William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 31/08/2026Introducing vulnbrocards.com blog.yossarian.net/2026/08/31/Intro… #oss #security 064
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 13/08/2026Running for the Python Packaging Council blog.yossarian.net/2026/08/13/pytho… #oss #python 011
Reposted by William Woodruff (1.3.6.1.4.1.55738)James Bennett @b-list.org · 10/08/2026Last year @yossarian.net wrote a brief post on the surprising complexity of the #Python "splitlines()" method. As a busy Unicode pedant, it took me a while to write up something explaining *why* it's complex, but here it finally is: www.b-list.org/weblog/2026/...b-list.orgBreaking up (lines) is hard to doHere’s a seemingly simple question: given a chunk of multi-line text, how do you split it and return an array … 022
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 10/08/2026GitHub Actions needs OIDC audience constraints blog.yossarian.net/2026/08/10/githu… #oss #security #dear-github 030
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 05/08/2026my keynote from EuroPython is online! youtu.be/wMPe_KepOjcyoutu.beKeynote: Securing Python for the next decade - William WoodruffYouTube video by EuroPython Conference 030
Reposted by William Woodruff (1.3.6.1.4.1.55738)Andrew Lilley Brinker @alilleybrinker.com · 04/08/2026Trusted publishing is good, but it's still just an authn method and doesn't mean the package itself is safe to run. Good breakdown by @yossarian.net about thatblog.yossarian.netYou shouldn't trust Trusted Publishing 2136
Reposted by William Woodruff (1.3.6.1.4.1.55738)Filippo Valsorda @filippo.abyssdomain.expert · 26/07/2026It's not my usual beat, but I wrote a pure-Python ML-DSA verifier. pip install mldsa It's 350 lines, CC0/0BSD, single-file, no dependencies, and thoroughly tested. Signature verification handles no secrets, so it doesn't need to be constant-time.words.filippo.ioProduction ML-DSA Verification in 350 Lines of PythonI am publishing a production, pure-Python ML-DSA verifier. It's just 350 lines, and pretty readable and robust. 17211
Reposted by William Woodruff (1.3.6.1.4.1.55738)Seth Larson @sethmlarson.dev · 17/07/2026Excited for the #EuroPython morning keynote today from @yossarian.net, starting at 9AM in S1: ep2026.europython.eu/session/secu...ep2026.europython.euSecuring Python for the next decadeThe next decade will challenge many assumptions in Python security. Join us for a session of speculation on secxuring the next decade. 082
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 16/07/2026README, not blog.yossarian.net/2026/07/16/READM… #ai #oss 051
Reposted by William Woodruff (1.3.6.1.4.1.55738)Brett Cannon @snarky.ca · 07/07/2026If you use GitHub Actions to publish to #PyPI, I wrote a blog post outlining what I consider the key things you can do to secure your publishing workflow. snarky.ca/how-to-publi... If you don't use GitHub Actions for publishing, this post will NOT be of interest to you.snarky.caHow to publish to PyPI using GitHub Actions securelyThere have been several security incidents lately that involved compromising GitHub Actions workflows. This has led some to say "GitHub Actions is the weakest link" in publishing and to GitHub publish... 2126
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 07/07/2026You shouldn’t trust Trusted Publishing blog.yossarian.net/2026/07/07/You-s… #python #security #oss 01510
Reposted by William Woodruff (1.3.6.1.4.1.55738)EuroPython 2026, Kraków @europython.eu · 23/06/2026We couldn't be happier to welcome @yossarian.net to the EuroPython 2026 speaker lineup! 🎉 At Astral, William builds secure Python tooling. He also maintains zizmor (GitHub Actions linter), pip-audit, and PyCA! 🛡️ 🎟️ europython.eu/tickets/ 031
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 08/06/2026I wrote a new post for the Astral blog about how we’re building more vulnerability and malware defenses directly into uv: astral.sh/blog/uv-auditastral.shVulnerability and malware checks in uvFind vulnerabilities in your Python dependencies with uv audit and prevent installation of known malware with uv's experimental malware detection. 1223
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 29/04/2026Registering my dissatisfaction with GitHub blog.yossarian.net/2026/04/29/Regis… #oss 030
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 11/04/2026Brocards for vulnerability triage blog.yossarian.net/2026/04/11/Broca… #security #oss 2106
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 08/04/2026the last two weeks have been ~exciting~ in terms of open source security! I've put together a post on Astral's blog about how we think about open source security: astral.sh/blog/open-so...astral.shOpen source security at AstralInsights and guidance from our engineering team on how Astral secures its tools. 3153
Reposted by William Woodruff (1.3.6.1.4.1.55738)🟡🐍Sviatoslove.pie♥🇺🇦#StandWithUkraine🙏 | українець на чужині @webknjaz.me · 07/04/2026Just cut a new release of `pypi-publish` v1.14.0! It's now verbose by default and prints out hashes. You can opt-out, though. The rest is internal updates, housekeeping, docs. github.com/pypa/gh-acti... / github.com/pypa/gh-acti... #python #Packaging 121
Reposted by William Woodruff (1.3.6.1.4.1.55738)David Buchanan @retr0.id · 31/03/2026have you seen the new supply chain vuln? don't update tubu. it's literally on heebee. they got poodee's deps. they infiltrated dippy. roll back weeno. disable scripts in ~/.gumpyrc. it's in poob. do not install poob. do not update poob. uninstall poob right now. poob has it in for you. 262843848
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 23/02/2026TIL: Rust has safe uninitialized bindings yossarian.net/til/post/rus...yossarian.netTIL: Rust has safe uninitialized bindings 010
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 29/12/2025Some flexibility with Go’s sumdb blog.yossarian.net/2025/12/29/Some-… #security #go #cryptography 121
Reposted by William Woodruff (1.3.6.1.4.1.55738)Filippo Valsorda @filippo.abyssdomain.expert · 27/12/2025At the gpg.fail talk and omg #39c3 You can just put a \0 in the Hash: header and then newlines and inject text in a cleartext message. Won’t even blame PGP here. C is unsafe at any speed. gpg has not fixed it yet. 4431108
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 25/12/2025TIL: serde's borrowing can be treacherous yossarian.net/til/post/ser...yossarian.netTIL: serde's borrowing can be treacherous 0233
Reposted by William Woodruff (1.3.6.1.4.1.55738)Aria Desires @gankra.bsky.social · 16/12/2025so pumped for the ty beta to finally be here, we did so much great work it rules! astral.sh/blog/tyastral.shty: An extremely fast Python type checker and language serverty is an extremely fast Python type checker and language server, written in Rust, and designed as an alternative to mypy, Pyright, and Pylance. 312720
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 13/12/2025Dependency cooldowns, redux blog.yossarian.net/2025/12/13/coold… #security #oss 041
Reposted by William Woodruff (1.3.6.1.4.1.55738)François Best @francoisbest.com · 08/12/2025I've been SHA-1 pinning ever since I started using GitHub Actions, but I didn't think of transitive (compound) actions, which can use unpinned sub-actions. This is fine 🔥🐶☕🔥 Time to setup zizmor.sh by @yossarian.net for automated scanning, I've had it in my "tools to try" list for a bit.nesbitt.ioGitHub Actions Has a Package Manager, and It Might Be the WorstGitHub Actions has a package manager that ignores decades of supply chain security best practices: no lockfile, no integrity verification, no transitive pinning 0163
Reposted by William Woodruff (1.3.6.1.4.1.55738)Seth Larson @sethmlarson.dev · 01/12/2025ICYMI, we want your #security talks at #PyConUS 🤩 CFP closes December 19th #python #supplychain #opensource #oss pycon.blogspot.com/2025/11/trai...pycon.blogspot.comJoin us in “Trailblazing Python Security” at PyCon US 2026PyCon US 2026 is coming to Long Beach, California ! PyCon US is the premiere conference for the Python programming language in North Americ... 054
Reposted by William Woodruff (1.3.6.1.4.1.55738)Alex @acyphus.lol · 01/12/2025I'm a big fan of zizmor.sh by @yossarian.net to provide static analysis of GitHub Actions workflows as I'm working on them. The remediation advice is also top notch, for `pull_request_target` as an example: docs.zizmor.sh/audits/#dang...zizmor.shzizmor - Static Analysis for GitHub ActionsFind and fix potential vulnerabilities in your GitHub workflows and action definitions with zizmor's powerful static analysis. 121
Reposted by William Woodruff (1.3.6.1.4.1.55738)Mike Fiedler @miketheman.com · 26/11/2025There's a nasty #OpenSource #SupplyChain worm going around named Shai-Hulud. It's also capable of exposing some projects' long-lived PyPI API Tokens. Read more on what's happening, and what you can do to protect your projects. TL,DR: Adopt Trusted Publishing 🔐🚀📦 blog.pypi.org/posts/2025-1...blog.pypi.orgPyPI and Shai-Hulud: Staying Secure Amid Emerging Threats - The Python Package Index BlogShai-Hulud is a great worm, not yet a snake. Attack on npm ecosystem may have implications for PyPI. 12517
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 21/11/2025We should all be using dependency cooldowns blog.yossarian.net/2025/11/21/We-sh… #security #oss 571
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 06/10/2025TIL: Safari has built-in WebDriver support yossarian.net/til/post/saf...yossarian.netTIL: Safari has built-in WebDriver support 010
Reposted by William Woodruff (1.3.6.1.4.1.55738)reaperhulk.bsky.social @reaperhulk.bsky.social · 24/09/2025All the world's developers are a toddler and X.509 is the neighbor's unfenced pool. 0338
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 22/09/2025Dear GitHub: no YAML anchors, please blog.yossarian.net/2025/09/22/dear-… #programming #rant 172
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 15/09/2025maslow’s hierarchy of needs? yeah, I think I’ve heard of that somewhere before 000
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 14/09/2025One year of zizmor blog.yossarian.net/2025/09/14/one-y… #devblog #programming #rust #zizmor 062
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 10/09/2025finally learned what a "labubu" is from my local bodega. very helpful 020
Reposted by William Woodruff (1.3.6.1.4.1.55738)🟡🐍Sviatoslove.pie♥🇺🇦#StandWithUkraine🙏 | українець на чужині @webknjaz.me · 04/09/2025Just cut a new release of `pypi-publish` v1.13.0! It's got internal runtime update, housekeeping, also diagnostic messages and security improvements from @yossarian.net! github.com/pypa/gh-acti... / github.com/pypa/gh-acti... #python #Packaginggithub.comRelease v1.13.0 · pypa/gh-action-pypi-publishTake the 2025 Python Packaging Survey if you still haven't! Important🚨 This release includes fixes for GHSA-vxmw-7h4f-hqxh discovered by @woodruffw💰. We've also integrated Zizmor to catch similar i... 043
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 23/08/2025i went on tom, deirdre, and david's podcast and talked about PGP and encrypted email: securitycryptographywhatever.com/2025/08/22/s...securitycryptographywhatever.comStop Using Encrypted Email with William WoodruffThere was a bug in an OpenPGP library which finally gave us an excuse to tear encrypted email via PGP to shreds. Our special guest William Woodruff joined us... 060
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 17/08/2025grape nuts is the only good cereal 310
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 14/08/2025PyPI now serves PEP 792 project statuses in its APIs. that means you can now programmatically check if a package is archived, quarantined, etc.! blog.pypi.org/posts/2025-0...blog.pypi.orgPyPI now serves project status markers in API responses - The Python Package Index BlogPyPI has implemented PEP 792, and is now serving project status markers in its standard HTML and JSON APIs. 0176
Reposted by William Woodruff (1.3.6.1.4.1.55738)Filippo Valsorda @filippo.abyssdomain.expert · 12/08/2025The Go 1.25 change I am most excited about is the new synctest package. How I think about it is as a way to deflake tests by simulating an infinitely fast processor (because time doesn’t move until all work is done), and then shorten them by compressing time (because time jumps once it moves). 27713
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 14/08/2025Fun with finite state transducers blog.yossarian.net/2025/08/14/Fun-w… #devblog #programming #rust #zizmor 000
Reposted by William Woodruff (1.3.6.1.4.1.55738)Charlie Marsh @crmarsh.com · 13/08/2025Today, we're announcing our first hosted infrastructure product: pyx, a Python-native package registry. We think of pyx as an optimized backend for uv: it’s a package registry, but it also solves problems that go beyond the scope of a traditional "package registry". 417237
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 13/08/2025zizmor v1.12.0 is released! this release comes with one new audit (unsound-condition), support for auto-fixing three more finding classes, plus much more in the way of general enhancements and bug fixes. full details here: docs.zizmor.sh/release-note...docs.zizmor.shRelease Notes - zizmorAbbreviated change notes about each zizmor release. 073
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 30/06/2025zizmor v1.11.0 is out! this release comes with experimental LSP support and an accompanying vscode extension: marketplace.visualstudio.com/items?itemNa... full release notes here: docs.zizmor.sh/release-note... 032
Reposted by William Woodruff (1.3.6.1.4.1.55738)Joe McManus @joemcmanus.bsky.social · 27/06/2025Do you want to find out more about how @grafana.bsky.social secures its GitHub actions using Zizmor? Check out this post from James on my team : grafana.com/blog/2025/06... @yossarian.netgrafana.comHow to detect vulnerable GitHub Actions at scale with Zizmor | Grafana LabsIn order to harden our infrastructure and pipelines, we have introduced the open source tool Zizmor into our CI/CD pipelines. 024
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 26/06/2025zizmor v1.10.0 is released! this is a *huge* new release: it exposes a new (experimental) auto-fix mode, more precise subspanning for fixtures, as well as a brand new pedantic audit (anonymous-definition) read the full notes here: docs.zizmor.sh/release-note...docs.zizmor.shRelease Notes - zizmorAbbreviated change notes about each zizmor release. 164
Reposted by William Woodruff (1.3.6.1.4.1.55738)Filippo Valsorda @filippo.abyssdomain.expert · 19/06/2025"Tuscolo2025h2, Tuscolo2026h1, and Tuscolo2026h2 have passed their compliance monitoring period and will be added to an upcoming version of Chrome." issues.chromium.org/issues/41669... The Geomys Certificate Transparency logs are on their way to become the first trusted Static CT API logs! 🎉 1294