UTC

I wonder who I know that knows someone at HackerOne that can convey the message that PyPI explicitly disallows security research packages, and bans users who upload them. Put that in a notice to your users somewhere prominent - since it's become pervasive and a drain on resources. This also takes time away from legitimate security incident response - so it's a net negative for the world.

Replies (0)

No replies.