Who’s Keeping the Python Ecosystem Safe?

Who’s Keeping the Python Ecosystem Safe?

Mike Fiedler, a PyPI safety and security engineer at the Python Software Foundation, prefers the title “code gardener,” reflecting his role in maintaining and securing open source projects. Recorded at PyCon US, Fiedler explains his task of “pulling the weeds” in code—handling unglamorous but crucial aspects of open source contributions. Since August, funded by Amazon Web Services, Fiedler has focused on enhancing the security of the Python Package Index (PyPI). His efforts include ensuring that both packages and the pipeline are secure, emphasizing the importance of vetting third-party modules before deployment.

One of Fiedler’s significant initiatives was enforcing mandatory two-factor authentication (2FA) for all PyPI user accounts by January 1, following a community awareness campaign. This transition was smooth, thanks to proactive outreach. Additionally, the foundation collaborates with security researchers and the public to report and address malicious packages.

In late 2023, a security audit by Trail of Bits, funded by the Open Technology Fund, identified and quickly resolved medium-sized vulnerabilities, increasing PyPI's overall security. More details on Fiedler's work are available in the full interview video.

Learn more from The New Stack about PyPl:

PyPl Strives to Pull Itself Out of Trouble

How Python Is Evolving

Poisoned Lolip0p PyPI Packages

Join our community of newsletter subscribers to stay on top of the news and at the top of your game.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(300)

The CNCF is graduating projects faster than ever. AI agents are helping with the due diligence.

The CNCF is graduating projects faster than ever. AI agents are helping with the due diligence.

Open-source technology has played a foundational role in the AI boom, giving companies the flexibility to scale unprecedented computing workloads across providers and hardware. OpenAI, for example, us...

6 Okt 30min

Dynatrace wants its AI agents to fix problems instead of adding alerts

Dynatrace wants its AI agents to fix problems instead of adding alerts

Dynatrace's view is that AI apps should be monitored like any other app. They still run alongside older systems, including mainframes, and when something breaks, teams need to know what it cost and wh...

5 Okt 20min

Bit Cloud’s next chapter starts after the AI builds your app

Bit Cloud’s next chapter starts after the AI builds your app

For many developers, turning an AI-generated prototype into maintainable software requires more than generating code—it requires infrastructure, collaboration, testing and review. In this episode of T...

1 Okt 31min

CloudBees just committed to an AI-first pivot. Here's why it matters for enterprise DevOps teams

CloudBees just committed to an AI-first pivot. Here's why it matters for enterprise DevOps teams

CloudBees CEO Mo Plassnig is leading the CI/CD company through a major transformation as generative AI reshapes software development. Returning to CloudBees eight years after joining through its acqui...

30 Sep 23min

A third option is emerging in the fight over AI and your data

A third option is emerging in the fight over AI and your data

The AI industry has faced a growing enterprise dilemma: companies want access to powerful proprietary AI models without risking sensitive data or intellectual property, while AI labs want to protect t...

23 Sep 30min

Drowning in AI pull requests: Harness's field CTO on code review and a Git repo built for agents

Drowning in AI pull requests: Harness's field CTO on code review and a Git repo built for agents

Harness Field CTO Martin Reynolds joins The New Stack to talk about what happens after coding agents start opening pull requests faster than anyone can review them. He explains how he first saw the bo...

7 Sep 26min

How to find failures without drowning in tracing data

How to find failures without drowning in tracing data

Traces provide a detailed view of a request’s journey through data, microservices and applications, helping SREs pinpoint where failures occur and resolve issues faster. But while tracing can reduce d...

3 Sep 31min

Why CPUs still matter in the age of AI agents

Why CPUs still matter in the age of AI agents

As AI evolves from conversational chatbots to autonomous agents, CPUs are becoming an increasingly important part of the infrastructure equation. In this episode, The New Stack speaks with Bhumik Pate...

11 Aug 26min

Populärt inom Politik & nyheter

svenska-fall
aftonbladet-krim
fordomspodden
p3-krim
rss-krimstad
flashback-forever
aftonbladet-daily
spar
de-fyras-gang
rss-vad-fan-hande
rss-sanning-konsekvens
svd-dokumentara-berattelser-2
rss-krimreportrarna
svd-ledarredaktionen
rss-flodet
politiken
omni-podd
motiv
ett-rent-noje
rss-frandfors-horna