EuroPython 2026: Learning from the “not-so-secret” Python security cabal
I delivered this talk at EuroPython 2026, I'll update this blog post once the recording is available onEuroPython's YouTube channel. Below are the slides and full list of links and resources included. This talk is a continuation of a talk I gave a year ago: “Security Work isn’t Special” as the keynote for OpenSSF Community Day NA where I lamented on how security work didn't match other Open Source contribution models like documentation, community, or code contributions.
more
My work as the Security Developer-in-Residence at the Python Software Foundation is sponsored byAlpha-Omega. Thanks to Alpha-Omega for supporting security in the Python ecosystem.
Links and ResourcesSlidesPython Software Foundation BlogPython Insider BlogSecurity Work isn’t SpecialSecurity Line Goes Up by Hugo van Kemenade
Vulnerability Reports are not special anymore by Filippo ValsordaLLM generated vulnerabilities by Linus TorvaldsPython Security Policy and Threat ModelPython Security Response TeamPEP 811 - Defining Python Security Response Team membership and responsibilities
Thanks for reading ♥ I would love to hear your thoughts! Contact me via Mastodon, Bluesky, or email. Browse the blog archive. Check out my blogroll.