Sign in

Mike Fiedler

@miketheman.com
3.2K followers 260 following 654 posts

Code Gardener. Wrangler of the Unusual. Roller Derby referee. AWS Hero. PyPI Maintainer. Shakshuka lover. he/him miketheman.dev

PostsRepliesMedia
Reposted by Mike Fiedler
Seth Larson @sethmlarson.dev · 4h
I've just published 10 blog posts detailing the #Python Language Summit 2026. The Language Summit was held in Kraków, Poland and included discussions about free-threading, #Rust, garbage collectors, and type annotations. Please enjoy and thank you for your patience: blog.python.org/2026/09/lang...
Group photo of the attendees of the 2026 Python Language Summit. Notably, Larry Hastings is laying flat on the ground with his eyes closed.
196
Mike Fiedler @miketheman.com · 24/09/2026
You probably should come to @fastly.com Xcelerate NYC this year. You might just see me and learn about some of the stuff I've been working on at the @python.org for @pypi.org. Wednesday, October 14th, one day only! www.fastly.com/events/xcele...
fastly.com
Xcelerate NYC 2026 | CDN & Security Event | Fastly
Join experts and peers at Xcelerate NYC on Wednesday, October 14! Find out how the Fastly platform was built to support fast and secure online experiences.
150
Reposted by Mike Fiedler
Python Software Foundation @python.org · 10/09/2026
🐍 Check out @sethmlarson.dev's talk at @europython.eu 2026: "Learning from the not-so-secret Python security 'cabal'". This talk is a deep dive into how CPython handles coordinated vulnerability disclosure, how the #Python security team is organized, & what it takes to run a disclosure program.
youtube.com
Learning from the not-so-secret Python security "cabal" - Seth Michael Larson
[EuroPython 2026 - S1 on 2026-07-16]🎤 *Learning from the not-so-secret Python security "cabal" by Seth Michael Larson* 🔗 https://ep2026.europython.eu/sess...
052
Mike Fiedler @miketheman.com · 08/09/2026
I wrote up a #PyPI incident report for some install-time issues experienced a few of weeks ago by some users, and what was changed. blog.pypi.org/posts/2026-0...
blog.pypi.org
Incident Report: File Hosting Errors - The Python Package Index Blog
For two weeks in August 2026, some PyPI users hit intermittent 502 and 503 errors downloading files. Here's what was happening, and what we changed.
095
Mike Fiedler @miketheman.com · 29/08/2026
I was this close to starting to try and write my own macOS clock widget to display UTC under my regular clock, since I often forget the math to calculate UTC from whatever time zone I'm in (and whatever daylight savings offset there might be!).
120
Mike Fiedler @miketheman.com · 27/08/2026
NYC is definitely a vibe
050
Mike Fiedler @miketheman.com · 24/08/2026
Wednesday night I'll be speaking at the NYC Open Source Security User Group meetup. If your release pipeline still has stored API tokens in it, come find out how to delete them for good. Free registration: luma.com/5mwalp6p?tk=... #Python #OpenSourceSecurity #SupplyChainSecurity #NYCTech #PyPI
luma.com
Trusted Publishing — Eliminating Credentials from Your Release Workflow · Luma
6:00-6:30 Network - Pizza provided 6:30-7:30 Talk and Q&A 7:30-8:00 Network In February 2024, about 10% of PyPI uploads used Trusted Publishers. By October…
161
Mike Fiedler @miketheman.com · 21/08/2026
Happy Hawaiian Shirt Day!
070
Reposted by Mike Fiedler
Seth Larson @sethmlarson.dev · 18/08/2026
A neat security vulnerability in Python caused by str.lower(). Also includes lots of RFCs so I’m having a good time :) sethmlarson.dev/when-str-low... #security #python #idna
sethmlarson.dev
When str.lower() is a security vulnerability in Python
Some internet standards only support ASCII characters, but the world uses much more than the Latin alphabet. Thus, a mapping from Unicode to ASCII for use in domain names is required. NamePrep was...
0208
Mike Fiedler @miketheman.com · 18/08/2026
Go home, GitHub, you're drunk
Screenshot of GitHub Issue closed 1 minute ago, and GitHub showing a message that it was closed 57 years ago
1121
Mike Fiedler @miketheman.com · 12/08/2026
Wow, @pypi.org crossed 2 EXABYTES bandwidth served in 2026. For comparison, **all traffic served in 2025** was only 1.95 Exabytes. Thanks to @fastly.com, over 99.999% of that is absorbed by their powerful global caching layer, chugging along to serve #OpenSource #Python users worldwide
Chart with blue line increasing gradually up and to the right, displaying total bandwidth served this year since January 1st
0328
Reposted by Mike Fiedler
OpenSSF @openssf.org · 04/08/2026
Mila Zhou recently sat down with Yesenia Yser on the What's in the SOSS podcast to share her path from accounting to her role as a Senior Open Source & Security Program Manager at Amazon Web Services (AWS). openssf.org/podcast/2026...
011
Mike Fiedler @miketheman.com · 31/07/2026
I can't be the first to discover that a Pillsbury biscuit with chipotle mayo is delicious?
000
Reposted by Mike Fiedler
Python Software Foundation @python.org · 28/07/2026
🗳️ Nominations for the inaugural Python Packaging Council election are open! Help shape how Python packages are built, distributed, and installed—the council needs consensus-builders who bring the packaging community together. Nominate yourself or someone else by Tuesday, August 11th, 2:00 pm UTC.
pyfound.blogspot.com
Get Ready: Python Packaging Council Nominations Opening Soon!
074
Reposted by Mike Fiedler
Python Software Foundation @python.org · 23/07/2026
You can be a part of guiding the future direction of the PSF 🩵🐍💛 Nominate yourself or someone else for the PSF Board for the 2026 election! Nominations open Tuesday, July 28th, 2:00 pm UTC and close Tuesday, August 11th, 2:00 pm UTC. #python
pyfound.blogspot.com
Get Ready: PSF Board Nominations Opening Soon!
Who runs for the PSF Board? People who care about the Python community, who want to see it flourish and grow, and also have a few hours a month to attend regular meetings, serve on committees, participate in conversations, and promote the Python community. We're looking for candidates with a diverse range of skills and backgrounds, including leadership experience, fundraising knowledge, non-profit familiarity, and event organizing. Technical expertise, a record of collaboration, and experience speaking or teaching in the Python community are also all qualities we hope to see in Board members.Want to learn more about being on the PSF Board? Check out the following resources to learn more about the PSF, as well as what being a part of the PSF Board entails:
0107
Mike Fiedler @miketheman.com · 22/07/2026
If you use the `setup-uv` #GitHub #Action in your workflows, consider upgrading to version 9.0.0 soon. This version changes the default behavior to store the downloaded #Python wheels from #PyPI in GHA Cache, shedding load from PyPI, especially relevant for frequent CI/CD runs.
131
Mike Fiedler @miketheman.com · 21/07/2026
I'm about to head home after a truly amazing experience at my first #EuroPython. I was honored to be able to share some stories, but more importantly I met a bunch of awesome people. Kudos to the @europython.eu organization and all the folks who make magic happen!
EuroPython closing event with as many volunteers on stage as could make it
130
Reposted by Mike Fiedler
Seth Larson @sethmlarson.dev · 16/07/2026
I'm speaking today at #EuroPython about learning from the #Python #Security Response Team and how to become a "Security Contributor" to an Open Source project. The talk is in Room S1 at 16:00 right before the evening keynote: ep2026.europython.eu/session/lear...
ep2026.europython.eu
Learning from the not-so-secret Python security "cabal"
It’s dangerous to go alone! 🐍🛡️ Learn sustainable open source security practices for projects of all sizes from the Python Security Response Team.
2102
Reposted by Mike Fiedler
Seth Larson @sethmlarson.dev · 17/07/2026
Excited for the #EuroPython morning keynote today from @yossarian.net, starting at 9AM in S1: ep2026.europython.eu/session/secu...
ep2026.europython.eu
Securing Python for the next decade
The next decade will challenge many assumptions in Python security. Join us for a session of speculation on secxuring the next decade.
082
Mike Fiedler @miketheman.com · 16/07/2026
Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year. ep2026.europython.eu/session/anat... #EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security
Anatomy of a Phishing Campaign, Mike Fiedler
EuroPython
163
Reposted by Mike Fiedler
EuroPython 2026, Kraków @europython.eu · 14/07/2026
We are pretty serious about learning out here at #EuroPython2026 and super stoked to have Guido with us here 🐍 ❤️
041
Reposted by Mike Fiedler
Mayor Zohran Kwame Mamdani @mayor.nyc.gov · 13/07/2026
If you’re a software engineer, designer, or technologist who wants to help make City government work better and faster, apply to join our PIT crews at nyc.gov/pitcrew.
Mayor Mamdani races on a Go Kart.
271088233
Reposted by Mike Fiedler
Simon Willison @simonwillison.net · 14/07/2026
New TIL: Using uvx in GitHub Actions in a cache-friendly way I finally found a recipe that I like for running `uvx tool-name` in GitHub Actions without downloading a fresh copy of the package every time til.simonwillison.net/github-actio...
til.simonwillison.net
Using uvx in GitHub Actions in a cache-friendly way
I often find myself wanting to run a quick Python tool inside of GitHub Actions using uvx name-of-tool - but I don't want that to result in a network request to PyPI every time the workflow runs. I wa...
1373
Mike Fiedler @miketheman.com · 13/07/2026
Good morning skitches! (Channelling @monkchips.com this morning)
Photograph of espresso coffee on wooden bar in front of draped window
130
Reposted by Mike Fiedler
EuroPython 2026, Kraków @europython.eu · 10/07/2026
Join @miketheman.com at EuroPython for "Security and Ethics in the Age of Generative AI" ep2026.europython.eu/N9HKQN
052
Reposted by Mike Fiedler
Yells at Cloud @yellsatcloudpod.com · 05/07/2026
Something's brewing. AWS Heroes arguing about cloud computing like it personally wronged them. Episode one in the works. Follow for more. yellsatcloudpod.com
yellsatcloudpod.com
Yells at Cloud - A podcast by AWS Heroes
A podcast where AWS Heroes argue about cloud computing like it personally wronged them. Strong opinions, real experience, disagreement guaranteed.
194
Reposted by Mike Fiedler
PyCon US @pycon.us · 07/07/2026
We’re thrilled to welcome our new #PyConUS Conference Co-Chair and future Conference Chair, Kattni! 🎉 Learn more about Kattni here: pycon.blogspot.com/2026/07/welc... 🗓️ Mark your calendars for #PyConUS 2027, May 12th-18th back in Long Beach, CA
pycon.blogspot.com
Welcome, Kattni!
We are thrilled to welcome Kattni as the next Co-Chair and future Chair of PyCon US! You may already know Kattni from her work on CircuitPy...
0116
Mike Fiedler @miketheman.com · 07/07/2026
Some days I wonder if the supply chain attackers are hoping I'll giggle before swinging the banhammer The creativity of some of these folks is wasted on scamming
Screenshot of:
Fah Queue
anchosuave
Joined about 2 hours ago
070
Mike Fiedler @miketheman.com · 05/07/2026
Sunday morning, coffee's on, laptop open. Nobody asked me to fix this. It might still be broken Monday, sure. but it's broken **better**! #OpenSource: the sometimes unglamorous work, done in public, one commit at a time.
040
Mike Fiedler @miketheman.com · 26/06/2026
Very excited to share stories, insights, recommendations at my first @europython.eu I'll also be attending the Packaging and Language Summits, as well as any other opportunities to increase awareness of #Python and #PyPI #OpenSource #SupplyChain #Security initiatives. #EP2026 #TooManyHashtags
1131
Reposted by Mike Fiedler
Python Software Foundation @python.org · 25/06/2026
Great coverage from @lwndotnet.bsky.social of the PSF PyPI Safety & Security Engineer @miketheman.com's talk on Trusted Publishing at Open Source Summit. 36% of PyPI uploads now use Trusted Publishing. Is yours one of them? lwn.net/Articles/107... #Python #PyPI #OSSumit #Security
lwn.net
Eliminating long-lived credentials with trusted publishing
Trusted publishing is an authentication mechanism that relies on short-lived credentials to red [...]
083
Mike Fiedler @miketheman.com · 25/06/2026
This is what collaborative, coordinated, responsible disclosure looks like. It was a pleasure to work with @gitguardian.com on this #PyPI #security investigation to help protect the global #Python #SupplyChain blog.gitguardian.com/hunting-leak...
blog.gitguardian.com
Hunting Leaked PyPI Tokens: 62 Live, 125 Packages Exposed
We found 62 live PyPI tokens leaking on public sources, enough to push malicious code to 125 packages with 25,000 monthly downloads. We reported them to PyPI, which revoked every one. Here's how we de...
2135
Mike Fiedler @miketheman.com · 22/06/2026
Look! It's @sethmlarson.dev and I at the #UNOpenSourceWeek ! We presented, facilitated, and listened to others. #Python #OpenSource #Security #WhatAWeirdJob
0110
Reposted by Mike Fiedler
Python Software Foundation @python.org · 22/06/2026
Watch PSF PyPI Safety & Security Engineer @miketheman.com's talk from Open Source Summit NA 2026: Trusted Publishing uses OIDC to generate short-lived tokens from CI/CD. No passwords. No tokens to rotate. No secrets in repos. www.youtube.com/watch?v=i0BW... #Python #PyPI #OSSummit #Security
youtube.com
Trusted Publishing: Eliminating Credentials From Your Release Workflow - Mike Fiedler
YouTube video by The Linux Foundation
0148
Reposted by Mike Fiedler
EuroPython 2026, Kraków @europython.eu · 20/06/2026
Join Mike Fiedler (@miketheman.com) at EuroPython for "Anatomy of a Phishing Campaign" talk: ep2026.europython.eu/NXNHSB
Speaker announcement for EuroPython 2026 conference: Mike Fiedler — Anatomy of a Phishing Campaign
021
Reposted by Mike Fiedler
Sovereign Tech Agency @sovereign.tech · 18/06/2026
Building on last year’s success, we are bringing the #maintainathon back to #UNOpenSourceWeek 🇺🇳 Together with the United Nations Office for Digital and Emerging Technologies, the Sovereign Tech Agency is hosting the maintain-a-thon, facilitated and led by the experts from our delegation:
Visual for the Sovereign Tech Agency’s Maintain-a-thon 2.0 during UN Open Source Week 2026, featuring a large group photo of participants in a conference room.
162
Mike Fiedler @miketheman.com · 17/06/2026
It was an honor to speak to a room full of people curious about how #phishing maintainers led to a #SupplyChain incident and some ideas on how to harden workflows to prevent
070
Mike Fiedler @miketheman.com · 16/06/2026
I'm starting to really think that the main benefit of the new waves of AI is exposing every business process weakness. Case and point: if you have terrible dev docs, test/validation steps, generative agents will produce about the same quality as an unguided junior dev
061
Reposted by Mike Fiedler
Python Software Foundation @python.org · 04/06/2026
The PSF's Strategic Plan full draft is available and we want your feedback. After sharing high-level goals in May, we're opening a 3-week community feedback window. Read the full draft and tell us: Are these the right goals? Is anything missing? #Python #PyPI pyfound.blogspot.com/2026/06/psf-...
02416
Mike Fiedler @miketheman.com · 27/05/2026
One behavioral modification of doing career switches between individual contributor and manager (and back!) is that manager-speak trains you to use "we" when referring to the work your team has accomplished, since it's not "you" per se - giving credit where credit is due
140
Mike Fiedler @miketheman.com · 26/05/2026
Let's go Liberty!
040
Reposted by Mike Fiedler
Jon Banafato @jonafato.bsky.social · 23/05/2026
If you participated in PyCon US, please fill out the survey. It helps a lot. Remind your friends.
065
Mike Fiedler @miketheman.com · 22/05/2026
Finally home. Seven speaking spots across seven days, three conferences in two states, many miles apart. Now some rest. #PyConUS #OSSummit #OpenSSFCommunity
Photograph of three conference badges laid side by side, all with speaker tags
2160
Reposted by Mike Fiedler
Nina Zakharenko @nina.codes · 17/05/2026
@miketheman.com and @sethmlarson.dev share some of the accomplishments of the PSF security team this year. That’s a lot of work for two people! And shoutout to the sponsors who make it possible to fund their roles.
0124
Mike Fiedler @miketheman.com · 17/05/2026
Woo! @sethmlarson.dev and I got a selfie with the #PyConUS Keynote speaker amada casari! The keynote starts in 15 minutes, followed by a #security update
070
Reposted by Mike Fiedler
Python Software Foundation @python.org · 16/05/2026
The community mosaic at the PSF booth at #PyConUS 2026 is looking awesome 🐍🎨 🤩 Come help us and color a tile (or a few) before the expo hall closes at the end of the day (no art skills required, we promise!) #PythonIsForEveryone
0224
Reposted by Mike Fiedler
Python Software Foundation @python.org · 15/05/2026
🔐 Catch PSF's PyPI Safety and Security Engineer, @miketheman.com, talking Trusted Publishing at #OSSummit next week! Learn how to eliminate long-lived credentials from your #PyPI release workflow: no tokens, no secrets, just secure deploys. Tue May 19 @ 11am CDT #Python #SupplyChain #Security
osselcna2026.sched.com
Open Source Summit + Embedded Linux Conference North America 2026: Trusted Publishing: Eliminating Credenti...
View more about this event at Open Source Summit + Embedded Linux Conference North America 2026
084
Mike Fiedler @miketheman.com · 11/05/2026
If you're attending #PyConUS and want to find me, I'm likely to be found: - Thursday evening Reception, PSF Booth - Friday afternoon, Packaging Summit - Saturday, before lunch, #Security Track - Saturday, after lunch, Maintainers Summit - Sunday morning, Keynote Stage, Update from Security Engineers
1112
Mike Fiedler @miketheman.com · 11/05/2026
TFW you're almost done with all of your #PyConUS preparation, which includes wayyyy too many things for one year, but you're busting with excitement to see everyone
static.klipy.com
Man Says 'I'm Exhausted' While Wrapped in Blanket
Alt: Man Says 'I'm Exhausted' While Wrapped in Blanket
020
Mike Fiedler @miketheman.com · 08/05/2026
First #rollerderby home league scrimmage practice now done! Feels good to be back on wheels in #NYC
150