Security work isn’t glamorous, but it sure beats being pwned. The PSF says its Python Security Response Team (PSRT) shipped 16 vulnerability advisories for CPython and pip last year—record high—and even coordinates to avoid blindsiding the ecosystem (hello, PyPI ZIP differential attack mitigation). Herding cats? More like herding CVEs 😼










