// the find
pypi/warehouse
The Python Package Index
This is the actual code running pypi.org — Warehouse is the Pyramid-based web app and API that serves the Python Package Index. It's for people who want to see how a registry serving billions of downloads a month is actually built, or who are contributing to PyPA infrastructure directly.
The security posture is unusually mature for a web app repo: custom CodeQL queries (e.g. ReadPermissionPostEscalation.ql), ast-grep lint rules enforcing patterns like no-sqla-backref and safe db-flush usage, and zizmor scanning GitHub Actions workflows for injection risks. The blog under docs/blog is a real incident-report archive — actual post-mortems on account takeovers, phishing campaigns, and supply-chain attacks (litellm/telnyx), which is more honest engineering writing than most companies publish. Trusted Publishers (OIDC-based publishing) and PEP 740 attestations are implemented here first, so it's a reference implementation for anyone building similar supply-chain integrity features.
This is not a reusable registry template — it's wired directly to PyPI's specific infrastructure (Fastly, AWS, RSTUF/TUF signing keys checked into dev/rstuf/keys, specific SES/email plumbing), so forking it to run your own package index means ripping out a lot of PyPI-specific assumptions first. The dev environment is heavy: docker-compose with OpenSearch, Postgres, and RSTUF services just to get running locally. Dependency management is sprawling — nine separate requirements files (deploy, dev, docs-blog, docs-dev, docs-user, ipython, lint, main, tests) which makes it harder to reason about what's actually needed for a given task. There's a legacy-application-structure doc still in the docs, meaning some of the codebase is acknowledged architectural debt rather than the target design.