Protestware & Sabotage 2022 Incident #16

atomicwrites deletion

Estimated Financial Impact
Minimal
Blast Radius
Protest against PyPI 2FA mandate

What Happened

A maintainer temporarily deleted the widely-used atomicwrites library from PyPI to protest PyPI mandating two-factor authentication for top-1% packages. The incident was reminiscent of left-pad and highlighted the tension between registry security mandates and volunteer maintainer autonomy.

○

Risk Guard: Partial

SOURCE_SINGLE_CONTRIBUTOR pre-existing; package availability risk

Risk Guard Check Codes That Flag This Incident

SOURCE_SINGLE_CONTRIBUTOR

How Every Tool Performed

0 Caught 1 Partial 5 Missed
Tool Verdict Details
OSS Risk Guard Partial SOURCE_SINGLE_CONTRIBUTOR pre-existing; package availability risk
Socket Missed Not detectable by package scanning
Snyk Missed No capability for this attack class
Sonatype (Nexus) Missed No capability for this attack class
Black Duck Missed No capability for this attack class
Endor Labs Missed No capability for this attack class
← node-ipc / peacenotwar es5-ext / styled-components →