Sign in

William Woodruff (1.3.6.1.4.1.55738)

@yossarian.net
466 followers 65 following 182 posts

skeeting in accordance with the universal law. yossarian.net / blog.yossarian.net

PostsRepliesMedia
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 31/08/2026
Introducing vulnbrocards.com blog.yossarian.net/2026/08/31/Intro… #oss #security
064
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 13/08/2026
Running for the Python Packaging Council blog.yossarian.net/2026/08/13/pytho… #oss #python
011
Reposted by William Woodruff (1.3.6.1.4.1.55738)
James Bennett @b-list.org · 10/08/2026
Last year @yossarian.net wrote a brief post on the surprising complexity of the #Python "splitlines()" method. As a busy Unicode pedant, it took me a while to write up something explaining *why* it's complex, but here it finally is: www.b-list.org/weblog/2026/...
b-list.org
Breaking up (lines) is hard to do
Here’s a seemingly simple question: given a chunk of multi-line text, how do you split it and return an array …
022
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 10/08/2026
GitHub Actions needs OIDC audience constraints blog.yossarian.net/2026/08/10/githu… #oss #security #dear-github
030
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 05/08/2026
my keynote from EuroPython is online! youtu.be/wMPe_KepOjc
youtu.be
Keynote: Securing Python for the next decade - William Woodruff
YouTube video by EuroPython Conference
030
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Andrew Lilley Brinker @alilleybrinker.com · 04/08/2026
Trusted publishing is good, but it's still just an authn method and doesn't mean the package itself is safe to run. Good breakdown by @yossarian.net about that
blog.yossarian.net
You shouldn't trust Trusted Publishing
2136
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 27/07/2026
“I take the green line to work”
000
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Filippo Valsorda @filippo.abyssdomain.expert · 26/07/2026
It's not my usual beat, but I wrote a pure-Python ML-DSA verifier. pip install mldsa It's 350 lines, CC0/0BSD, single-file, no dependencies, and thoroughly tested. Signature verification handles no secrets, so it doesn't need to be constant-time.
words.filippo.io
Production ML-DSA Verification in 350 Lines of Python
I am publishing a production, pure-Python ML-DSA verifier. It's just 350 lines, and pretty readable and robust.
17211
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Seth Larson @sethmlarson.dev · 17/07/2026
Excited for the #EuroPython morning keynote today from @yossarian.net, starting at 9AM in S1: ep2026.europython.eu/session/secu...
ep2026.europython.eu
Securing Python for the next decade
The next decade will challenge many assumptions in Python security. Join us for a session of speculation on secxuring the next decade.
082
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 16/07/2026
README, not blog.yossarian.net/2026/07/16/READM… #ai #oss
051
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Brett Cannon @snarky.ca · 07/07/2026
If you use GitHub Actions to publish to #PyPI, I wrote a blog post outlining what I consider the key things you can do to secure your publishing workflow. snarky.ca/how-to-publi... If you don't use GitHub Actions for publishing, this post will NOT be of interest to you.
snarky.ca
How to publish to PyPI using GitHub Actions securely
There have been several security incidents lately that involved compromising GitHub Actions workflows. This has led some to say "GitHub Actions is the weakest link" in publishing and to GitHub publish...
2126
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 07/07/2026
You shouldn’t trust Trusted Publishing blog.yossarian.net/2026/07/07/You-s… #python #security #oss
01510
Reposted by William Woodruff (1.3.6.1.4.1.55738)
EuroPython 2026, Kraków @europython.eu · 23/06/2026
We couldn't be happier to welcome @yossarian.net to the EuroPython 2026 speaker lineup! 🎉 At Astral, William builds secure Python tooling. He also maintains zizmor (GitHub Actions linter), pip-audit, and PyCA! 🛡️ 🎟️ europython.eu/tickets/
William Woodruff
031
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 08/06/2026
I wrote a new post for the Astral blog about how we’re building more vulnerability and malware defenses directly into uv: astral.sh/blog/uv-audit
astral.sh
Vulnerability and malware checks in uv
Find vulnerabilities in your Python dependencies with uv audit and prevent installation of known malware with uv's experimental malware detection.
1223
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 29/04/2026
Registering my dissatisfaction with GitHub blog.yossarian.net/2026/04/29/Regis… #oss
030
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 11/04/2026
Brocards for vulnerability triage blog.yossarian.net/2026/04/11/Broca… #security #oss
2106
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 08/04/2026
the last two weeks have been ~exciting~ in terms of open source security! I've put together a post on Astral's blog about how we think about open source security: astral.sh/blog/open-so...
astral.sh
Open source security at Astral
Insights and guidance from our engineering team on how Astral secures its tools.
3153
Reposted by William Woodruff (1.3.6.1.4.1.55738)
🟡🐍Sviatoslove.pie♥🇺🇦#StandWithUkraine🙏 | українець на чужині @webknjaz.me · 07/04/2026
Just cut a new release of `pypi-publish` v1.14.0! It's now verbose by default and prints out hashes. You can opt-out, though. The rest is internal updates, housekeeping, docs. github.com/pypa/gh-acti... / github.com/pypa/gh-acti... #python #Packaging
121
Reposted by William Woodruff (1.3.6.1.4.1.55738)
David Buchanan @retr0.id · 31/03/2026
have you seen the new supply chain vuln? don't update tubu. it's literally on heebee. they got poodee's deps. they infiltrated dippy. roll back weeno. disable scripts in ~/.gumpyrc. it's in poob. do not install poob. do not update poob. uninstall poob right now. poob has it in for you.
262843848
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 23/02/2026
TIL: Rust has safe uninitialized bindings yossarian.net/til/post/rus...
yossarian.net
TIL: Rust has safe uninitialized bindings
010
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 22/02/2026
absolut etrog limited edition
010
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 29/12/2025
Some flexibility with Go’s sumdb blog.yossarian.net/2025/12/29/Some-… #security #go #cryptography
121
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Filippo Valsorda @filippo.abyssdomain.expert · 27/12/2025
At the gpg.fail talk and omg #39c3 You can just put a \0 in the Hash: header and then newlines and inject text in a cleartext message. Won’t even blame PGP here. C is unsafe at any speed. gpg has not fixed it yet.
4431108
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 25/12/2025
TIL: serde's borrowing can be treacherous yossarian.net/til/post/ser...
yossarian.net
TIL: serde's borrowing can be treacherous
0233
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Aria Desires @gankra.bsky.social · 16/12/2025
so pumped for the ty beta to finally be here, we did so much great work it rules! astral.sh/blog/ty
astral.sh
ty: An extremely fast Python type checker and language server
ty is an extremely fast Python type checker and language server, written in Rust, and designed as an alternative to mypy, Pyright, and Pylance.
312720
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 13/12/2025
Dependency cooldowns, redux blog.yossarian.net/2025/12/13/coold… #security #oss
041
Reposted by William Woodruff (1.3.6.1.4.1.55738)
François Best @francoisbest.com · 08/12/2025
I've been SHA-1 pinning ever since I started using GitHub Actions, but I didn't think of transitive (compound) actions, which can use unpinned sub-actions. This is fine 🔥🐶☕🔥 Time to setup zizmor.sh by @yossarian.net for automated scanning, I've had it in my "tools to try" list for a bit.
nesbitt.io
GitHub Actions Has a Package Manager, and It Might Be the Worst
GitHub Actions has a package manager that ignores decades of supply chain security best practices: no lockfile, no integrity verification, no transitive pinning
0163
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Seth Larson @sethmlarson.dev · 01/12/2025
ICYMI, we want your #security talks at #PyConUS 🤩 CFP closes December 19th #python #supplychain #opensource #oss pycon.blogspot.com/2025/11/trai...
pycon.blogspot.com
Join us in “Trailblazing Python Security” at PyCon US 2026
PyCon US 2026 is coming to Long Beach, California ! PyCon US is the premiere conference for the Python programming language in North Americ...
054
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Alex @acyphus.lol · 01/12/2025
I'm a big fan of zizmor.sh by @yossarian.net to provide static analysis of GitHub Actions workflows as I'm working on them. The remediation advice is also top notch, for `pull_request_target` as an example: docs.zizmor.sh/audits/#dang...
zizmor.sh
zizmor - Static Analysis for GitHub Actions
Find and fix potential vulnerabilities in your GitHub workflows and action definitions with zizmor's powerful static analysis.
121
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Mike Fiedler @miketheman.com · 26/11/2025
There's a nasty #OpenSource #SupplyChain worm going around named Shai-Hulud. It's also capable of exposing some projects' long-lived PyPI API Tokens. Read more on what's happening, and what you can do to protect your projects. TL,DR: Adopt Trusted Publishing 🔐🚀📦 blog.pypi.org/posts/2025-1...
blog.pypi.org
PyPI and Shai-Hulud: Staying Secure Amid Emerging Threats - The Python Package Index Blog
Shai-Hulud is a great worm, not yet a snake. Attack on npm ecosystem may have implications for PyPI.
12517
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 21/11/2025
We should all be using dependency cooldowns blog.yossarian.net/2025/11/21/We-sh… #security #oss
571
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 06/10/2025
TIL: Safari has built-in WebDriver support yossarian.net/til/post/saf...
yossarian.net
TIL: Safari has built-in WebDriver support
010
Reposted by William Woodruff (1.3.6.1.4.1.55738)
reaperhulk.bsky.social @reaperhulk.bsky.social · 24/09/2025
All the world's developers are a toddler and X.509 is the neighbor's unfenced pool.
0338
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 22/09/2025
Dear GitHub: no YAML anchors, please blog.yossarian.net/2025/09/22/dear-… #programming #rant
172
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 15/09/2025
maslow’s hierarchy of needs? yeah, I think I’ve heard of that somewhere before
000
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 14/09/2025
One year of zizmor blog.yossarian.net/2025/09/14/one-y… #devblog #programming #rust #zizmor
062
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 10/09/2025
finally learned what a "labubu" is from my local bodega. very helpful
020
Reposted by William Woodruff (1.3.6.1.4.1.55738)
🟡🐍Sviatoslove.pie♥🇺🇦#StandWithUkraine🙏 | українець на чужині @webknjaz.me · 04/09/2025
Just cut a new release of `pypi-publish` v1.13.0! It's got internal runtime update, housekeeping, also diagnostic messages and security improvements from @yossarian.net! github.com/pypa/gh-acti... / github.com/pypa/gh-acti... #python #Packaging
github.com
Release v1.13.0 · pypa/gh-action-pypi-publish
Take the 2025 Python Packaging Survey if you still haven't! Important🚨 This release includes fixes for GHSA-vxmw-7h4f-hqxh discovered by @woodruffw💰. We've also integrated Zizmor to catch similar i...
043
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 23/08/2025
i went on tom, deirdre, and david's podcast and talked about PGP and encrypted email: securitycryptographywhatever.com/2025/08/22/s...
securitycryptographywhatever.com
Stop Using Encrypted Email with William Woodruff
There was a bug in an OpenPGP library which finally gave us an excuse to tear encrypted email via PGP to shreds. Our special guest William Woodruff joined us...
060
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 17/08/2025
grape nuts is the only good cereal
310
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 14/08/2025
PyPI now serves PEP 792 project statuses in its APIs. that means you can now programmatically check if a package is archived, quarantined, etc.! blog.pypi.org/posts/2025-0...
blog.pypi.org
PyPI now serves project status markers in API responses - The Python Package Index Blog
PyPI has implemented PEP 792, and is now serving project status markers in its standard HTML and JSON APIs.
0176
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Filippo Valsorda @filippo.abyssdomain.expert · 12/08/2025
The Go 1.25 change I am most excited about is the new synctest package. How I think about it is as a way to deflake tests by simulating an infinitely fast processor (because time doesn’t move until all work is done), and then shorten them by compressing time (because time jumps once it moves).
27713
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 14/08/2025
Fun with finite state transducers blog.yossarian.net/2025/08/14/Fun-w… #devblog #programming #rust #zizmor
000
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Charlie Marsh @crmarsh.com · 13/08/2025
Today, we're announcing our first hosted infrastructure product: pyx, a Python-native package registry. We think of pyx as an optimized backend for uv: it’s a package registry, but it also solves problems that go beyond the scope of a traditional "package registry".
417237
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 13/08/2025
zizmor v1.12.0 is released! this release comes with one new audit (unsound-condition), support for auto-fixing three more finding classes, plus much more in the way of general enhancements and bug fixes. full details here: docs.zizmor.sh/release-note...
docs.zizmor.sh
Release Notes - zizmor
Abbreviated change notes about each zizmor release.
073
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 30/06/2025
zizmor v1.11.0 is out! this release comes with experimental LSP support and an accompanying vscode extension: marketplace.visualstudio.com/items?itemNa... full release notes here: docs.zizmor.sh/release-note...
032
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Joe McManus @joemcmanus.bsky.social · 27/06/2025
Do you want to find out more about how @grafana.bsky.social secures its GitHub actions using Zizmor? Check out this post from James on my team : grafana.com/blog/2025/06... @yossarian.net
grafana.com
How to detect vulnerable GitHub Actions at scale with Zizmor | Grafana Labs
In order to harden our infrastructure and pipelines, we have introduced the open source tool Zizmor into our CI/CD pipelines.
024
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 26/06/2025
zizmor v1.10.0 is released! this is a *huge* new release: it exposes a new (experimental) auto-fix mode, more precise subspanning for fixtures, as well as a brand new pedantic audit (anonymous-definition) read the full notes here: docs.zizmor.sh/release-note...
docs.zizmor.sh
Release Notes - zizmor
Abbreviated change notes about each zizmor release.
164
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Filippo Valsorda @filippo.abyssdomain.expert · 19/06/2025
"Tuscolo2025h2, Tuscolo2026h1, and Tuscolo2026h2 have passed their compliance monitoring period and will be added to an upcoming version of Chrome." issues.chromium.org/issues/41669... The Geomys Certificate Transparency logs are on their way to become the first trusted Static CT API logs! 🎉
1294