Studies / S5
Who publishes attestations on PyPI and npm — and who stopped?
Abstract
PEP 740 attestations let anyone check that a PyPI file was built by a named repository and workflow. Not attesting is the norm. We measured, on 2026-10-02:
- the full upload history of the 15,000 most-downloaded PyPI projects (hugovk's list of 2026-10-01);
- the publisher identity of every attested project (PyPI Integrity API);
- a 1,500-package npm sample.
Of the 14,995 projects we could analyse, 11,336 (75.6%) have never uploaded an attested file.
Adoption. The latest version is attested for 3,479 of 14,995 projects (23.2%), and for 31.1% of those whose latest version was first uploaded after 2024-10-01. By rank band:
| ranks | latest version attested |
|---|---|
| 1–100 | 59.0% |
| 10,001–15,000 | 20.3% |
Projects whose latest version is attested went from 4.0% (end of November 2024) to 23.2% (end of September 2026). We agree with Trail of Bits' Are we PEP 740 yet? on 359 of its 360 packages.
Projects that stopped. 148 projects uploaded an attested file and later released without one. For 138, the line pip installs had attestations and its latest version has none: 3.8% of the 3,659 projects that ever attested. By cause:
| cause | projects |
|---|---|
| tool or workflow change | 96 |
| one isolated release | 15 |
| restored after the latest release | 1 |
| unknown | 26 |
In 53 of the tool or workflow changes, the publishing workflow now runs uv publish with no attestation step. Examples, each backed by a commit in paper.md §5.3: fastapi, typer, fastmcp and supabase. Stopping is a change of release tooling, not a sign of compromise.
Publisher changes. At least 307 attested projects changed publisher. Of the 188 changes that cross repositories or publisher kinds:
- 160 are confirmed by public data;
- 16 are consistent with the project's own metadata;
- 12, in 5 projects, are not confirmed.
npm. 30.8% of the top 1,000 publish provenance; 4 of 459 packages that ever did (0.9%) stopped.
Prior work. The closest existing measurement is Trail of Bits' tracker, which covers the top 360 PyPI packages by latest release. This study adds the distribution beyond those 360, the history, the stops and their causes, and the publisher audit (paper.md §2).
Automation and review. AI agents ran the study and wrote the text. An independent AI reviewer checked it (paper.md §4.1).
Cite this study
EasyxLab (2026). Who publishes attestations on PyPI and npm — and who stopped? Study S5. EasyByte Hub S. Coop. Mad. https://github.com/easybytehub/easyxlab/tree/main/studies/s5-pypi-attestations@techreport{easyxlab_s5,
title = {Who publishes attestations on PyPI and npm — and who stopped?},
author = {{EasyxLab}},
institution = {EasyByte Hub S. Coop. Mad.},
number = {S5},
year = {2026},
url = {https://github.com/easybytehub/easyxlab/tree/main/studies/s5-pypi-attestations}
}