William Woodruff

  1. Introducing vulnbrocards.com

    TL;DR: I’ve turned my April post on Brocards for vulnerability triage into a more permanent website. You can now link to each brocard directly, like this, without having to worry about link rot1. My blog’s URLs should be very stable, but a separate domain and site ↩

    Published

  2. Running for the Python Packaging Council

    TL;DR: I’m announcing my candidacy for the inaugural Python Packaging Council. I hope you’ll honor me with your vote, if you’re a voting member of the PSF, but regardless I have high hopes (and expectations) for the council.

    Published

  3. GitHub Actions needs OIDC audience constraints

    TL;DR: GitHub Actions should allow end-users to express audience constraints, to make it harder for an attacker to pivot across services that use independent OIDC-bearing jobs. They could do this with relatively small syntax tweak, although the backend implications are probably nontrivial.

    Published

  4. README, not

    (Thanks to Facundo Tuesca for the name inspiration). If you’re like me, you spend a lot of your working day (and a good chunk of your personal time) reading code online. Increasingly, that means accidentally reading a lot of “slop”1. Personally, slop isn’t annoying per se2: it’s okay for personal software3…

    Published

  5. You shouldn’t trust Trusted Publishing

    …because Trusted Publishing isn’t for you (or me) to trust! It’s for the machines.

    Published

  6. Registering my dissatisfaction with GitHub

    Mini-post.

    Published

  7. Brocards for vulnerability triage

    See vulnbrocards.com for a more permanent and maintained list of vulnerability brocards.

    Published

  8. Some flexibility with Go’s sumdb

    I noticed this a year or two ago, but forgot to write it up back then.

    Published

  9. Dependency cooldowns, redux

    See cooldowns.dev for up-to-date information on cooldown adoption across various languages and package ecosystems.

    Published

  10. We should all be using dependency cooldowns

    See cooldowns.dev for up-to-date information on cooldown adoption across various languages and package ecosystems.

    Published