The #PyConUS #Security Track fires back up after lunch! See you at 1:45PM in Room 103ABC where Python core developer Emma Smith (@emmatyping) will be talking about โRust and CPythonโ.
Don't miss it!! ๐ฆ๐
The #PyConUS #Security Track fires back up after lunch! See you at 1:45PM in Room 103ABC where Python core developer Emma Smith (@emmatyping) will be talking about โRust and CPythonโ.
Don't miss it!! ๐ฆ๐
Ask HN: How do you defend against supply chain attacks today?
์ต๊ทผ NPM๊ณผ PyPI ํจํค์ง์์ ์ํํธ์จ์ด ๊ณต๊ธ๋ง ๊ณต๊ฒฉ์ด ๋น ๋ฅด๊ฒ ์ฆ๊ฐํ๊ณ ๋ณต์กํด์ง๊ณ ์๋ค. ๊ธฐ์กด ์์กด์ฑ ์ค์บ๋๋ ๋์ ์๋๊ฐ ๋๋ฆฌ๊ณ , ์๋ ์ ๋ฐ์ดํธ๋ ์ ์ฑ์ฝ๋ ํฌํจ ์ํ์ด ์์ด ํจ๊ณผ์ ์ด์ง ์๋ค. ๋ชจ๋ ์์กด์ฑ ๋ฒ์ ์ ์ผ์ผ์ด ๊ฐ์ฌํ๋ ๊ฒ์ ๋น์ฉ์ด ๋ง์ด ๋ค๊ธฐ ๋๋ฌธ์, ๊ฐ๋ฐ์๋ค์ ๋ณด๋ค ํจ์จ์ ์ด๊ณ ์ ์ํ ๊ณต๊ธ๋ง ๊ณต๊ฒฉ ๋ฐฉ์ด ์ ๋ต์ ๋ชจ์ ์ค์ด๋ค.
https://news.ycombinator.com/item?id=48134972
#supplychainsecurity #npm #pypi #dependencysecurity #softwaresecurity
<at my funeral>: "And I leave my remaining wealth to the first heir to contractually agree with the estate to maintain my 55 #pypi packages and update them forever."
I'm pretty sure that is what companies think open source maintainers do.
BEEP, BEEP - I am your friendly #Snakemake release announcement bot.
There is a new release of Snakemake. Its version now is 9.21.0!
Give us some time, and you will automatically find it on #Bioconda and #Pypi.
The maintainer is here on Mastodon -
@johanneskoester .
If you discover any issues, please report them on https://github.com/snakemake/snakemake/issues.
See https://github.com/snakemake/snakemake/releases/tag/v9.21.0 for details. Here is the header of the changelog:
๐
๐๐๐๐๐ ๐ ๐๐๐ก๐๐ (๐๐๐ ๐ ๐๐๐๐ฆ ๐๐๐๐๐๐๐๐):
๐
๐๐๐ญ๐ฎ๐ซ๐๐ฌ
* add a function to help with prepending arguments to filenames; close [#672]: https://github.com/snakemake/snakemake/issues/672, https://github.com/snakemake/snakemake/issues/4090
๐๐ฎ๐ ๐ ๐ข๐ฑ๐๐ฌ
* close plugin handlers after draining QueueListener in LoggerManager.stop: https://github.com/snakemake/snakemake/issues/4137
๐๐๐ซ๐๐จ๐ซ๐ฆ๐๐ง๐๐ ๐๐ฆ๐ฉ๐ซ๐จ๐ฏ๐๐ฆ๐๐ง๐ญ๐ฌ
* adjust default sqlite PRAGMAs, auto detect network fstype: https://github.com/snakemake/snakemake/issues/4152
Malware Worm Targets npm, PyPi in Mass Supply-Chain Attack
A self-spreading worm, dubbed Mini Shai-Hulud, has infected over 170 packages with nearly 180 million weekly downloads, posing a massive threat to the software supply chain. This highly contagious malware has been open-sourced, making it easier for others to exploit and escalate the attack.
"Bei den meisten ... handelt es sich um NPM-Pakete. ... aber auch Pakete aus dem Python Package Index (PyPI) betroffen, etwa von Mistral AI und Guardrails AI. Die Angreifer haben jeweils Schadcode eingeschleust, der der bereits genannten Datenausleitung dient. Auf die Zielsysteme gelangt er in Form einer rund 2,3 MByte groรen und stark verschleierten Datei namens router_init.js."
#pypi ist tief in #ai und ein war Argument fรผr die Grรผndung von
@sovtechfund