
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
setuptools
Advanced tools
pypi-version py-version test-badge ruff-badge docs-badge skeleton-badge codecov-badge discord-badge
See the Quickstart and the User's Guide for instructions on how to use Setuptools.
Questions and comments should be directed to GitHub Discussions. Bug reports and especially tested patches may be submitted directly to the bug tracker.
Everyone interacting in the setuptools project's codebases, issue trackers, chat rooms, and fora is expected to follow the PSF Code of Conduct.
Available as part of the Tidelift Subscription.
Setuptools and the maintainers of thousands of other packages are working with Tidelift to deliver one enterprise subscription that covers all of the open source you use.
FAQs
Most extensible Python build backend with support for C/C++ extension modules
The pypi package setuptools receives a total of 216,083,061 weekly downloads. As such, setuptools popularity was classified as popular.
We found that setuptools demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.