Planet Python
Follow
Python Software Foundation: Everything Security at PyCon US 2026
PyCon US 2026 highlighted significant developments in Python security. A new dedicated security track, "Trailblazing Python Security," featured talks on topics like phishing, zero trust, Rust for CPython, and SBOM generation. The Python Software Foundation (PSF) reported an increase in both package publishing and malware on PyPI. An Open Space session focused on security challenges for open source project maintainers. Discussions centered on hardening CI/CD pipelines and managing an overwhelming volume of vulnerability reports, often generated by LLMs. Maintainers explored strategies for handling these reports, considering the increased workload and the rise of low-quality submissions. The use of security policies and threat models was encouraged to mitigate LLM-driven issues. A meta-conversation addressed the need for "contributor quality signals" to help maintainers prioritize their time. Alpha-Omega's sponsorship supports key security roles at the PSF, including the Security Developer-in-Residence and PyPI Safety & Security Engineer. Updates included changes to the Python Security Response Team (PSRT) governance and efforts to mitigate malware and supply-chain attacks on PyPI.