Preventing ZIP parser confusion attacks on Python package installers

Preventing ZIP parser confusion attacks on Python package installers

News
PyPI will reject malformed or ambiguous wheel ZIPs and begin enforcing RECORD consistency to prevent ZIP parser confusion attacks across Python installers.