How to secure your software with Python archives

Every software supply chain relies on archives like ZIP and tar. This paper from Seth Michael Larson helps you understand where unseen risks exist and how the Python ecosystem is advancing stronger safeguards. Learn practical steps that help protect your software at scale. 📄 Read Slippery Zips and Sticky Tar Pits: Security and Archives: https://lnkd.in/eYEuiZ_a By Seth Michael Larson, Python Software Foundation Sponsored by Alpha-Omega #SupplyChainSecurity #Python #OpenSource

  • No alternative text description for this image

Fantastic read Seth Michael Larson. At the Reproducible Build Summit I had not one, but few discussions that started with "Should we develop a new archive standard specifically targeted for reproducible packages ?". And reading the document like yours make me think that maybe it's actually a good idea - and maybe we - the open source industry - that have common packaging needs, solving the same reproducibility issues over and over could actually come up with a better packaging formats and tools. Michael Winser - as you are stil in Vienna, maybe that is an idea worth funding ?

See more comments

To view or add a comment, sign in

Explore content categories