Security incidents in the repositories PyPI and crates.io
The developers of the Python package index PyPI reported on a security issue with the implementation of the "Organization Team" feature, which allows the formation of a team of several developers working collaboratively on a project in PyPI. The essence of the identified issues is that privileges delegated to a user as a member of the "Organization Team" were retained even after the user was removed from the organization. The vulnerability in PyPI has been fixed […]
