In the final blog post in a series about @urllib3 a Python package that is downloaded billions of times a year, @bill_nottingham reviews lessons learned and how paying the maintainers makes all of this work possible https://t.co/k0TIsouXbm
In the second blog post in a series about @urllib3, a Python package that is downloaded billions of times a year, we explore how the urllib3 team establishes account security, fine tunes processes, and more https://t.co/lhiV2Dim6Q
In the first in a series of posts about @urllib3, a Python package that is downloaded billions of times a year, we dive into how maintainers keep the project secure (and why you should care) https://t.co/wfUYBesBqL
Introducing the brand new Sigstore landscape!
As the ecosystem grows quickly, this landscape (which is part of @theopenssf ) highlights:
- @projectsigstore projects
- integrations
- signed projects
- language clients
- case studies
& more!
https://t.co/vaAQIdm25h
today's video is about a neat python packaging hack that `urllib3` did to deprecate `urllib[secure]` -- I explain how it works and why it's such a clever idea -- https://t.co/lTnEpa64rm
New from Scorecards - Badges that show off your hard work to improve security practices - especially useful for maintainers to assess dependencies at a glance https://t.co/XyF54W7WbW Examples from @TensorFlow@FlutterDev@urllib3
In a wholesome collaboration between open source projects, @SeleniumHQ quickly merged and released a deprecation warning fix submitted by the @urllib3 team, making it actionable for all users 🤗
PSA: urllib3 v2.0 (due later this year) will follow Python 3.10 and PEP 644 by only supporting OpenSSL 1.1.1 and greater, not alternatives like LibreSSL. This will increase the security of all our users and will help us move faster!
📦urllib3 v1.26.12 has been released! 🎉
This release deprecates the urllib3[secure] extra and the urllib3.contrib.pyopenssl module. Both will be removed in a future v2.x version.
This release is also the first with SLSA provenance information: https://t.co/MSclv4BDy2
Just released version 0.2.0 of Sublime REST Client 🚀 Powered by @urllib3
If you use Sublime Text 4 give it a try, let me know what you think
https://t.co/NdT3foXn14
CPython has experimental support for OpenSSL 3.0 with "known performance regressions, missing features and potential bugs".
Major distributions ship Python with OpenSSL 3.0 though, which breaks urllib3 tests. 😿
Help us understand why and get paid $300! https://t.co/xoJ3c89Po3