HTTPX2 and the Art of the Open-Source Handover
In late August, OpenAI’s Python SDK — one of the most-installed packages on PyPI — quietly completed a migration to
Continue readingHTTPX2 and the Art of the Open-Source Handover
In late August, OpenAI’s Python SDK — one of the most-installed packages on PyPI — quietly completed a migration to
Continue readingHTTPX2 and the Art of the Open-Source Handover
On August 4, 2026, someone took over the GitHub account of the maintainer of keyv, a key-value storage abstraction library
Continue readingThe keyv Worm and the Anatomy of a Modern Supply Chain Attack
The software supply chain has become the soft underbelly of modern applications. While teams harden their APIs, patch their runtimes,
Continue readingSBOMs in Practice: Generating, Scanning, and Surviving Supply Chain Audits
OWASP has released the Top 10:2025 — the eighth edition of its flagship security awareness document — and the changes
Continue readingWhat the OWASP Top 10:2025 Changes Mean for Your Codebase