Quoting Seth Larson
PyPI now blocks file uploads to releases older than 14 days to prevent supply chain poisoning.
“there is no technical reason beyond that attackers weren't aware it was possible”
PyPI implemented a proactive security policy rejecting new file uploads to releases older than 14 days, closing a supply chain attack vector where compromised publishing tokens could poison stable, widely-trusted packages. No known abuse has occurred, making this a rare preemptive hardening move by a major package registry. Relevant to AI developers given Python's dominance in ML tooling, but not a direct AI industry signal.