William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 04/10/2026TIL: Rust's derive often implies inline yossarian.net/til/post/rus...yossarian.netTIL: Rust's derive often implies inline 011
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 31/08/2026If you have suggestions for how to convey the nuance there, I’d appreciate them! I was trying to go for “standards are sometimes bad and tools should be stricter than bad standards, and when they *try* to be stricter it’s a vulnerability when they fail to be.” But it’s a hard sentiment to express 140
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 31/08/2026thank you Al, that means a great deal! although I don’t think I’m listed on your post 😅 000
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 31/08/2026Introducing vulnbrocards.com blog.yossarian.net/2026/08/31/Intro… #oss #security 064
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 13/08/2026Running for the Python Packaging Council blog.yossarian.net/2026/08/13/pytho… #oss #python 011
Reposted by William Woodruff (1.3.6.1.4.1.55738)James Bennett @b-list.org · 10/08/2026Last year @yossarian.net wrote a brief post on the surprising complexity of the #Python "splitlines()" method. As a busy Unicode pedant, it took me a while to write up something explaining *why* it's complex, but here it finally is: www.b-list.org/weblog/2026/...b-list.orgBreaking up (lines) is hard to doHere’s a seemingly simple question: given a chunk of multi-line text, how do you split it and return an array … 022
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 10/08/2026GitHub Actions needs OIDC audience constraints blog.yossarian.net/2026/08/10/githu… #oss #security #dear-github 030
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 05/08/2026my keynote from EuroPython is online! youtu.be/wMPe_KepOjcyoutu.beKeynote: Securing Python for the next decade - William WoodruffYouTube video by EuroPython Conference 030
Reposted by William Woodruff (1.3.6.1.4.1.55738)Andrew Lilley Brinker @alilleybrinker.com · 04/08/2026Trusted publishing is good, but it's still just an authn method and doesn't mean the package itself is safe to run. Good breakdown by @yossarian.net about thatblog.yossarian.netYou shouldn't trust Trusted Publishing 2136
Reposted by William Woodruff (1.3.6.1.4.1.55738)Filippo Valsorda @filippo.abyssdomain.expert · 26/07/2026It's not my usual beat, but I wrote a pure-Python ML-DSA verifier. pip install mldsa It's 350 lines, CC0/0BSD, single-file, no dependencies, and thoroughly tested. Signature verification handles no secrets, so it doesn't need to be constant-time.words.filippo.ioProduction ML-DSA Verification in 350 Lines of PythonI am publishing a production, pure-Python ML-DSA verifier. It's just 350 lines, and pretty readable and robust. 17211
Reposted by William Woodruff (1.3.6.1.4.1.55738)Seth Larson @sethmlarson.dev · 17/07/2026Excited for the #EuroPython morning keynote today from @yossarian.net, starting at 9AM in S1: ep2026.europython.eu/session/secu...ep2026.europython.euSecuring Python for the next decadeThe next decade will challenge many assumptions in Python security. Join us for a session of speculation on secxuring the next decade. 082
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 16/07/2026README, not blog.yossarian.net/2026/07/16/READM… #ai #oss 051
Reposted by William Woodruff (1.3.6.1.4.1.55738)Brett Cannon @snarky.ca · 07/07/2026If you use GitHub Actions to publish to #PyPI, I wrote a blog post outlining what I consider the key things you can do to secure your publishing workflow. snarky.ca/how-to-publi... If you don't use GitHub Actions for publishing, this post will NOT be of interest to you.snarky.caHow to publish to PyPI using GitHub Actions securelyThere have been several security incidents lately that involved compromising GitHub Actions workflows. This has led some to say "GitHub Actions is the weakest link" in publishing and to GitHub publish... 2126
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 07/07/2026You shouldn’t trust Trusted Publishing blog.yossarian.net/2026/07/07/You-s… #python #security #oss 01510
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 06/07/2026Bsky: officially more reliable than GitHub notifications 030
Reposted by William Woodruff (1.3.6.1.4.1.55738)EuroPython 2026, Kraków @europython.eu · 23/06/2026We couldn't be happier to welcome @yossarian.net to the EuroPython 2026 speaker lineup! 🎉 At Astral, William builds secure Python tooling. He also maintains zizmor (GitHub Actions linter), pip-audit, and PyCA! 🛡️ 🎟️ europython.eu/tickets/ 031
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 08/06/2026I wrote a new post for the Astral blog about how we’re building more vulnerability and malware defenses directly into uv: astral.sh/blog/uv-auditastral.shVulnerability and malware checks in uvFind vulnerabilities in your Python dependencies with uv audit and prevent installation of known malware with uv's experimental malware detection. 1223
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 29/04/2026Registering my dissatisfaction with GitHub blog.yossarian.net/2026/04/29/Regis… #oss 030
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 15/04/2026Yeah, I think my single biggest regret from that post is using Dependabot for the example; their cooldown feature is way buggier than I realized (and that’s only being shaken out now that people are using it more). Longer term I think each packaging ecosystem is implementing this directly 110
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 11/04/2026Brocards for vulnerability triage blog.yossarian.net/2026/04/11/Broca… #security #oss 2106
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 08/04/2026the last two weeks have been ~exciting~ in terms of open source security! I've put together a post on Astral's blog about how we think about open source security: astral.sh/blog/open-so...astral.shOpen source security at AstralInsights and guidance from our engineering team on how Astral secures its tools. 3153
Reposted by William Woodruff (1.3.6.1.4.1.55738)🟡🐍Sviatoslove.pie♥🇺🇦#StandWithUkraine🙏 | українець на чужині @webknjaz.me · 07/04/2026Just cut a new release of `pypi-publish` v1.14.0! It's now verbose by default and prints out hashes. You can opt-out, though. The rest is internal updates, housekeeping, docs. github.com/pypa/gh-acti... / github.com/pypa/gh-acti... #python #Packaging 121
Reposted by William Woodruff (1.3.6.1.4.1.55738)David Buchanan @retr0.id · 31/03/2026have you seen the new supply chain vuln? don't update tubu. it's literally on heebee. they got poodee's deps. they infiltrated dippy. roll back weeno. disable scripts in ~/.gumpyrc. it's in poob. do not install poob. do not update poob. uninstall poob right now. poob has it in for you. 262844850
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 23/02/2026TIL: Rust has safe uninitialized bindings yossarian.net/til/post/rus...yossarian.netTIL: Rust has safe uninitialized bindings 010
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 09/01/2026I also agree that there are potentially better ways to *structure* this kind of dependency awareness, but a public registry + consensus mechanism requires people to commit to building and operating those things, which isn't trivial! That's something I think needs future work, though 000
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 09/01/2026those are good questions that a lot of people had! I covered them in some detail in a follow-up here: blog.yossarian.net/2025/12/13/c... TL;DR yes, the assumption is that security scanners provide more value than users incidentally tripping over malware, i.e. universalization is not a concernblog.yossarian.netDependency cooldowns, redux 100
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 29/12/2025Some flexibility with Go’s sumdb blog.yossarian.net/2025/12/29/Some-… #security #go #cryptography 121
Reposted by William Woodruff (1.3.6.1.4.1.55738)Filippo Valsorda @filippo.abyssdomain.expert · 27/12/2025At the gpg.fail talk and omg #39c3 You can just put a \0 in the Hash: header and then newlines and inject text in a cleartext message. Won’t even blame PGP here. C is unsafe at any speed. gpg has not fixed it yet. 4431108
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 25/12/2025TIL: serde's borrowing can be treacherous yossarian.net/til/post/ser...yossarian.netTIL: serde's borrowing can be treacherous 0233
Reposted by William Woodruff (1.3.6.1.4.1.55738)Aria Desires @gankra.bsky.social · 16/12/2025so pumped for the ty beta to finally be here, we did so much great work it rules! astral.sh/blog/tyastral.shty: An extremely fast Python type checker and language serverty is an extremely fast Python type checker and language server, written in Rust, and designed as an alternative to mypy, Pyright, and Pylance. 312720
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 13/12/2025Dependency cooldowns, redux blog.yossarian.net/2025/12/13/coold… #security #oss 041
Reposted by William Woodruff (1.3.6.1.4.1.55738)François Best @francoisbest.com · 08/12/2025I've been SHA-1 pinning ever since I started using GitHub Actions, but I didn't think of transitive (compound) actions, which can use unpinned sub-actions. This is fine 🔥🐶☕🔥 Time to setup zizmor.sh by @yossarian.net for automated scanning, I've had it in my "tools to try" list for a bit.nesbitt.ioGitHub Actions Has a Package Manager, and It Might Be the WorstGitHub Actions has a package manager that ignores decades of supply chain security best practices: no lockfile, no integrity verification, no transitive pinning 0163
Reposted by William Woodruff (1.3.6.1.4.1.55738)Seth Larson @sethmlarson.dev · 01/12/2025ICYMI, we want your #security talks at #PyConUS 🤩 CFP closes December 19th #python #supplychain #opensource #oss pycon.blogspot.com/2025/11/trai...pycon.blogspot.comJoin us in “Trailblazing Python Security” at PyCon US 2026PyCon US 2026 is coming to Long Beach, California ! PyCon US is the premiere conference for the Python programming language in North Americ... 054
Reposted by William Woodruff (1.3.6.1.4.1.55738)Alex @acyphus.lol · 01/12/2025I'm a big fan of zizmor.sh by @yossarian.net to provide static analysis of GitHub Actions workflows as I'm working on them. The remediation advice is also top notch, for `pull_request_target` as an example: docs.zizmor.sh/audits/#dang...zizmor.shzizmor - Static Analysis for GitHub ActionsFind and fix potential vulnerabilities in your GitHub workflows and action definitions with zizmor's powerful static analysis. 121
Reposted by William Woodruff (1.3.6.1.4.1.55738)Mike Fiedler @miketheman.com · 26/11/2025There's a nasty #OpenSource #SupplyChain worm going around named Shai-Hulud. It's also capable of exposing some projects' long-lived PyPI API Tokens. Read more on what's happening, and what you can do to protect your projects. TL,DR: Adopt Trusted Publishing 🔐🚀📦 blog.pypi.org/posts/2025-1...blog.pypi.orgPyPI and Shai-Hulud: Staying Secure Amid Emerging Threats - The Python Package Index BlogShai-Hulud is a great worm, not yet a snake. Attack on npm ecosystem may have implications for PyPI. 12517
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 21/11/2025We should all be using dependency cooldowns blog.yossarian.net/2025/11/21/We-sh… #security #oss 571
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 06/10/2025TIL: Safari has built-in WebDriver support yossarian.net/til/post/saf...yossarian.netTIL: Safari has built-in WebDriver support 010
Reposted by William Woodruff (1.3.6.1.4.1.55738)reaperhulk.bsky.social @reaperhulk.bsky.social · 24/09/2025All the world's developers are a toddler and X.509 is the neighbor's unfenced pool. 0338
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 22/09/2025Dear GitHub: no YAML anchors, please blog.yossarian.net/2025/09/22/dear-… #programming #rant 172
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 15/09/2025maslow’s hierarchy of needs? yeah, I think I’ve heard of that somewhere before 000
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 14/09/2025One year of zizmor blog.yossarian.net/2025/09/14/one-y… #devblog #programming #rust #zizmor 062
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 10/09/2025finally learned what a "labubu" is from my local bodega. very helpful 020
Reposted by William Woodruff (1.3.6.1.4.1.55738)🟡🐍Sviatoslove.pie♥🇺🇦#StandWithUkraine🙏 | українець на чужині @webknjaz.me · 04/09/2025Just cut a new release of `pypi-publish` v1.13.0! It's got internal runtime update, housekeeping, also diagnostic messages and security improvements from @yossarian.net! github.com/pypa/gh-acti... / github.com/pypa/gh-acti... #python #Packaginggithub.comRelease v1.13.0 · pypa/gh-action-pypi-publishTake the 2025 Python Packaging Survey if you still haven't! Important🚨 This release includes fixes for GHSA-vxmw-7h4f-hqxh discovered by @woodruffw💰. We've also integrated Zizmor to catch similar i... 043
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 23/08/2025i went on tom, deirdre, and david's podcast and talked about PGP and encrypted email: securitycryptographywhatever.com/2025/08/22/s...securitycryptographywhatever.comStop Using Encrypted Email with William WoodruffThere was a bug in an OpenPGP library which finally gave us an excuse to tear encrypted email via PGP to shreds. Our special guest William Woodruff joined us... 060