Imagining a zero-trust future for PyPI - William Woodruff

  Рет қаралды 23

transparency-dev

transparency-dev

Күн бұрын

Over the past year, PyPI (the default package index for the Python ecosystem) has moved rapidly to adopt digital attestations, building atop the foundations offered by the Sigstore project and previous initiatives like Trusted Publishing. This work has left PyPI itself in a stronger position than ever before, but has not yet meaningfully diminished the amount of trust required by package consumers in PyPI. This talk attempts to tackle the latter: it imagines a hypothetical “zero-trust” future for PyPI, and asks which technologies (whether currently practical and not) could get us to that future.
Speaker
William Woodruff is an Engineering Director at Trail of Bits, a NYC-based consultancy. He splits his time between OSS engineering and running the Ecosystem Security group, which is responsible for contributing security and usability improvements to a wide range of OSS tools and services (PyPI, Homebrew, pip-audit, Sigstore, LLVM, PyCA Cryptography, etc.). Outside of work, William is a maintainer of Homebrew and contributes to a variety of OSS projects. He blogs at blog.yossarian...

Пікірлер
The Next Decade of Software Development - Richard Campbell - NDC London 2023
1:07:05
Living off Microsoft Copilot
42:06
Black Hat
Рет қаралды 23 М.
Friends make memories together part 2  | Trà Đặng #short #bestfriend #bff #tiktok
00:18
How to whistle ?? 😱😱
00:31
Tibo InShape
Рет қаралды 17 МЛН
REAL 3D brush can draw grass Life Hack #shorts #lifehacks
00:42
MrMaximus
Рет қаралды 11 МЛН
Хасанның өзі эфирге шықты! “Қылмыстық топқа қатысым жоқ” дейді. Талғарда не болды? Халық сене ме?
09:25
Демократиялы Қазақстан / Демократический Казахстан
Рет қаралды 346 М.
ICML 2024 Tutorial: Physics of Language Models
1:53:43
Zeyuan Allen-Zhu
Рет қаралды 28 М.
Data Exchange Podcast (Episode 253): Mars Lan of Metaphor
59:33
Gradient Flow
Рет қаралды 1,8 М.
Simple Code, High Performance
2:50:14
Molly Rocket
Рет қаралды 256 М.
The Turing Lectures: The future of generative AI
1:37:37
The Alan Turing Institute
Рет қаралды 613 М.
The Basics of Computing Security: Linux & SQL | Google Cybersecurity Certificate
1:54:38
Google Career Certificates
Рет қаралды 163 М.
Building a Realtime Video and Chat App in React Native with Stream
3:59:43
Shining a new light on Certificate Transparency - Matthew McPherrin
33:29
Friends make memories together part 2  | Trà Đặng #short #bestfriend #bff #tiktok
00:18