3 comments

  • binukajayaweera 18 hours ago
    the packages get flagged or escalated if its at a trust boundary for example if it parses, decodes or authenticates data that an attacker can influence and have either a known CVE or is basically unmaintained. Non trust boundary packages also get reported but not escalated. I welcome contributions to the repo to make it more useful. More info can be found in the readme and docs attached to it.
  • zahlman 9 hours ago
    Have you considered talking to PyPI staff about this?
    • binukajayaweera 58 minutes ago
      I dont know how I can reach them, I would love to get their feedback on this
  • ivo93 4 hours ago
    [flagged]