Skip to content

Publish a list of malicious packages that have been taken down #4703

Open
@di

Description

@di

What's the problem this feature will solve?
Users who may have possibly installed malicious packages don't have insight into what packages have been taken down by PyPI administrators.

Describe the solution you'd like
PyPI should publish both a human-readable and machine-readable (API) list of malicious packages that have been taken down. Ideally the human-readable list would be sortable by package name, or by the date it was created/taken down.

Additional context
Feature request to automatically uninstall packages via this API in pip: pypa/pip#5777

Metadata

Metadata

Assignees

No one assigned

    Labels

    APIs/feedsfeature requestmalware-detectionIssues related to automated malware detection.needs discussiona product management/policy issue maintainers and users should discuss

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions