Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Mike Fiedler, Code Gardener

@miketheman@hachyderm.io
mastodon 4.7.3
  • Open on hachyderm.io

#Security on @pypi@fosstodon.org for @ThePSF@fosstodon.org. Pyoneer 🐍

Wrangler of the Unusual, Roller Derby referee. AWS Hero.
Pronouns: he/him

730 Followers
376 Following
36 Posts
Joined November 18, 2022
GitHub:
https://github.com/miketheman
Blog:
https://www.miketheman.net/
Links:
https://miketheman.dev
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 4mo ago

Finally home. Seven speaking spots across seven days, three conferences in two states, many miles apart.
Now some rest.
#PyConUS #OSSummit #OpenSSFCommunity

hachyderm.io
27
0
3
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 4mo ago

I wonder who I know that knows someone at HackerOne that can convey the message that PyPI explicitly disallows security research packages, and bans users who upload them. Put that in a notice to your users somewhere prominent - since it's become pervasive and a drain on resources.
This also takes time away from legitimate security incident response - so it's a net negative for the world.

24
2
34
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 6mo ago

Any time I see something like this in a #Python REPL, I can't help but smile for two reasons:

1. Yes, yes I did forget.
2. I know some of the folks who worked so hard to make that message do exactly what I want it to do. Thanks to Pablo, @ambv@mastodon.social, and so many others!

#OpenSource

hachyderm.io

Hachyderm.io

33
2
6
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 4mo ago

One behavioral modification of doing career switches between individual contributor and manager (and back!) is that manager-speak trains you to use "we" when referring to the work your team has accomplished, since it's not "you" per se - giving credit where credit is due

The problem is when you then work somewhere as a team-of-one, like #PyPI #Security. It's astonishing how many folks think there's a whole team here, when it's just me for the past 3 years.

I will endeavor to update my verbiage accordingly to prevent further misperceptions

hachyderm.io
12
3
1
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 5mo ago

RE: @pypi@fosstodon.org

It's still awesome to me that I get to work on some really hard problems for the common good. This was a lot of work, hope you enjoy the read!

fosstodon.org
15
2
8
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 2mo ago
Replying to
@simon@fedi.simonwillison.net it's giving rubocop circa 2013 vibes
2
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 10mo ago

There's a nasty #OpenSource #SupplyChain worm going around named Shai-Hulud. It's also capable of exposing some projects' long-lived PyPI API Tokens. Read more on what's happening, and what you can do to protect your projects.

TL,DR: Adopt Trusted Publishing 🔐🚀📦

https://blog.pypi.org/posts/2025-11-26-pypi-and-shai-hulud/

hachyderm.io

Hachyderm.io

24
6
41
1
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 4mo ago

What do I do on a day off? Spend time on non-security work, refactoring #OpenSource projects to try a new idea I had.

Sometimes it's really hard to turn the brain off...

hachyderm.io

Hachyderm.io

5
0
1
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 4mo ago

@AlSweigart@mastodon.social here's a bad one:
"Free apps" == "fapps"

4
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 6mo ago

Publishing projects to PyPI without a source distribution, links to a source codebase, or other indications of "what might be in this binary package"? is definitely a smell to me when I'm evaluating which projects I want to rely upon.

So many projects advertise an #OpenSource License like MIT and Apache-2.0 and do not supply any sources in the "obvious" spots.

hachyderm.io

Hachyderm.io

8
0
5
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 4mo ago

If you're attending #PyConUS and want to find me, I'm likely to be found:
- Thursday evening Reception, PSF Booth
- Friday afternoon, Packaging Summit
- Saturday, before lunch, #Security Track
- Saturday, after lunch, Maintainers Summit
- Sunday morning, Keynote Stage, Update from Security Engineers

Find these and more on the PyCon US Mobile app. Pro Tip: sign in with your registration details to favorite sessions: https://us.pycon.org/2026/attend/onsite-information/#:~:text=PyCon%20US-,Mobile%20App,-Conference%20information%20on

Lots of links:
- https://us.pycon.org/2026/events/opening-reception/
- https://us.pycon.org/2026/schedule/presentation/74/
- https://us.pycon.org/2026/schedule/talks/#May16
- https://us.pycon.org/2026/events/maintainers-summit/#schedule

hachyderm.io
4
2
3
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 7mo ago

I really liked this notice that the @biomejs@fosstodon.org maintainers put in one of their discussions on GitHub. Hopefully folks read it, sadly I suspect the abusers won't

#OpenSource #Maintainer #Sustainability

hachyderm.io

Hachyderm.io

7
0
1
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 11mo ago

Does your org run a self-managed version of GitLab and publish your own #Python packages to @pypi@fosstodon.org ?

If you want to try out an alpha of Trusted Publishing for GitLab Self-Managed instances, let me know via DM - I'm collecting interest now, and should have something to show soon.

hachyderm.io

Hachyderm.io

15
8
22
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 7mo ago

Whoa. Cool

7
2
1
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 14mo ago

Incident Report of the recent #PyPI Phishing Campaign

TL,DR:
• PyPI was not breached
• PyPI users were targeted with phishing emails
• A single project saw uploads with malicious code and those releases have been removed

https://blog.pypi.org/posts/2025-07-31-incident-report-phishing-attack/

#Python #OpenSource #Security

hachyderm.io
19
0
31
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 4mo ago

RE: @andrewnez@mastodon.social

Excellent blog on the turducken problem of package managers

mastodon.social
2
0
1
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 5mo ago
Replying to
@bagder@mastodon.social you're lucky. I got 30+ yesterday. 1 was kind of credible. The others were effectively documented behaviors of projects. There's still little to no consequences for wasting time - I've been thinking about the "name and shame" approach you have, maybe that helps change the behavior?
3
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 6mo ago
Replying to
@glyph@mastodon.social that sounds like a very cool idea
3
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 7mo ago

RE: @pypi@fosstodon.org

Thanks
@fastlydevs@mastodon.social for taking some time to ask me questions and share my responses - it's quite unique to work on a system like this

fosstodon.org
4
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 9mo ago

RE: @sustainoss@hachyderm.io

This is a great podcast that discusses some of the details by @lorenipsum@fosstodon.org and @BajoranEngineer@mastodon.online on @ThePSF@fosstodon.org 's rejection of the NSF grant conditions.
"We are ALL spine 🐍 " --Loren

hachyderm.io
6
0
7
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 6mo ago
Replying to
@bagder@mastodon.social congratulations!
2
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 6mo ago

Pro tip: If you use @ohmyzsh@mstdn.social #python plugin, AND use https://starship.rs/ for prompt decorations, AND set `PYTHON_AUTO_VRUN=true` to automatically activate a virtualenv when you enter a directory, you may see your starship prompt lose it's style when navigating away in certain circumstances.

The fix is to tell the python plugin to leave the prompt alone since starship will handle it with:
`VIRTUAL_ENV_DISABLE_PROMPT=1`
in your .zshrc

#shell

hachyderm.io

Hachyderm.io

2
0
3
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 6mo ago

There are many problems with trust-based systems.
We can add all the cryptographic proofs we want, all the monitors and witnesses, but ultimately if the end-consumer doesn't understand well enough how these layers add trustworthiness, they won't trust the trust system itself, much less the original system.
So we're back to where we started, but we added piles of complexity, ossification of protocols and interchanges.

Ultimately, you kind of have to trust someone or something else. How much you trust them, understanding the risks associated with said trust, are all critical to reduce risks.

2
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 7mo ago
Replying to
@fallenhitokiri@social.screamingatmyscreen.com I probably didn't need to link/quote OSI here. PyPI policies already disallow obfuscated code, I linked to the OSI definition since it was handy
2
3
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 6mo ago
Replying to
@wilfredh had you seen scaf? Might be interesting. https://github.com/getscaf/scaf
GitHub

GitHub - getscaf/scaf: scaf is a template manager that simplifies bootstrapping and updating projects.

scaf is a template manager that simplifies bootstrapping and updating projects. - getscaf/scaf

1
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 10mo ago
Replying to
@silmathoron@floss.social you are correct that you always need to secure your repository permissions regardless. With this facet of Shai-Hulud, repositories' stored secrets were exposed, and Trusted Publishing removes the need to store secrets at all.
2
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 11mo ago
Replying to

@diazona@techhub.social No process to request it other than open an issue. It helps if you have references to how these services act as OIDC Providers today. If they don't have said support, we won't be able to add it to PyPI. See https://docs.pypi.org/trusted-publishers/internals/#how-do-i-become-a-trusted-publishing-provider for details on that And if you're more closely involved with any of of hose services, you can also work on the PyPI-side implementation yourself - both the Google and Activestate implementations were added via pull requests from folks in those ecosystems

docs.pypi.org
2
1
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 10mo ago
Replying to
@kaleissin@wandering.shop yes, that's also one approach, which assumes you have another way to secure long-lived credentials instead of trusting a third party to generate a short-lived, minimally scoped token. Teams that publish from a CI/CD provider have a better option than storing long-lived tokens.
1
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 5mo ago
Replying to
@andrewnez@mastodon.social complain
0
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 4mo ago
Replying to
@rogzilla71@mastodon.social hahahha I like that one!!
0
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 11mo ago
Replying to
@vagrantc TL,DR: using OIDC to generate short-lived access tokens to publish from known publishers. Lots of docs: https://docs.pypi.org/trusted-publishers/
docs.pypi.org
0
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 11mo ago
Replying to
@meejah @sethmlarson The overall concepts are detailed here: https://docs.pypi.org/trusted-publishers/ TL,DR: using OIDC to generate short-lived access tokens to publish from known publishers, instead of holding on to long-lived API Tokens
docs.pypi.org
0
0
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 7mo ago
Replying to
@webology@mastodon.social my apologies for any confusion, I had the page open and it was handy. Thanks @pradyunsg@mastodon.social for the actual citations
0
1
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 11mo ago
Replying to
@matmair Sure! You could start with the intro to Trusted Publishers from back in 2023: https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/ And more: https://blog.pypi.org/posts/2024-04-17-expanding-trusted-publisher-support/ https://blog.pypi.org/posts/2024-11-14-pypi-now-supports-digital-attestations/ For this specific work, I'm working on a lot in this issue: https://github.com/pypi/warehouse/issues/15838
blog.pypi.org
0
1
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 7mo ago
Replying to
@fallenhitokiri@social.screamingatmyscreen.com I handle a fair amount of reports where this is the case, and if the C2 endpoint contains malicious code, it's usually removed from PyPI
0
2
0
0
Open post
Mike Fiedler, Code Gardener @miketheman@hachyderm.io
· 2mo ago
Can Claude design a secure system that even Claude cannot break into?
0
1
1
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:38:12 UTC