Seth Michael Larson(@sethmlarson) 's Twitter Profileg
Seth Michael Larson

@sethmlarson

@ThePSF Security Developer-in-Residence 🐍
PSF Fellow ✨ Minnesoootan, he/him

https://t.co/Bd3K7TNj7b

ID:722557924011184128

linkhttps://sethmlarson.dev calendar_today19-04-2016 22:50:08

7,3K Tweets

3,0K Followers

456 Following

William Woodruff (1.3.6.1.4.1.55738)(@8x5clPW2) 's Twitter Profile Photo

PyPI now has three new Trusted Publishing, thanks (in part) to our work at Trail of Bits! This realizes our goal of expanding Trusted Publishing to compute environments outside of GitHub Actions:

blog.pypi.org/posts/2024-04-…

account_circle
Python Package Index(@pypi) 's Twitter Profile Photo

Starting today, PyPI package maintainers can publish via Trusted Publishing from three additional providers:

- 🦊 GitLab
- Google Cloud
- ActiveState

They join GitHub Actions to support publishing without long-lived passwords or API tokens.

blog.pypi.org/posts/2024-04-…

account_circle
ActiveState(@ActiveState) 's Twitter Profile Photo

🎉 ActiveState is pleased to announce our inclusion as a Trusted Publisher to PyPI, enabling Python authors to securely publish Python packages directly via ActiveState’s Platform.

Become a trusted author today: ow.ly/Z34i50RikiO

account_circle
Seth Michael Larson(@sethmlarson) 's Twitter Profile Photo

An update on the release process, , and some thoughts on after talking about it with lots of folks.

sethmlarson.dev/security-devel…

account_circle
FFmpeg(@FFmpeg) 's Twitter Profile Photo

The xz fiasco has shown how a dependence on unpaid volunteers can cause major problems. Trillion dollar corporations expect free and urgent support from volunteers.

Microsoft MicrosoftTeams posted on a bug tracker full of volunteers that their issue is 'high priority'

The xz fiasco has shown how a dependence on unpaid volunteers can cause major problems. Trillion dollar corporations expect free and urgent support from volunteers. @Microsoft @MicrosoftTeams posted on a bug tracker full of volunteers that their issue is 'high priority'
account_circle
Python Software Foundation(@ThePSF) 's Twitter Profile Photo

The PSF is pleased to announce our participation in a new Open Initiative for Standards with Apache - The ASF and Eclipse Foundation to establish common specifications for secure development based on open source best practices
pyfound.blogspot.com/2024/04/new-op…

account_circle
Seth Michael Larson(@sethmlarson) 's Twitter Profile Photo

Sustainability is a security issue. Consumers only have demands for a burnt out maintainer and the only help that arrives has long-term malicious intentions.

robmensching.com/blog/posts/202…

account_circle
æva black(@aevavoom) 's Twitter Profile Photo

Worth a read. OSS maintainers have been raising alarms about a general lack of support (from their employers, communities, and users) for years.

Burnout is a security risk.

account_circle
Seth Michael Larson(@sethmlarson) 's Twitter Profile Photo

While I was away my article on unexpected behavior of '$' in regular expressions hit #1 on Hacker News (and I only discovered this fact by receiving hate mail).

If you missed it and use '$' in Python regular expressions you might be interested:

sethmlarson.dev/regex-%24-matc…

account_circle
Seth Michael Larson(@sethmlarson) 's Twitter Profile Photo

Back from vacation! 👋 I covered the CISA OSS Security Summit, Google Summer of Code 2024, SOSS Community Day NA in this weekly report:

sethmlarson.dev/security-devel…

account_circle