Another supply chain attack, this time on the "mistralai" Python package which is used by Pydantic AI ("mistralai>=2.0.0") and many others. PyPI has already quarantined the package, and it appears as though only version 2.4.6 was affected.

Luckily I've been using the new PDM lock feature: pdm lock --exclude-newer 7d, so I wasn't affected. Although I can't install pydantic-ai at the moment because mistralai is quarantined.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论