EuroPython 2026: Learning from the “not-so-secret” Python security cabal

I delivered this talk at EuroPython 2026, I'll update this blog post once the recording is available onEuroPython's YouTube channel. Below are the slides and full list of links and resources included. This talk is a continuation of a talk I gave a year ago: “Security Work isn’t Special” as the keynote for OpenSSF Community Day NA where I lamented on how security work didn't match other Open Source contribution models like documentation, community, or code contributions.

more

My work as the Security Developer-in-Residence at the Python Software Foundation is sponsored byAlpha-Omega. Thanks to Alpha-Omega for supporting security in the Python ecosystem.

Links and ResourcesSlidesPython Software Foundation BlogPython Insider BlogSecurity Work isn’t SpecialSecurity Line Goes Up by Hugo van Kemenade

Vulnerability Reports are not special anymore by Filippo ValsordaLLM generated vulnerabilities by Linus TorvaldsPython Security Policy and Threat ModelPython Security Response TeamPEP 811 - Defining Python Security Response Team membership and responsibilities

Thanks for reading ♥ I would love to hear your thoughts! Contact me via Mastodon, Bluesky, or email. Browse the blog archive. Check out my blogroll.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论