Discussion
Loading...

#Tag

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
pvergain (framapiaf) boosted
Python Software Foundation
@ThePSF@fosstodon.org  ·  activity timestamp 3 days ago

PyPI serves billions of requests daily- but sustaining it isn’t free. The PSF joined the OpenSSF & others in calling for organizations to invest in sustainable open infrastructure. Learn what this means for #PyPI, the PSF, & how our community can pitch in:
https://pyfound.blogspot.com/2025/10/open-infrastructure-is-not-free-pypi.html

Python Software Foundation Blog

Open Infrastructure is Not Free: PyPI, the Python Software Foundation, and Sustainability

In September, the Python Software Foundation (PSF) co-signed the Open Infrastructure is Not Free: A Joint Statement on Sustainable Stewardsh...
  • Copy link
  • Flag this post
  • Block
Python Software Foundation
@ThePSF@fosstodon.org  ·  activity timestamp 3 days ago

PyPI serves billions of requests daily- but sustaining it isn’t free. The PSF joined the OpenSSF & others in calling for organizations to invest in sustainable open infrastructure. Learn what this means for #PyPI, the PSF, & how our community can pitch in:
https://pyfound.blogspot.com/2025/10/open-infrastructure-is-not-free-pypi.html

Python Software Foundation Blog

Open Infrastructure is Not Free: PyPI, the Python Software Foundation, and Sustainability

In September, the Python Software Foundation (PSF) co-signed the Open Infrastructure is Not Free: A Joint Statement on Sustainable Stewardsh...
  • Copy link
  • Flag this post
  • Block
Snakemake Release Robot
@snakemake@fediscience.org  ·  activity timestamp 4 days ago

Beep, Beep - I am your friendly #Snakemake release announcement bot.

There is a new release of the Snakemake executor for #SLURM on #HPC systems. Its version now is 1.9.2!

Give us some time, and you will automatically find the plugin on #Bioconda and #Pypi.

If you want to discuss the release, you will find the maintainers here on Mastodon!
@rupdecat and @johanneskoester

If you discover any issues, please report them on https://github.com/snakemake/snakemake-executor-plugin-slurm/issues.

See https://github.com/snakemake/snakemake-executor-plugin-slurm/releases/tag/v1.9.2 for details. Here is the header of the changelog:

𝑅𝑒𝑙𝑒𝑎𝑠𝑒 𝑁𝑜𝑡𝑒𝑠 (𝑝𝑜𝑠𝑠𝑖𝑏𝑙𝑦 𝑎𝑏𝑏𝑟𝑖𝑔𝑒𝑑):
𝐁𝐮𝐠 𝐅𝐢𝐱𝐞𝐬

* logo: https://github.com/snakemake/snakemake-executor-plugin-slurm/issues/367

GitHub

Release v1.9.2 · snakemake/snakemake-executor-plugin-slurm

1.9.2 (2025-10-28) Bug Fixes logo (#367) (3781f36)
Snakemake HPC logo for Mastodon
Snakemake HPC logo for Mastodon
Snakemake HPC logo for Mastodon
  • Copy link
  • Flag this post
  • Block
Matthew Martin
@mistersql@mastodon.social  ·  activity timestamp 2 weeks ago

Not a replacement for docker. Works like pytest-socket.

Anyhow, looking forward to examples of exploits, which I imagine would be un-monkeypatching or just using other libraries.

Still I think this would be a nice way to seal apps you distribute against highjacked 3rd party libraries that weren't specifically targetting this defense.

Matthew Martin
@mistersql@mastodon.social replied  ·  activity timestamp 2 weeks ago

And why is this called `hermetic-seal?` ? Well after searching for a perfect name I picked `hermetic`, which is 404 on pypi, free to take? Nope, if you register trusted publisher for that name #pypi says it is **taken**!

  • Copy link
  • Flag this comment
  • Block
Charly Coste 🇫🇷 boosted
Python Package Index
@pypi@fosstodon.org  ·  activity timestamp 2 months ago

PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to take over #PyPI accounts through password resets. #Python#OpenSource#SupplyChain#Security
https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/

  • Copy link
  • Flag this post
  • Block
Python Package Index
@pypi@fosstodon.org  ·  activity timestamp 2 months ago

PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to take over #PyPI accounts through password resets. #Python#OpenSource#SupplyChain#Security
https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/

  • Copy link
  • Flag this post
  • Block
STOP OCCUPATION 🍉 S. Costa and 1 other boosted
Seth Larson
@sethmlarson@mastodon.social  ·  activity timestamp 3 months ago

🚨 Be aware there's a potential phishing campaign likely targeting #PyPI / #Python package maintainers:

https://discuss.python.org/t/phishing-attack/100267

  • Copy link
  • Flag this post
  • Block
Seth Larson
@sethmlarson@mastodon.social  ·  activity timestamp 3 months ago

🚨 Be aware there's a potential phishing campaign likely targeting #PyPI / #Python package maintainers:

https://discuss.python.org/t/phishing-attack/100267

  • Copy link
  • Flag this post
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.3.21 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login