PyCon US 2026 introduced a dedicated security track and highlighted critical efforts by the Python Software Foundation to combat rising supply chain attacks and automated vulnerability report volumes.
Key Points
- PyCon US 2026 featured its first dedicated security track, covering topics like SBOM generation, Rust for CPython, and GitHub Actions security.
- The Python Software Foundation reported a significant increase in malware and watering-hole attacks targeting the Python Package Index (PyPI).
- Open source maintainers discussed the burden of managing high volumes of low-quality vulnerability reports generated by large language models (LLMs).
- Recommended security tools for CI/CD pipelines included Zizmor, gha-update, and dependency locking mechanisms like pip-compile.
- The Alpha-Omega project continues to fund the Security Developer-in-Residence and PyPI Safety & Security Engineer roles to bolster ecosystem defenses.
- PEP 811 was highlighted as a key governance update to improve the capacity of the Python Security Response Team in handling increased workloads.