TGViewer
Computer Science and Programming Computer Science and Programming @computer_science_and_programming · 140K subscribers
Post #2207 15.8K
Open source security at Astral
Astral shares the security practices they use to protect their open source tools (Ruff, uv, ty) from supply chain attacks. Key areas covered include: hardening GitHub Actions CI/CD by banning dangerous triggers like pull_request_target, pinning all actions to commit SHAs, limiting permissions, and isolating secrets in deployment environments. For releases, they use Trusted Publishing to eliminate long-lived credentials, Sigstore-based attestations, immutable releases, and two-person approval gates. They also use GitHub Apps to safely handle tasks that GitHub Actions can't do securely, maintain dependency hygiene with Dependabot/Renovate plus cooldowns, and contribute financially and technically to upstream projects. The post includes shareable GitHub rulesets and practical recommendations for other maintainers.
  • ❤ 9
  • 👍 8
  • 👨‍💻 1
More from @computer_science_and_programming
  1. Oct 3, 2026BYD says it will have a solid-state car next year, the earliest date anyone has given BYD…
  2. Oct 1, 2026Introducing G#: A Go-like language for .NET G# is a new open-source, Go-inspired programmi…
  3. Sep 30, 2026Chrome for Developers Chrome 146 introduces three notable features for web developers. Scr…
  4. Sep 26, 2026Introduction to Solon A comprehensive tutorial walks through building a REST API with Solo…
  5. Sep 25, 2026The strangler fig pattern: modernizing without a big-bang rewrite A detailed guide to the…
  6. Sep 24, 2026Lessons From Four Years of Writing a Weekly Newsletter A .NET blogger reflects on four yea…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →