<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Jupyter Blog - Joe Lucas</title><link href="https://jasongrout.github.io/medium-archive/pelican/" rel="alternate"/><link href="https://jasongrout.github.io/medium-archive/pelican/feeds/author-joe-lucas.atom.xml" rel="self"/><id>https://jasongrout.github.io/medium-archive/pelican/</id><updated>2026-03-20T19:47:00+00:00</updated><subtitle>The Project Jupyter blog: news, releases, and community stories, archived from blog.jupyter.org.</subtitle><entry><title>Jupyter Security Sprint March 31st</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2026/jupyter-security-sprint-march-31st/" rel="alternate"/><published>2026-03-20T19:47:00+00:00</published><updated>2026-03-20T19:47:00+00:00</updated><author><name>Joe Lucas </name></author><id>tag:jasongrout.github.io,2026-03-20:/medium-archive/pelican/posts/2026/jupyter-security-sprint-march-31st/</id><summary type="html">&lt;p&gt;This is a critical moment for open source software. AI enables new contributors in new ways, but maintainers are also faced with an…&lt;/p&gt;
</summary><content type="html">&lt;p&gt;&lt;img src="https://jasongrout.github.io/medium-archive/pelican/posts/2026/jupyter-security-sprint-march-31st/images/001-1_OphBxiSYkkxD-KWM4wcatA.webp" alt="" loading="lazy" data-body-image=""&gt;&lt;/p&gt;
&lt;p&gt;This is a critical moment for open source software. AI enables new contributors in new ways, but maintainers are also faced with an unprecedented volume of contributions and security reports. This speed also puts pressure on maintainers and the processes that keep projects secure and reliable.&lt;/p&gt;
&lt;p&gt;At the same time, there have been significant recent advances in tooling for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;dependency analysis&lt;/li&gt;
&lt;li&gt;vulnerability scanning&lt;/li&gt;
&lt;li&gt;supply chain security&lt;/li&gt;
&lt;li&gt;automated security checks in CI pipelines&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;But many open source software projects still struggle to evaluate and integrate these tools into their workflows.&lt;/p&gt;
&lt;h2 id="the-security-tooling-sprint"&gt;The Security Tooling Sprint&lt;/h2&gt;
&lt;p&gt;To help address this challenge, the Linux Foundation and the Berkeley Institute for Data Science (BIDS) are hosting the &lt;a href="https://events.linuxfoundation.org/security-tooling-sprint/"&gt;Security Tooling Sprint&lt;/a&gt; on March 31st. This sprint will bring together maintainers, security experts, and contributors to explore how security tooling can better support the secure development of &lt;a href="https://jupyter.org/"&gt;Project Jupyter&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Participants will work to understand what tools exist, what problems they solve, and how they can be used in real projects.&lt;/p&gt;
&lt;h2 id="what-we-will-do"&gt;What We Will Do&lt;/h2&gt;
&lt;p&gt;During the sprint, participants will work together to explore the current landscape of security tooling and apply it to real workflows.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://events.linuxfoundation.org/security-tooling-sprint/program/schedule/"&gt;Activities will include&lt;/a&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;identifying common maintainer pain points&lt;/li&gt;
&lt;li&gt;reviewing the modern security tooling ecosystem&lt;/li&gt;
&lt;li&gt;experimenting with tools in real project environments&lt;/li&gt;
&lt;li&gt;sharing results and ideas with the group&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The event focuses on collaboration and hands-on exploration in order to derive actionable recommendations back as issues and pull requests.&lt;/p&gt;
&lt;h2 id="why-this-matters-for-jupyter"&gt;Why This Matters for Jupyter&lt;/h2&gt;
&lt;p&gt;Project Jupyter is used by millions of people in research, education, and industry. Like many open source projects, it relies on a global community of maintainers and contributors volunteering their time, energy, and expertise.&lt;/p&gt;
&lt;p&gt;Improving security practices helps protect users while reducing maintainer burden and strengthening trust in the ecosystem.&lt;/p&gt;
&lt;h2 id="join-us"&gt;Join Us&lt;/h2&gt;
&lt;p&gt;If you are interested in open source security, developer tooling, or the future of the Jupyter ecosystem, we encourage you to participate.&lt;/p&gt;
&lt;p&gt;Learn more and &lt;a href="https://events.linuxfoundation.org/security-tooling-sprint/"&gt;register here&lt;/a&gt;. We hope you will join us in Berkeley and help improve how to evolve how open source communities approach security.&lt;/p&gt;
</content><category term="security"/></entry></feed>