cd/entity/PyPI· home› entities› PyPI
grep -l @pypi /news/*.json | wc -l → 391

PyPI

mentions 391 type Organization page 1/20 feed RSS

// recent coverage 391 mentions

16:57
2026-10-02
dev.to
ai-agents

Running DeepAgents in a Docker Sandbox, with no cloud keys

A developer published a four-file Docker Sandbox Kit that packages the DeepAgents agent harness into an isolated microVM-style sandbox pre-wired to a local Docker Model Runner, letting the agent run w…

10:00
2026-10-02
safedep.io
ai-safety

An Attacker Hijacked an AI Coding Assistant to Spread a Worm

Security researchers reported in September 2026 that an attacker hijacked a live AI coding assistant session at a software company, causing the assistant to recommend a malicious PyPI package whose in…

13:56
2026-09-30
csoonline.com
ai-safety

Unsloth’s model picker had a code-execution problem

Pillar Security found that selecting a model in Unsloth Studio triggered the download and execution of Python code from the model repository, with researcher Ariel Fogel stating "Reading the model's c…

08:41
2026-09-30
dev.to
ai-agents

One Repo, One Package: How We Structure Code for AI Agents

A developer at Microwise AI outlined MWD (Microwise Development), a methodology that enforces one Git repository per package so AI coding agents work within concrete, easily scoped boundaries. To pres…

04:34
2026-09-30
pub.towardsai.net
ai-safety

What the LiteLLM Breach Teaches Us About Securing LLM Gateways

Two LiteLLM releases, 1.82.7 and 1.82.8, were published to PyPI with a credential stealer inside after attackers tracked as TeamPCP stole a PyPI publishing token via a compromised Trivy GitHub Action,…

08:53
2026-09-28
marimo.io
developer-tools

Pixi adds non-Python deps to Python notebooks

Marimo's notebook sandboxes now support Pixi, letting standalone notebooks record Conda and PyPI requirements alongside their code, the marimo team announced. The integration, built with the Pixi team…

07:34
2026-09-28
anas-security-portfolio.vercel.app
ai-agents

I found an SSRF in Google's official MCP Toolbox (CVE-2026-14540)

Google assigned CVE-2026-14540, a CVSS 8.0 server-side request forgery in its MCP Toolbox for Databases, where the HTTP client was initialized without a CheckRedirect policy or target IP validation, a…

22:21
2026-09-26
dev.to
ai-tools

AI Powered Git Commit Assistant

A developer built cmt-cli, an open-source command-line tool that analyzes staged Git changes and generates commit messages using OpenAI models, defaulting to gpt-4o-mini. The tool, installable from Py…

page 1 / 20 next →
// co-occurs with top 8 entities
// topics top 6 topics