Archive formats like ZIP and tar can be abused to undermine the integrity of Python package users 📦 Learn how PSF Developer-in-Residence Seth Larson is strengthening Python's security with the #Python community in the new white paper "Slippery ZIPs and Sticky tar-pits" with Alpha-Omega. https://lnkd.in/gU9t5bgf
Every software supply chain relies on archives like ZIP and tar. This paper from Seth Michael Larson helps you understand where unseen risks exist and how the Python ecosystem is advancing stronger safeguards. Learn practical steps that help protect your software at scale. 📄 Read Slippery Zips and Sticky Tar Pits: Security and Archives: https://lnkd.in/eYEuiZ_a By Seth Michael Larson, Python Software Foundation Sponsored by Alpha-Omega #SupplyChainSecurity #Python #OpenSource