Mike Fiedler, Code Gardener
miketheman@hachyderm.io
<p><a href="https://hachyderm.io/tags/Security" class="mention hashtag" rel="tag">#<span>Security</span></a> on <span class="h-card" translate="no"><a href="https://fosstodon.org/@pypi" class="u-url mention">@<span>pypi</span></a></span> for <span class="h-card" translate="no"><a href="https://fosstodon.org/@ThePSF" class="u-url mention">@<span>ThePSF</span></a></span>. Pyoneer ๐</p><p>Wrangler of the Unusual, Roller Derby referee. AWS Hero.<br />Pronouns: he/him</p>
Posts
-
View post
Can Claude design a secure system that even Claude cannot break into?
-
View post
Finally home. Seven speaking spots across seven days, three conferences in two states, many miles apart. Now some rest. #PyConUS #OSSummit #OpenSSFCommunity
-
View post
@AlSweigart here&#39;s a bad one: &quot;Free apps&quot; == &quot;fapps&quot;
-
View post
I wonder who I know that knows someone at HackerOne that can convey the message that PyPI explicitly disallows security research packages, and bans users who upload them. Put that in a notice to your users somewhere prominent - since it&#39;s become pervasive and a drain on resources. This also takes time away from legitimate security incident response - so it&#39;s a net negative for the world.
-
View post
One behavioral modification of doing career switches between individual contributor and manager (and back!) is that manager-speak trains you to use &quot;we&quot; when referring to the work your team has accomplished, since it&#39;s not &quot;you&quot; per se - giving credit where credit is due The problem is when you then work somewhere as a team-of-one, like #PyPI #Security. It&#39;s astonishing how many folks think there&#39;s a whole team here, when it&#39;s...
-
View post
RE: https://mastodon.social/@andrewnez/116652324434840347 Excellent blog on the turducken problem of package managers
-
View post
What do I do on a day off? Spend time on non-security work, refactoring #OpenSource projects to try a new idea I had. Sometimes it&#39;s really hard to turn the brain off...
-
View post
If you&#39;re attending #PyConUS and want to find me, I&#39;m likely to be found: - Thursday evening Reception, PSF Booth - Friday afternoon, Packaging Summit - Saturday, before lunch, #Security Track - Saturday, after lunch, Maintainers Summit - Sunday morning, Keynote Stage, Update from Security Engineers Find these and more on the PyCon US Mobile app. Pro Tip: sign in with your registration details to favorite sessions: https://us.pycon.org/2026/attend/onsite-information/#:~:text=PyC...
-
View post
There&#39;s a nasty #OpenSource #SupplyChain worm going around named Shai-Hulud. It&#39;s also capable of exposing some projects&#39; long-lived PyPI API Tokens. Read more on what&#39;s happening, and what you can do to protect your projects. TL,DR: Adopt Trusted Publishing ๐๐๐ฆ https://blog.pypi.org/posts/2025-11-26-pypi-and-shai-hulud/
-
View post
Does your org run a self-managed version of GitLab and publish your own #Python packages to @pypi ? If you want to try out an alpha of Trusted Publishing for GitLab Self-Managed instances, let me know via DM - I&#39;m collecting interest now, and should have something to show soon.
-
View post
RE: https://fosstodon.org/@pypi/116414611218430369 It&#39;s still awesome to me that I get to work on some really hard problems for the common good. This was a lot of work, hope you enjoy the read!
-
View post
Incident Report of the recent #PyPI Phishing Campaign TL,DR: โข PyPI was not breached โข PyPI users were targeted with phishing emails โข A single project saw uploads with malicious code and those releases have been removed https://blog.pypi.org/posts/2025-07-31-incident-report-phishing-attack/ #Python #OpenSource #Security
-
View post
Any time I see something like this in a #Python REPL, I can&#39;t help but smile for two reasons: 1. Yes, yes I did forget. 2. I know some of the folks who worked so hard to make that message do exactly what I want it to do. Thanks to Pablo, @ambv, and so many others! #OpenSource
-
View post
Whoa. Cool
-
View post
I really liked this notice that the @biomejs maintainers put in one of their discussions on GitHub. Hopefully folks read it, sadly I suspect the abusers won&#39;t #OpenSource #Maintainer #Sustainability
-
View post
RE: https://fosstodon.org/@pypi/116165865450616991 Thanks @fastlydevs for taking some time to ask me questions and share my responses - it&#39;s quite unique to work on a system like this
-
View post
&lt;personal-rant&gt; Publishing projects to PyPI without a source distribution, links to a source codebase, or other indications of &quot;what might be in this binary package&quot;? is definitely a smell to me when I&#39;m evaluating which projects I want to rely upon. So many projects advertise an #OpenSource License like MIT and Apache-2.0 and do not supply any sources in the &quot;obvious&quot; spots. &lt;/personal-rant&gt;
-
View post
There are many problems with trust-based systems. We can add all the cryptographic proofs we want, all the monitors and witnesses, but ultimately if the end-consumer doesn&#39;t understand well enough how these layers add trustworthiness, they won&#39;t trust the trust system itself, much less the original system. So we&#39;re back to where we started, but we added piles of complexity, ossification of protocols and interchanges. Ultimately, you kind of have to trust someone or somet...
-
View post
Pro tip: If you use @ohmyzsh #python plugin, AND use https://starship.rs/ for prompt decorations, AND set `PYTHON_AUTO_VRUN=true` to automatically activate a virtualenv when you enter a directory, you may see your starship prompt lose it&#39;s style when navigating away in certain circumstances. The fix is to tell the python plugin to leave the prompt alone since starship will handle it with: `VIRTUAL_ENV_DISABLE_PROMPT=1` in your .zshrc #shell
-
View post
RE: https://hachyderm.io/@sustainoss/115707191758680464 This is a great podcast that discusses some of the details by @lorenipsum and @BajoranEngineer on @ThePSF &#39;s rejection of the NSF grant conditions. &quot;We are ALL spine ๐ &quot; --Loren