Talk Python To Me cover image

Talk Python To Me

#435: PyPI Security

Oct 25, 2023
01:03:23
Snipd AI
Mike Fiedler, PyPI Safety & Security Engineer, discusses the state of PyPI security and plans for the future. They cover challenges of software security, PyPI publishing, working with corporations, package security concerns, and the importance of two-factor authentication. They also talk about the 'p print' package for pretty printing in Python.
Read more

Podcast summary created with Snipd AI

Quick takeaways

  • The Python Software Foundation (PSF) has hired a full-time PyPI safety and security engineer to enhance the security of the Python ecosystem and protect users from potential threats.
  • Two-factor authentication (2FA) will be mandatory for all PyPI publishers starting from the end of 2023, ensuring a higher level of security for the packages and mitigating the risk of compromised accounts.

Deep dives

Importance of Supply Chain Security in Developer Data Science

Supply chain security is a critical concern for developers and data scientists. Attackers often target the supply chain, exploiting vulnerabilities in packages and tools used in the development process. This can lead to the distribution of malicious software and compromise of code and systems. To address these risks, the Python Software Foundation (PSF) has hired a full-time PIPI safety and security engineer, Mike Fiedler. With a focus on PIPI security, the PSF aims to enhance the security of the Python ecosystem and protect users from potential threats.

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode