TL;DR: I’m announcing my candidacy for the inaugural Python Packaging Council. I hope you’ll honor me with your vote, if you’re a voting member of the PSF, but regardless I have high hopes (and expectations) for the council.
TL;DR: GitHub Actions should allow end-users to express audience constraints, to make it harder for an attacker to pivot across services that use independent OIDC-bearing jobs. They could do this with relatively small syntax tweak, although the backend implications are probably nontrivial.
(Thanks to Facundo Tuesca for the name inspiration). If you’re like me, you spend a lot of your working day (and a good chunk of your personal time) reading code online. Increasingly, that means accidentally reading a lot of “slop” 1 . Personally, slop isn’t annoying per se 2 : it’s okay for personal software 3 , for example, to be slop. What makes slop annoying is the feeling of being…
I spend some of my hobby time doing vulnerability triage on open source projects. As part of that, I see (and filter through) a lot of nonsense1. Spam, “beg bounty” submissions, and increasingly zero-effort LLM submissions.