Mila Zhou recently sat down with Yesenia Yser on the What's in the SOSS podcast to share her path from accounting to her role as a Senior Open Source & Security Program Manager at Amazon Web Services (AWS). openssf.org/podcast/2026...
Mike Fiedler
@miketheman.com
Code Gardener. Wrangler of the Unusual. Roller Derby referee. AWS Hero. PyPI Maintainer. Shakshuka lover. he/him https://miketheman.dev
I can't be the first to discover that a Pillsbury biscuit with chipotle mayo is delicious?
🗳️ Nominations for the inaugural Python Packaging Council election are open! Help shape how Python packages are built, distributed, and installed—the council needs consensus-builders who bring the packaging community together. Nominate yourself or someone else by Tuesday, August 11th, 2:00 pm UTC.
Get Ready: Python Packaging Council Nominations Opening Soon!
pyfound.blogspot.com
You can be a part of guiding the future direction of the PSF 🩵🐍💛 Nominate yourself or someone else for the PSF Board for the 2026 election! Nominations open Tuesday, July 28th, 2:00 pm UTC and close Tuesday, August 11th, 2:00 pm UTC. #python
Get Ready: PSF Board Nominations Opening Soon!
Who runs for the PSF Board? People who care about the Python community, who want to see it flourish and grow, and also have a few hours a month to attend regular meetings, serve on committees, participate in conversations, and promote the Python community. We're looking for candidates with a diverse range of skills and backgrounds, including leadership experience, fundraising knowledge, non-profit familiarity, and event organizing. Technical expertise, a record of collaboration, and experience speaking or teaching in the Python community are also all qualities we hope to see in Board members.Want to learn more about being on the PSF Board? Check out the following resources to learn more about the PSF, as well as what being a part of the PSF Board entails:
pyfound.blogspot.com
I'm about to head home after a truly amazing experience at my first #EuroPython. I was honored to be able to share some stories, but more importantly I met a bunch of awesome people. Kudos to the @europython.eu organization and all the folks who make magic happen!
I'm speaking today at #EuroPython about learning from the #Python #Security Response Team and how to become a "Security Contributor" to an Open Source project. The talk is in Room S1 at 16:00 right before the evening keynote: ep2026.europython.eu/session/lear...
Learning from the not-so-secret Python security "cabal"
It’s dangerous to go alone! 🐍🛡️ Learn sustainable open source security practices for projects of all sizes from the Python Security Response Team.
ep2026.europython.eu
Excited for the #EuroPython morning keynote today from @yossarian.net, starting at 9AM in S1: ep2026.europython.eu/session/secu...
Securing Python for the next decade
The next decade will challenge many assumptions in Python security. Join us for a session of speculation on secxuring the next decade.
ep2026.europython.eu
Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year. ep2026.europython.eu/session/anat... #EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security
We are pretty serious about learning out here at #EuroPython2026 and super stoked to have Guido with us here 🐍 ❤️
If you’re a software engineer, designer, or technologist who wants to help make City government work better and faster, apply to join our PIT crews at nyc.gov/pitcrew.
New TIL: Using uvx in GitHub Actions in a cache-friendly way I finally found a recipe that I like for running `uvx tool-name` in GitHub Actions without downloading a fresh copy of the package every time til.simonwillison.net/github-actio...
Using uvx in GitHub Actions in a cache-friendly way
I often find myself wanting to run a quick Python tool inside of GitHub Actions using uvx name-of-tool - but I don't want that to result in a network request to PyPI every time the workflow runs. I wa...
til.simonwillison.net
Join @miketheman.com at EuroPython for "Security and Ethics in the Age of Generative AI" ep2026.europython.eu/N9HKQN
Something's brewing. AWS Heroes arguing about cloud computing like it personally wronged them. Episode one in the works. Follow for more. yellsatcloudpod.com
Yells at Cloud - A podcast by AWS Heroes
A podcast where AWS Heroes argue about cloud computing like it personally wronged them. Strong opinions, real experience, disagreement guaranteed.
yellsatcloudpod.com
We’re thrilled to welcome our new #PyConUS Conference Co-Chair and future Conference Chair, Kattni! 🎉 Learn more about Kattni here: pycon.blogspot.com/2026/07/welc... 🗓️ Mark your calendars for #PyConUS 2027, May 12th-18th back in Long Beach, CA
Welcome, Kattni!
We are thrilled to welcome Kattni as the next Co-Chair and future Chair of PyCon US! You may already know Kattni from her work on CircuitPy...
pycon.blogspot.com
Some days I wonder if the supply chain attackers are hoping I'll giggle before swinging the banhammer The creativity of some of these folks is wasted on scamming
Sunday morning, coffee's on, laptop open. Nobody asked me to fix this. It might still be broken Monday, sure. but it's broken **better**! #OpenSource: the sometimes unglamorous work, done in public, one commit at a time.
Very excited to share stories, insights, recommendations at my first @europython.eu I'll also be attending the Packaging and Language Summits, as well as any other opportunities to increase awareness of #Python and #PyPI #OpenSource #SupplyChain #Security initiatives. #EP2026 #TooManyHashtags
Join Mike Fiedler (@miketheman.com) at EuroPython for "Anatomy of a Phishing Campaign" talk: ep2026.europython.eu/NXNHSB
Great coverage from @lwndotnet.bsky.social of the PSF PyPI Safety & Security Engineer @miketheman.com's talk on Trusted Publishing at Open Source Summit. 36% of PyPI uploads now use Trusted Publishing. Is yours one of them? lwn.net/Articles/107... #Python #PyPI #OSSumit #Security
Eliminating long-lived credentials with trusted publishing
Trusted publishing is an authentication mechanism that relies on short-lived credentials to red [...]
lwn.net
This is what collaborative, coordinated, responsible disclosure looks like. It was a pleasure to work with @gitguardian.com on this #PyPI #security investigation to help protect the global #Python #SupplyChain blog.gitguardian.com/hunting-leak...
Hunting Leaked PyPI Tokens: 62 Live, 125 Packages Exposed
We found 62 live PyPI tokens leaking on public sources, enough to push malicious code to 125 packages with 25,000 monthly downloads. We reported them to PyPI, which revoked every one. Here's how we de...
blog.gitguardian.com
Look! It's @sethmlarson.dev and I at the #UNOpenSourceWeek ! We presented, facilitated, and listened to others. #Python #OpenSource #Security #WhatAWeirdJob
Watch PSF PyPI Safety & Security Engineer @miketheman.com's talk from Open Source Summit NA 2026: Trusted Publishing uses OIDC to generate short-lived tokens from CI/CD. No passwords. No tokens to rotate. No secrets in repos. www.youtube.com/watch?v=i0BW... #Python #PyPI #OSSummit #Security
Trusted Publishing: Eliminating Credentials From Your Release Workflow - Mike Fiedler
YouTube video by The Linux Foundation
youtube.com
Join Mike Fiedler (@miketheman.com) at EuroPython for "Anatomy of a Phishing Campaign" talk: ep2026.europython.eu/NXNHSB
Building on last year’s success, we are bringing the #maintainathon back to #UNOpenSourceWeek 🇺🇳 Together with the United Nations Office for Digital and Emerging Technologies, the Sovereign Tech Agency is hosting the maintain-a-thon, facilitated and led by the experts from our delegation:
It was an honor to speak to a room full of people curious about how #phishing maintainers led to a #SupplyChain incident and some ideas on how to harden workflows to prevent
Did you miss #PyConUS this year? 🐍🛡️ Here's a summary of everything security at @pycon.us 2026, including the new security talk track, an update from PSF security engineers, and notes from the OSS maintainer security open space. #Security #OpenSource #SupplyChain #SBOM
I'm starting to really think that the main benefit of the new waves of AI is exposing every business process weakness. Case and point: if you have terrible dev docs, test/validation steps, generative agents will produce about the same quality as an unguided junior dev
The PSF's Strategic Plan full draft is available and we want your feedback. After sharing high-level goals in May, we're opening a 3-week community feedback window. Read the full draft and tell us: Are these the right goals? Is anything missing? #Python #PyPI pyfound.blogspot.com/2026/06/psf-...
One behavioral modification of doing career switches between individual contributor and manager (and back!) is that manager-speak trains you to use "we" when referring to the work your team has accomplished, since it's not "you" per se - giving credit where credit is due