Every Technerdo story filed under Pypi, newest first.
A popular open-source package with roughly 1 million monthly downloads was caught stealing credentials. Here is a practical supply-chain security checklist for developers and self-hosters.