Wonder what the DoJ wants PyPI data for. <https://...
# random
b
Wonder what the DoJ wants PyPI data for. https://blog.pypi.org/posts/2023-05-24-pypi-was-subpoenaed/
Reddit's guess is malware in a package
One comment there noted that the phrase about how this subpoena didn't have an NDA might be suggestive that other subpoenas came in and DID have one
a
two days later, they make a post about removing IP data from their databases/systems. Get in.
b
Oh yeah that's not surprising. The Head on Infra said they'd be making changes based on this happening
a
b
What a clever new attack vector