
Security News
GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.
packaging
Advanced tools
Reusable core utilities for various Python Packaging interoperability specifications.
This library provides utilities that implement the interoperability specifications which have clearly one correct behaviour (eg: 440) or benefit greatly from having a single shared implementation (eg: 425).
The packaging project includes the following: version handling, specifiers,
markers, requirements, tags, metadata, lockfiles, utilities.
The documentation provides information and the API for the following:
Use pip to install these utilities
pip install packagingThe packaging library uses calendar-based versioning (YY.N).
If you run into bugs, you can file them in our issue tracker.
You can also join discussions on GitHub Discussions to ask questions or get involved.
Everyone interacting in the packaging project's codebases, issue trackers, chat rooms, and mailing lists is expected to follow the PSF Code of Conduct.
The CONTRIBUTING.rst file outlines how to contribute to this project as
well as how to report a potential security issue. The documentation for this
project also covers information about project development and security.
Please review the CHANGELOG.rst file or the Changelog documentation for
recent changes and project history.
FAQs
Core utilities for Python packages
The pypi package packaging receives a total of 348,238,080 weekly downloads. As such, packaging popularity was classified as popular.
We found that packaging demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.