5 hours ago
- PyPI is introducing a new 'Security' tab to centralize provenance and attestation metadata, with indicators for missing or changed provenance.
- Navigation will move from the sidebar to horizontal tabs, reserving the sidebar for metadata.
- The metadata sidebar will shift to the right, aligning the package description/readme on the left for better readability.
- Trust levels will be explicitly labeled to help users evaluate data source trustworthiness.
- Sidebar metadata will be reordered by utility, prioritizing links and freshness signals.
- Clearer status labeling with bolder colors will distinguish quarantined, yanked, archived, and pre-release states.
- Updates are visual only and require no action from maintainers; existing attestations will map automatically.
- The rollout has four phases: Project Details (live on TestPyPI), Files and Release History, Security Tab, and Documentation Refresh.
- Community feedback is welcome via GitHub issues, with detailed bug reports including browser and device info.
- The updates are based on user research and the OpenSSF style guide for attestations, with contributions from user interviews and a survey of 777 people.