Search
1000 results for “pycon”
-
-
-
Want help navigating #PyConUS? Check out Newcomers orientation for some tips! 4:30pm at the Pacific Ballroom. All are welcome!
Bonus: you'll get access to the super awesome 2nd entrance to the reception! https://us.pycon.org/2026/events/newcomer-orientation/ -
-
Okay #PyConUS peeps, I haven't had lunch and will definitely be looking to get a bite after my ~3 PM check-in. Any recs near the conference center for something light or people in the same position who wanna do late lunch?
-
Remember to use your scaffolding to keep students in that zone of proximal development, and *always* reflect! - Elizabeth Bacon @ the #pycon Education Summit
-
Remember to use your scaffolding to keep students in that zone of proximal development, and *always* reflect! - Elizabeth Bacon @ the #pycon Education Summit
-
When we design instruction, we must think about what kinds of cognitive processes we want students to engage in and what kinds of authentic tasks encourage that process.
Motivate students with context, explain how the skill is really used, scaffold enough for students to complete a meaningful portion of the task, and then assess/reflect on it. - Elizabeth Bacon @ the #pycon Education Summit
-
When we design instruction, we must think about what kinds of cognitive processes we want students to engage in and what kinds of authentic tasks encourage that process.
Motivate students with context, explain how the skill is really used, scaffold enough for students to complete a meaningful portion of the task, and then assess/reflect on it. - Elizabeth Bacon @ the #pycon Education Summit
-
We still have many authentic skills and practices that students will be very much expected to use as future developers, including the decomposition, using documentation, and communication! - Elizabeth Bacon @ the #pycon Education Summit
-
We still have many authentic skills and practices that students will be very much expected to use as future developers, including the decomposition, using documentation, and communication! - Elizabeth Bacon @ the #pycon Education Summit
-
CS Students have always been able to copy from StackOverflow, so giving the right answer without understanding is not new. However, students are newly extra-tempted to offload cognitive work in ways that do not serve them well, and there are distractions with screens. - Elizabeth Bacon @ the #pycon Education Summit
-
CS Students have always been able to copy from StackOverflow, so giving the right answer without understanding is not new. However, students are newly extra-tempted to offload cognitive work in ways that do not serve them well, and there are distractions with screens. - Elizabeth Bacon @ the #pycon Education Summit
-
We ate lunch, I'm awake, and up next at the #pycon Education Summit is Elizabeth Bacon with a talk on Scaffolding CS Activities! 🎉
-
We ate lunch, I'm awake, and up next at the #pycon Education Summit is Elizabeth Bacon with a talk on Scaffolding CS Activities! 🎉
-
Other things to do as maintainers:
- Do a threat model analysis on your own software -- "What isn't a vuln?"
- Create a security policy; github will support a SECURITY.md
- Having a CoC helps set standards for respecting maintainer time
- .well-known/security.txt, look at https://securitytxt.org/
- Handle vuln reporting, as internal tickets, to the best of your ability -
So what can package maintainers do to help?
Know who to call: [email protected] and [email protected]
Look into Zizmor, then CodeQL, Semgrep, Fuzzer, LLM
-
So what can package maintainers do to help?
Know who to call: [email protected] and [email protected]
Look into Zizmor, then CodeQL, Semgrep, Fuzzer, LLM
-
So what can package maintainers do to help?
Know who to call: [email protected] and [email protected]
Look into Zizmor, then CodeQL, Semgrep, Fuzzer, LLM
-
So what can package maintainers do to help?
Know who to call: [email protected] and [email protected]
Look into Zizmor, then CodeQL, Semgrep, Fuzzer, LLM
-
So what can package maintainers do to help?
Know who to call: [email protected] and [email protected]
Look into Zizmor, then CodeQL, Semgrep, Fuzzer, LLM
-
Next Goal: Improving Python Ecosystem Vuln response capacity
This means:
- Threat model guide (@sethmlarson is sprinting on this!)
- Scanning projects
- Sec. Engineer time to respond more
- Incident response that's more than just "when Seth and Mike are working" -
Next Goal: Improving Python Ecosystem Vuln response capacity
This means:
- Threat model guide (@sethmlarson is sprinting on this!)
- Scanning projects
- Sec. Engineer time to respond more
- Incident response that's more than just "when Seth and Mike are working" -
Next Goal: Improving Python Ecosystem Vuln response capacity
This means:
- Threat model guide (@sethmlarson is sprinting on this!)
- Scanning projects
- Sec. Engineer time to respond more
- Incident response that's more than just "when Seth and Mike are working" -
Next Goal: Improving Python Ecosystem Vuln response capacity
This means:
- Threat model guide (@sethmlarson is sprinting on this!)
- Scanning projects
- Sec. Engineer time to respond more
- Incident response that's more than just "when Seth and Mike are working" -
Next Goal: Improving Python Ecosystem Vuln response capacity
This means:
- Threat model guide (@sethmlarson is sprinting on this!)
- Scanning projects
- Sec. Engineer time to respond more
- Incident response that's more than just "when Seth and Mike are working" -
How else are Watering Hole Attacks being mitigated?
- Trusted Reporters / Auto-Quarantine
- More Trusted Publishing providers
- sudo mode and more scoped privileges
- "Staged Releases"
- "Secure Distributions" for CPythonMore Trusted Publishing Providers is desired! Warehouse is open source and PRs are welcome.
-
How else are Watering Hole Attacks being mitigated?
- Trusted Reporters / Auto-Quarantine
- More Trusted Publishing providers
- sudo mode and more scoped privileges
- "Staged Releases"
- "Secure Distributions" for CPythonMore Trusted Publishing Providers is desired! Warehouse is open source and PRs are welcome.
-
How else are Watering Hole Attacks being mitigated?
- Trusted Reporters / Auto-Quarantine
- More Trusted Publishing providers
- sudo mode and more scoped privileges
- "Staged Releases"
- "Secure Distributions" for CPythonMore Trusted Publishing Providers is desired! Warehouse is open source and PRs are welcome.