yossarian

@yossarian@infosec.exchange · Joined ⁨Nov⁩ ⁨2022⁩

open source interloper; attracts bugs easily

אַ ביסל ייִדיש־פּאָסטינג

website
yossarian.net verified
OID
1.3.6.1.4.1.55738

following PEP 833, Python packaging now considers the HTML index representation frozen!

I’m really happy we got this out: IMO it’s a small but very important step towards nudging clients to prefer the JSON index, which is better in every regard.

blog.pypi.org/posts/2026-08-11

blog.pypi.org/posts/2026-08-11-html-index-is-frozen/
blog.pypi.orgThe HTML representation of the index API is now frozen - The Python Package Index BlogPyPI has adopted PEP 833, which

Replying to @⁨yossarian@infosec.exchange⁩

(this officially loosens zizmor's "GHA only" policy. if there are other platforms you care about, help me understand them better here: github.com/orgs/zizmorcore/dis)

github.com/orgs/zizmorcore/discussions/2253
Starting with 1.29.0, I've decided to relax zizmor's unofficial "GitHub Actions" only support policy by adding support for auditing pre-commit hooks and configurations. In a sense this opens the fl...GitHubWhat platforms would you like zizmor to support? · zizmorcore · Discussion #2253Starting with 1.29.0, I've decided to relax zizmor's unofficial "GitHub Actions" only support policy by adding support for auditing pre-commit hooks and configurations. In a sense this opens the fl...

zizmor 1.29.0 is released!

this release comes with a number of enhancements and bug fixes, but the big one is that we now support auditing pre-commit inputs! support is limited to just a single audit for now, but will expand over subsequent releases.

full notes: docs.zizmor.sh/release-notes/#

docs.zizmor.sh/release-notes/#1290
docs.zizmor.shRelease Notes - zizmorAbbreviated change notes about each zizmor release.