Finally home. Seven speaking spots across seven days, three conferences in two states, many miles apart.
Now some rest.
#PyConUS #OSSummit #OpenSSFCommunity
Mike Fiedler, Code Gardener
mastodon 4.7.3#Security on @pypi@fosstodon.org for @ThePSF@fosstodon.org. Pyoneer 🐍
Wrangler of the Unusual, Roller Derby referee. AWS Hero.
Pronouns: he/him
I wonder who I know that knows someone at HackerOne that can convey the message that PyPI explicitly disallows security research packages, and bans users who upload them. Put that in a notice to your users somewhere prominent - since it's become pervasive and a drain on resources.
This also takes time away from legitimate security incident response - so it's a net negative for the world.
Any time I see something like this in a #Python REPL, I can't help but smile for two reasons:
1. Yes, yes I did forget.
2. I know some of the folks who worked so hard to make that message do exactly what I want it to do. Thanks to Pablo, @ambv@mastodon.social, and so many others!
One behavioral modification of doing career switches between individual contributor and manager (and back!) is that manager-speak trains you to use "we" when referring to the work your team has accomplished, since it's not "you" per se - giving credit where credit is due
The problem is when you then work somewhere as a team-of-one, like #PyPI #Security. It's astonishing how many folks think there's a whole team here, when it's just me for the past 3 years.
I will endeavor to update my verbiage accordingly to prevent further misperceptions
It's still awesome to me that I get to work on some really hard problems for the common good. This was a lot of work, hope you enjoy the read!
There's a nasty #OpenSource #SupplyChain worm going around named Shai-Hulud. It's also capable of exposing some projects' long-lived PyPI API Tokens. Read more on what's happening, and what you can do to protect your projects.
TL,DR: Adopt Trusted Publishing 🔐🚀📦
What do I do on a day off? Spend time on non-security work, refactoring #OpenSource projects to try a new idea I had.
Sometimes it's really hard to turn the brain off...
@AlSweigart@mastodon.social here's a bad one:
"Free apps" == "fapps"
Publishing projects to PyPI without a source distribution, links to a source codebase, or other indications of "what might be in this binary package"? is definitely a smell to me when I'm evaluating which projects I want to rely upon.
So many projects advertise an #OpenSource License like MIT and Apache-2.0 and do not supply any sources in the "obvious" spots.
If you're attending #PyConUS and want to find me, I'm likely to be found:
- Thursday evening Reception, PSF Booth
- Friday afternoon, Packaging Summit
- Saturday, before lunch, #Security Track
- Saturday, after lunch, Maintainers Summit
- Sunday morning, Keynote Stage, Update from Security Engineers
Find these and more on the PyCon US Mobile app. Pro Tip: sign in with your registration details to favorite sessions: https://us.pycon.org/2026/attend/onsite-information/#:~:text=PyCon%20US-,Mobile%20App,-Conference%20information%20on
Lots of links:
- https://us.pycon.org/2026/events/opening-reception/
- https://us.pycon.org/2026/schedule/presentation/74/
- https://us.pycon.org/2026/schedule/talks/#May16
- https://us.pycon.org/2026/events/maintainers-summit/#schedule
I really liked this notice that the @biomejs@fosstodon.org maintainers put in one of their discussions on GitHub. Hopefully folks read it, sadly I suspect the abusers won't
Does your org run a self-managed version of GitLab and publish your own #Python packages to @pypi@fosstodon.org ?
If you want to try out an alpha of Trusted Publishing for GitLab Self-Managed instances, let me know via DM - I'm collecting interest now, and should have something to show soon.
Incident Report of the recent #PyPI Phishing Campaign
TL,DR:
• PyPI was not breached
• PyPI users were targeted with phishing emails
• A single project saw uploads with malicious code and those releases have been removed
https://blog.pypi.org/posts/2025-07-31-incident-report-phishing-attack/
RE: @andrewnez@mastodon.social
Excellent blog on the turducken problem of package managers
Thanks
@fastlydevs@mastodon.social for taking some time to ask me questions and share my responses - it's quite unique to work on a system like this
This is a great podcast that discusses some of the details by @lorenipsum@fosstodon.org and @BajoranEngineer@mastodon.online on @ThePSF@fosstodon.org 's rejection of the NSF grant conditions.
"We are ALL spine 🐍 " --Loren
Pro tip: If you use @ohmyzsh@mstdn.social #python plugin, AND use https://starship.rs/ for prompt decorations, AND set `PYTHON_AUTO_VRUN=true` to automatically activate a virtualenv when you enter a directory, you may see your starship prompt lose it's style when navigating away in certain circumstances.
The fix is to tell the python plugin to leave the prompt alone since starship will handle it with:
`VIRTUAL_ENV_DISABLE_PROMPT=1`
in your .zshrc
There are many problems with trust-based systems.
We can add all the cryptographic proofs we want, all the monitors and witnesses, but ultimately if the end-consumer doesn't understand well enough how these layers add trustworthiness, they won't trust the trust system itself, much less the original system.
So we're back to where we started, but we added piles of complexity, ossification of protocols and interchanges.
Ultimately, you kind of have to trust someone or something else. How much you trust them, understanding the risks associated with said trust, are all critical to reduce risks.
@diazona@techhub.social No process to request it other than open an issue. It helps if you have references to how these services act as OIDC Providers today. If they don't have said support, we won't be able to add it to PyPI. See https://docs.pypi.org/trusted-publishers/internals/#how-do-i-become-a-trusted-publishing-provider for details on that And if you're more closely involved with any of of hose services, you can also work on the PyPI-side implementation yourself - both the Google and Activestate implementations were added via pull requests from folks in those ecosystems