Reviewing open source trends in 2025 - Duck Alignment Academy
How well did I capture trends in open source for 2025? The vibe was right, even if some of the specifics were wrong.
Follow-up on the recent phishing attack targeting PyPI users.
How well did I capture trends in open source for 2025? The vibe was right, even if some of the specifics were wrong.
Wire pip-audit into your CI and unit tests to automatically block known vulnerable dependencies.
Project compromises have common root causes we can mitigate: phishing, control handoff, and unsafe GitHub Actions triggers.