Sign in

William Woodruff (1.3.6.1.4.1.55738)

@yossarian.net
467 followers 65 following 183 posts

skeeting in accordance with the universal law. yossarian.net / blog.yossarian.net

PostsRepliesMedia
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 04/10/2026
TIL: Rust's derive often implies inline yossarian.net/til/post/rus...
yossarian.net
TIL: Rust's derive often implies inline
011
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 31/08/2026
If you have suggestions for how to convey the nuance there, I’d appreciate them! I was trying to go for “standards are sometimes bad and tools should be stricter than bad standards, and when they *try* to be stricter it’s a vulnerability when they fail to be.” But it’s a hard sentiment to express
140
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 31/08/2026
thank you Al, that means a great deal! although I don’t think I’m listed on your post 😅
000
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 31/08/2026
Introducing vulnbrocards.com blog.yossarian.net/2026/08/31/Intro… #oss #security
064
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 13/08/2026
Running for the Python Packaging Council blog.yossarian.net/2026/08/13/pytho… #oss #python
011
Reposted by William Woodruff (1.3.6.1.4.1.55738)
James Bennett @b-list.org · 10/08/2026
Last year @yossarian.net wrote a brief post on the surprising complexity of the #Python "splitlines()" method. As a busy Unicode pedant, it took me a while to write up something explaining *why* it's complex, but here it finally is: www.b-list.org/weblog/2026/...
b-list.org
Breaking up (lines) is hard to do
Here’s a seemingly simple question: given a chunk of multi-line text, how do you split it and return an array …
022
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 10/08/2026
GitHub Actions needs OIDC audience constraints blog.yossarian.net/2026/08/10/githu… #oss #security #dear-github
030
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 05/08/2026
my keynote from EuroPython is online! youtu.be/wMPe_KepOjc
youtu.be
Keynote: Securing Python for the next decade - William Woodruff
YouTube video by EuroPython Conference
030
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Andrew Lilley Brinker @alilleybrinker.com · 04/08/2026
Trusted publishing is good, but it's still just an authn method and doesn't mean the package itself is safe to run. Good breakdown by @yossarian.net about that
blog.yossarian.net
You shouldn't trust Trusted Publishing
2136
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 27/07/2026
“I take the green line to work”
000
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Filippo Valsorda @filippo.abyssdomain.expert · 26/07/2026
It's not my usual beat, but I wrote a pure-Python ML-DSA verifier. pip install mldsa It's 350 lines, CC0/0BSD, single-file, no dependencies, and thoroughly tested. Signature verification handles no secrets, so it doesn't need to be constant-time.
words.filippo.io
Production ML-DSA Verification in 350 Lines of Python
I am publishing a production, pure-Python ML-DSA verifier. It's just 350 lines, and pretty readable and robust.
17211
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Seth Larson @sethmlarson.dev · 17/07/2026
Excited for the #EuroPython morning keynote today from @yossarian.net, starting at 9AM in S1: ep2026.europython.eu/session/secu...
ep2026.europython.eu
Securing Python for the next decade
The next decade will challenge many assumptions in Python security. Join us for a session of speculation on secxuring the next decade.
082
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 16/07/2026
README, not blog.yossarian.net/2026/07/16/READM… #ai #oss
051
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Brett Cannon @snarky.ca · 07/07/2026
If you use GitHub Actions to publish to #PyPI, I wrote a blog post outlining what I consider the key things you can do to secure your publishing workflow. snarky.ca/how-to-publi... If you don't use GitHub Actions for publishing, this post will NOT be of interest to you.
snarky.ca
How to publish to PyPI using GitHub Actions securely
There have been several security incidents lately that involved compromising GitHub Actions workflows. This has led some to say "GitHub Actions is the weakest link" in publishing and to GitHub publish...
2126
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 07/07/2026
You shouldn’t trust Trusted Publishing blog.yossarian.net/2026/07/07/You-s… #python #security #oss
01510
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 06/07/2026
Bsky: officially more reliable than GitHub notifications
030
Reposted by William Woodruff (1.3.6.1.4.1.55738)
EuroPython 2026, Kraków @europython.eu · 23/06/2026
We couldn't be happier to welcome @yossarian.net to the EuroPython 2026 speaker lineup! 🎉 At Astral, William builds secure Python tooling. He also maintains zizmor (GitHub Actions linter), pip-audit, and PyCA! 🛡️ 🎟️ europython.eu/tickets/
William Woodruff
031
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 08/06/2026
I wrote a new post for the Astral blog about how we’re building more vulnerability and malware defenses directly into uv: astral.sh/blog/uv-audit
astral.sh
Vulnerability and malware checks in uv
Find vulnerabilities in your Python dependencies with uv audit and prevent installation of known malware with uv's experimental malware detection.
1223
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 29/04/2026
Registering my dissatisfaction with GitHub blog.yossarian.net/2026/04/29/Regis… #oss
030
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 15/04/2026
Yeah, I think my single biggest regret from that post is using Dependabot for the example; their cooldown feature is way buggier than I realized (and that’s only being shaken out now that people are using it more). Longer term I think each packaging ecosystem is implementing this directly
110
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 11/04/2026
Brocards for vulnerability triage blog.yossarian.net/2026/04/11/Broca… #security #oss
2106
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 08/04/2026
the last two weeks have been ~exciting~ in terms of open source security! I've put together a post on Astral's blog about how we think about open source security: astral.sh/blog/open-so...
astral.sh
Open source security at Astral
Insights and guidance from our engineering team on how Astral secures its tools.
3153
Reposted by William Woodruff (1.3.6.1.4.1.55738)
🟡🐍Sviatoslove.pie♥🇺🇦#StandWithUkraine🙏 | українець на чужині @webknjaz.me · 07/04/2026
Just cut a new release of `pypi-publish` v1.14.0! It's now verbose by default and prints out hashes. You can opt-out, though. The rest is internal updates, housekeeping, docs. github.com/pypa/gh-acti... / github.com/pypa/gh-acti... #python #Packaging
121
Reposted by William Woodruff (1.3.6.1.4.1.55738)
David Buchanan @retr0.id · 31/03/2026
have you seen the new supply chain vuln? don't update tubu. it's literally on heebee. they got poodee's deps. they infiltrated dippy. roll back weeno. disable scripts in ~/.gumpyrc. it's in poob. do not install poob. do not update poob. uninstall poob right now. poob has it in for you.
262844850
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 23/02/2026
TIL: Rust has safe uninitialized bindings yossarian.net/til/post/rus...
yossarian.net
TIL: Rust has safe uninitialized bindings
010
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 22/02/2026
absolut etrog limited edition
010
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 09/01/2026
I also agree that there are potentially better ways to *structure* this kind of dependency awareness, but a public registry + consensus mechanism requires people to commit to building and operating those things, which isn't trivial! That's something I think needs future work, though
000
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 09/01/2026
those are good questions that a lot of people had! I covered them in some detail in a follow-up here: blog.yossarian.net/2025/12/13/c... TL;DR yes, the assumption is that security scanners provide more value than users incidentally tripping over malware, i.e. universalization is not a concern
blog.yossarian.net
Dependency cooldowns, redux
100
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 29/12/2025
thank you, fixed!
010
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 29/12/2025
Some flexibility with Go’s sumdb blog.yossarian.net/2025/12/29/Some-… #security #go #cryptography
121
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Filippo Valsorda @filippo.abyssdomain.expert · 27/12/2025
At the gpg.fail talk and omg #39c3 You can just put a \0 in the Hash: header and then newlines and inject text in a cleartext message. Won’t even blame PGP here. C is unsafe at any speed. gpg has not fixed it yet.
4431108
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 25/12/2025
TIL: serde's borrowing can be treacherous yossarian.net/til/post/ser...
yossarian.net
TIL: serde's borrowing can be treacherous
0233
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Aria Desires @gankra.bsky.social · 16/12/2025
so pumped for the ty beta to finally be here, we did so much great work it rules! astral.sh/blog/ty
astral.sh
ty: An extremely fast Python type checker and language server
ty is an extremely fast Python type checker and language server, written in Rust, and designed as an alternative to mypy, Pyright, and Pylance.
312720
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 13/12/2025
Dependency cooldowns, redux blog.yossarian.net/2025/12/13/coold… #security #oss
041
Reposted by William Woodruff (1.3.6.1.4.1.55738)
François Best @francoisbest.com · 08/12/2025
I've been SHA-1 pinning ever since I started using GitHub Actions, but I didn't think of transitive (compound) actions, which can use unpinned sub-actions. This is fine 🔥🐶☕🔥 Time to setup zizmor.sh by @yossarian.net for automated scanning, I've had it in my "tools to try" list for a bit.
nesbitt.io
GitHub Actions Has a Package Manager, and It Might Be the Worst
GitHub Actions has a package manager that ignores decades of supply chain security best practices: no lockfile, no integrity verification, no transitive pinning
0163
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Seth Larson @sethmlarson.dev · 01/12/2025
ICYMI, we want your #security talks at #PyConUS 🤩 CFP closes December 19th #python #supplychain #opensource #oss pycon.blogspot.com/2025/11/trai...
pycon.blogspot.com
Join us in “Trailblazing Python Security” at PyCon US 2026
PyCon US 2026 is coming to Long Beach, California ! PyCon US is the premiere conference for the Python programming language in North Americ...
054
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 01/12/2025
thanks for the kind words!
010
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Alex @acyphus.lol · 01/12/2025
I'm a big fan of zizmor.sh by @yossarian.net to provide static analysis of GitHub Actions workflows as I'm working on them. The remediation advice is also top notch, for `pull_request_target` as an example: docs.zizmor.sh/audits/#dang...
zizmor.sh
zizmor - Static Analysis for GitHub Actions
Find and fix potential vulnerabilities in your GitHub workflows and action definitions with zizmor's powerful static analysis.
121
Reposted by William Woodruff (1.3.6.1.4.1.55738)
Mike Fiedler @miketheman.com · 26/11/2025
There's a nasty #OpenSource #SupplyChain worm going around named Shai-Hulud. It's also capable of exposing some projects' long-lived PyPI API Tokens. Read more on what's happening, and what you can do to protect your projects. TL,DR: Adopt Trusted Publishing 🔐🚀📦 blog.pypi.org/posts/2025-1...
blog.pypi.org
PyPI and Shai-Hulud: Staying Secure Amid Emerging Threats - The Python Package Index Blog
Shai-Hulud is a great worm, not yet a snake. Attack on npm ecosystem may have implications for PyPI.
12517
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 21/11/2025
that would be so awesome!
000
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 21/11/2025
We should all be using dependency cooldowns blog.yossarian.net/2025/11/21/We-sh… #security #oss
571
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 06/10/2025
TIL: Safari has built-in WebDriver support yossarian.net/til/post/saf...
yossarian.net
TIL: Safari has built-in WebDriver support
010
Reposted by William Woodruff (1.3.6.1.4.1.55738)
reaperhulk.bsky.social @reaperhulk.bsky.social · 24/09/2025
All the world's developers are a toddler and X.509 is the neighbor's unfenced pool.
0338
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 22/09/2025
Dear GitHub: no YAML anchors, please blog.yossarian.net/2025/09/22/dear-… #programming #rant
172
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 15/09/2025
maslow’s hierarchy of needs? yeah, I think I’ve heard of that somewhere before
000
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 14/09/2025
One year of zizmor blog.yossarian.net/2025/09/14/one-y… #devblog #programming #rust #zizmor
062
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 10/09/2025
finally learned what a "labubu" is from my local bodega. very helpful
020
Reposted by William Woodruff (1.3.6.1.4.1.55738)
🟡🐍Sviatoslove.pie♥🇺🇦#StandWithUkraine🙏 | українець на чужині @webknjaz.me · 04/09/2025
Just cut a new release of `pypi-publish` v1.13.0! It's got internal runtime update, housekeeping, also diagnostic messages and security improvements from @yossarian.net! github.com/pypa/gh-acti... / github.com/pypa/gh-acti... #python #Packaging
github.com
Release v1.13.0 · pypa/gh-action-pypi-publish
Take the 2025 Python Packaging Survey if you still haven't! Important🚨 This release includes fixes for GHSA-vxmw-7h4f-hqxh discovered by @woodruffw💰. We've also integrated Zizmor to catch similar i...
043
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 23/08/2025
i went on tom, deirdre, and david's podcast and talked about PGP and encrypted email: securitycryptographywhatever.com/2025/08/22/s...
securitycryptographywhatever.com
Stop Using Encrypted Email with William Woodruff
There was a bug in an OpenPGP library which finally gave us an excuse to tear encrypted email via PGP to shreds. Our special guest William Woodruff joined us...
060