Python
fromArtem Golubin
6 days agoPyPI packages are increasing rapidly
AI-driven growth has increased weekly PyPI package releases, while many new packages use eval/exec/subprocess in ways that can trigger malicious-code detection false positives.
The Eclipse Foundation today revealed it has created a framework for the Open VSX Registry, for tools based on open source VS Code that scan for known malicious patterns, detect namespace impersonation and extension name spoofing, flag exposed credentials or embedded secrets and quarantine suspicious uploads for review.