yossarian.net / blog.yossarian.net
https://blog.yossarian.net/2025/12/29/Some-flexibility-with-Go-s-sumdb
#security #go #cryptography
https://blog.yossarian.net/2025/12/29/Some-flexibility-with-Go-s-sumdb
#security #go #cryptography
Time to setup zizmor.sh by @yossarian.net for automated scanning, I've had it in my "tools to try" list for a bit.
Time to setup zizmor.sh by @yossarian.net for automated scanning, I've had it in my "tools to try" list for a bit.
#python #supplychain #opensource #oss
pycon.blogspot.com/2025/11/trai...
#python #supplychain #opensource #oss
pycon.blogspot.com/2025/11/trai...
@yossarian.net to provide static analysis of GitHub Actions workflows as I'm working on them. The remediation advice is also top notch, for `pull_request_target` as an example: docs.zizmor.sh/audits/#dang...
@yossarian.net to provide static analysis of GitHub Actions workflows as I'm working on them. The remediation advice is also top notch, for `pull_request_target` as an example: docs.zizmor.sh/audits/#dang...
TL,DR: Adopt Trusted Publishing 🔐🚀📦
blog.pypi.org/posts/2025-1...
TL,DR: Adopt Trusted Publishing 🔐🚀📦
blog.pypi.org/posts/2025-1...
https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
#security #oss
https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
#security #oss
https://blog.yossarian.net/2025/09/22/dear-github-no-yaml-anchors
#programming #rant
https://blog.yossarian.net/2025/09/22/dear-github-no-yaml-anchors
#programming #rant
- RubyCentral have managed this exceptionally poorly in many ways including removing literally the most active member of the RubyGems organisation by mistake who has declined to return
- RubyCentral have managed this exceptionally poorly in many ways including removing literally the most active member of the RubyGems organisation by mistake who has declined to return
https://blog.yossarian.net/2025/09/14/one-year-of-zizmor
#devblog #programming #rust #zizmor
It's got internal runtime update, housekeeping, also diagnostic messages and security improvements from @yossarian.net!
github.com/pypa/gh-acti... / github.com/pypa/gh-acti...
#python #Packaging
It's got internal runtime update, housekeeping, also diagnostic messages and security improvements from @yossarian.net!
github.com/pypa/gh-acti... / github.com/pypa/gh-acti...
#python #Packaging
securitycryptographywhatever.com/2025/08/22/s...
securitycryptographywhatever.com/2025/08/22/s...
blog.pypi.org/posts/2025-0...
blog.pypi.org/posts/2025-0...
How I think about it is as a way to deflake tests by simulating an infinitely fast processor (because time doesn’t move until all work is done), and then shorten them by compressing time (because time jumps once it moves).
📝 Release notes: https://go.dev/doc/go1.25
⬇️ Download: https://go.dev/dl/#go1.25.0
#golang
How I think about it is as a way to deflake tests by simulating an infinitely fast processor (because time doesn’t move until all work is done), and then shorten them by compressing time (because time jumps once it moves).
https://blog.yossarian.net/2025/08/14/Fun-with-finite-state-transducers
#devblog #programming #rust #zizmor
https://blog.yossarian.net/2025/08/14/Fun-with-finite-state-transducers
#devblog #programming #rust #zizmor
We think of pyx as an optimized backend for uv: it’s a package registry, but it also solves problems that go beyond the scope of a traditional "package registry".
We think of pyx as an optimized backend for uv: it’s a package registry, but it also solves problems that go beyond the scope of a traditional "package registry".
this release comes with one new audit (unsound-condition), support for auto-fixing three more finding classes, plus much more in the way of general enhancements and bug fixes.
full details here:
docs.zizmor.sh/release-note...
this release comes with one new audit (unsound-condition), support for auto-fixing three more finding classes, plus much more in the way of general enhancements and bug fixes.
full details here:
docs.zizmor.sh/release-note...