<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Jupyter Blog - Rick Wagner</title><link href="https://jasongrout.github.io/medium-archive/pelican/" rel="alternate"/><link href="https://jasongrout.github.io/medium-archive/pelican/feeds/author-rick-wagner.atom.xml" rel="self"/><id>https://jasongrout.github.io/medium-archive/pelican/</id><updated>2025-03-31T21:24:00+00:00</updated><subtitle>The Project Jupyter blog: news, releases, and community stories, archived from blog.jupyter.org.</subtitle><entry><title>JupyterCon 2025!</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2025/jupytercon-2025/" rel="alternate"/><published>2025-03-31T21:24:00+00:00</published><updated>2025-03-31T21:24:00+00:00</updated><author><name>Rick Wagner</name></author><id>tag:jasongrout.github.io,2025-03-31:/medium-archive/pelican/posts/2025/jupytercon-2025/</id><summary type="html">&lt;p&gt;The Call for Proposals for JupyterCon 2025 is officially open!&lt;/p&gt;
</summary><content type="html">&lt;figure&gt;
&lt;img alt="JupyterCon 2025 banner" src="https://jasongrout.github.io/medium-archive/pelican/posts/2025/jupytercon-2025/images/001-1__2ttDyIYFGjwOobsV8T_vQ.webp" loading="lazy" data-body-image=""&gt;
&lt;figcaption&gt;JupyterCon 2025 will be in San Diego, California, from November 3 to November 6.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;hr&gt;
&lt;p&gt;We’re excited to host this year’s &lt;a href="https://events.linuxfoundation.org/jupytercon/"&gt;JupyterCon&lt;/a&gt; in sunny San Diego, California, from November 3–6, 2025. From its beginnings as IPython in 2001, Project Jupyter has grown to a global scale platform with millions of *.ipynb files on GitHub (not all of which are named Untitled.ipynb!). The Jupyter ecosystem has transformed data science, scientific research, and education and has shaped the way a generation of developers and scientists develop their workflows.&lt;/p&gt;
&lt;h2 id="quick-links"&gt;Quick Links:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://events.linuxfoundation.org/jupytercon/"&gt;JupyterCon website&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://events.linuxfoundation.org/jupytercon/register/"&gt;Register to attend&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://events.linuxfoundation.org/jupytercon/program/cfp/"&gt;Call for proposals&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://events.linuxfoundation.org/jupytercon/sponsor/"&gt;Sponsor JupyterCon&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="about-jupytercon-2025"&gt;About JupyterCon 2025&lt;/h2&gt;
&lt;p&gt;At JupyterCon 2025, we will bring together data scientists, business analysts, scientists, educators, developers, core Project Jupyter contributors, data visualization specialists, and tool creators in a collegial environment to push at the boundaries of what can be done with the Project Jupyter ecosystem.&lt;/p&gt;
&lt;p&gt;The conference begins on Monday, November 3, with technical training tutorials and workshops, followed by two days of keynote talks and breakout sessions, and ending on November 6 with a day of community-led technical sprints. Attendees can expect in-depth training, insightful keynotes, networking, and practical talks that expand our collective knowledge of what the Project Jupyter platform can do. JupyterCon focuses on real-world practices and how to successfully implement interactive computation in your workflow and projects.&lt;/p&gt;
&lt;p&gt;We’re &lt;a href="https://events.linuxfoundation.org/jupytercon/program/cfp/"&gt;seeking proposals&lt;/a&gt; for Presentations (Talks), Tutorials, Group Sessions (Workshops, Birds-of-a-Feather, Symposia), and Posters. Topics can include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Data Science:&lt;/strong&gt; Proposals that illustrate how Jupyter is used by data science practitioners in industry, government, science, and beyond.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Community:&lt;/strong&gt; Proposals that demonstrate the Jupyter community, best practices, and tooling. Community practices include how Jupyter is used in a workflow and introspection into the Jupyter community itself, while tooling includes frontends, kernels, extensions, and other tools in the Jupyter ecosystem.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Research and Scientific Discovery:&lt;/strong&gt; Proposals on how Jupyter is used in specific scientific research fields, such as medical research, astronomy, physics, climate change, meteorology, humanities, social science, and more.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Education:&lt;/strong&gt; Proposals in this track focus on how to teach and learn using Jupyter in a variety of settings.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Jupyter Infrastructure:&lt;/strong&gt; Proposals that focus on deploying Jupyter and JupyterHub at scale in industry, government, high-performance computing, science, education, and other settings. Topics include DevOps, scaling services, security concerns, regulation compliance, and more.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Learn more and submit your talk by Sunday, July 13 at 11:59 PM PDT (UTC -7).&lt;/p&gt;
&lt;h2 id="registration"&gt;Registration&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Reserve your pass by 11:59 PM PDT on August 22 for Early Bird.&lt;/li&gt;
&lt;li&gt;Standard pricing continues from August 23 to October 3.&lt;/li&gt;
&lt;li&gt;Late registration is from October 4 until the first day of JupyterCon.&lt;/li&gt;
&lt;li&gt;Student or faculty can register at a &lt;a href="https://events.linuxfoundation.org/jupytercon/register/#registration-rates"&gt;discounted academic rate&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="become-a-sponsor-at-jupytercon-2025"&gt;Become a Sponsor at JupyterCon 2025&lt;/h2&gt;
&lt;p&gt;Be recognized for your impact on data science, interactive computing, and data visualization by sponsoring JupyterCon 2025. Project Jupyter has been a leader in the open science and interactive computing renaissance, empowering contributions from academia, industry, and government.&lt;/p&gt;
&lt;p&gt;As a sponsor, you’ll be investing in a thriving community of open source developers and maintainers committed to innovation. Sponsorships will position your organization at the center of a vibrant, open source ecosystem and enable you to connect directly with hundreds of expert attendees, researchers, engineers, and decision-makers, and actively shape the conversations driving the next era of data science and interactive computing.&lt;/p&gt;
&lt;p&gt;For more details on CFP submissions, registration, and sponsorship, visit the &lt;a href="https://events.linuxfoundation.org/jupytercon/"&gt;JupyterCon Website&lt;/a&gt;.&lt;/p&gt;
</content><category term="events"/><category term="JupyterCon"/></entry><entry><title>European Commission Funds Jupyter Bug Bounty Program</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2023/european-commission-funds-jupyter-bug-bounty-program/" rel="alternate"/><published>2023-07-28T19:46:00+00:00</published><updated>2023-07-28T19:46:00+00:00</updated><author><name>Rick Wagner</name></author><id>tag:jasongrout.github.io,2023-07-28:/medium-archive/pelican/posts/2023/european-commission-funds-jupyter-bug-bounty-program/</id><summary type="html">&lt;p&gt;Three Jupyter Subprojects – Jupyter Server, JupyterLab, and JupyterHub –are participating in a bug bounty program sponsored by the European…&lt;/p&gt;
</summary><content type="html">&lt;p&gt;Three Jupyter Subprojects – Jupyter Server, JupyterLab, and JupyterHub –are participating in a &lt;a href="https://app.intigriti.com/programs/jupyter/jupyter/detail"&gt;bug bounty program&lt;/a&gt; &lt;a href="https://commission.europa.eu/news/european-commissions-open-source-programme-office-starts-bug-bounties-2022-01-19_en"&gt;sponsored by the European Commission&lt;/a&gt; and hosted on the &lt;a href="https://www.intigriti.com/"&gt;Intigriti platform&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://jasongrout.github.io/medium-archive/pelican/posts/2023/european-commission-funds-jupyter-bug-bounty-program/images/001-1_8C-9fnjUJwJ56vdcNX0-bA.webp" alt="Screenshot showing the bug bounty program description on the Intigriti site." loading="lazy" data-body-image=""&gt;&lt;/p&gt;
&lt;p&gt;Intigriti is a cybersecurity company that specializes in crowdsourced security services like &lt;a href="https://www.intigriti.com/landing/bug-bounty"&gt;bug bounty programs&lt;/a&gt;, hybrid penetration testing, and hosting live hacking events. The financial support covers bounties from €250 to €5,000 and is part of the European Commission’s &lt;a href="https://commission.europa.eu/about-european-commission/departments-and-executive-agencies/informatics/open-source-software-strategy_en"&gt;Open Source Software Strategy 2020–2023&lt;/a&gt;, which:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Promotes the sharing and reuse of software solutions, knowledge and expertise, to deliver better European services that benefit society and lower costs to that society. The Commission commits to increasing its use of open source not only in practical areas such as IT, but also in areas where it can be strategic.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This is a great opportunity for Project Jupyter to reduce the number of potential vulnerabilities in critical Jupyter components and to evaluate our vulnerability handling processes.&lt;/p&gt;
&lt;p&gt;Project Jupyter was selected for sponsorship at the end of 2022. After discussions involving several Jupyter Subprojects and other stakeholders, the three Jupyter software components were chosen for inclusion. Representatives from Jupyter Server, JupyterLab, and JupyterHub have committed to validating and responding to submissions for their area. Focusing on a limited number of key Jupyter components was a way to balance the benefits of identifying vulnerabilities against developer obligations to review vulnerability submissions. The Jupyter Security Subproject is contributing to this effort by drafting the bug bounty program details and being a liaison between Intigriti and the other Jupyter Subprojects.&lt;/p&gt;
&lt;p&gt;Submissions are triaged by Intigriti, including reproducing potential vulnerabilities and assigning a severity. The triage process ensures that submissions fall within the scope (software components, versions, etc.) defined by the program. Vulnerability severity is based on Intigriti’s &lt;a href="https://kb.intigriti.com/en/articles/5041991-intigriti-s-contextual-cvss-standard"&gt;contextualized Common Vulnerability Scoring System (CVSS)&lt;/a&gt; and assigned a rating of low, medium, high, critical, or exceptional. The severity determines both the bounty and the response time for Project Jupyter to validate a submission. After a submission passes triage, it is sent to Project Jupyter for validation.&lt;/p&gt;
&lt;p&gt;Project Jupyter appreciates the financial support from the European Commission and the help by Intigriti representatives to establish the program. Security researchers and others interested in the bug bounty program can view the details &lt;a href="https://app.intigriti.com/programs/jupyter/jupyter/detail"&gt;on the Intigriti website&lt;/a&gt;.&lt;/p&gt;
</content><category term="funding"/><category term="security"/></entry><entry><title>Requiring 2FA for Jupyter GitHub Organizations</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2022/requiring-2fa-for-jupyter-github-organizations/" rel="alternate"/><published>2022-07-05T15:00:00+00:00</published><updated>2022-08-11T09:23:00+00:00</updated><author><name>Rick Wagner</name></author><id>tag:jasongrout.github.io,2022-07-05:/medium-archive/pelican/posts/2022/requiring-2fa-for-jupyter-github-organizations/</id><summary type="html">&lt;p&gt;This requirement and the outlined plan was discussed and agreed upon at the Jupyter Governance meeting on Friday, July 1, 2022.&lt;/p&gt;
</summary><content type="html">&lt;p&gt;&lt;em&gt;This requirement and the outlined plan was discussed and agreed upon at the Jupyter Governance meeting on Friday, July 1, 2022.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;By October 1, 2022, Project Jupyter aims to &lt;a href="https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/requiring-two-factor-authentication-in-your-organization"&gt;require two-factor authentication (2FA)&lt;/a&gt; for all GitHub organizations hosting repositories for &lt;a href="https://jupyter.org/governance/list_of_subprojects.html#official-subprojects-with-ssc-representation"&gt;official Jupyter Subprojects&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://github.blog/2021-08-16-securing-your-github-account-two-factor-authentication/"&gt;Enabling 2FA&lt;/a&gt; is the single most important step Jupyter contributors can take to protect their GitHub accounts from bad actors. This benefits the entire Jupyter Community by reducing the chance for malicious code to be slipped into a repository.&lt;/p&gt;
&lt;p&gt;Fortunately, most Jupyter GitHub organization members and external collaborators have 2FA enabled, at this time. This process will get us to 100% so we can enable the requirement as a GitHub org setting.&lt;/p&gt;
&lt;h2 id="whats-the-process"&gt;What’s the process?&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://docs.github.com/en/authentication/securing-your-account-with-two-factor-authentication-2fa"&gt;GitHub Documentation on 2FA&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;We recommend that all GitHub users secure their account with 2FA, even if you don’t have an organizational role like admin or owner, or write permissions to a Jupyter repository.&lt;/p&gt;
&lt;p&gt;Over the next month (by August 1, 2022) contributors to the Jupyter Security Subproject will reach out to owners of each Jupyter GitHub org with a list of their users without 2FA enabled. The list of users will be an intersection across the GitHub orgs so that users aren’t contacted multiple times, and org maintainers are asked to do double work.&lt;/p&gt;
&lt;p&gt;From there, the org owners can decide how they want to work within their area of the Community. They may choose to contact the users or ask the Security Subproject to reach out to the users. Or, the users without 2FA may no longer need the access or role they were granted.&lt;/p&gt;
&lt;p&gt;At end of August, 2022, we’ll review the list of the remaining accounts without 2FA. (Hopefully none!) If possible, we’ll begin enabling the requirement on our GitHub orgs. The Security Subproject will work with org owners on plans for contacting any remaining users.&lt;/p&gt;
&lt;p&gt;At the end of September, 2022, users without 2FA enabled may lose explicit permissions or roles within Jupyter GitHub orgs. This will only impact access to private repositories, commit privileges, or having a role such as owner or admin. Read access to public repositories will remain the same, along with opening issues or pull requests. And once users enable 2FA on their account, any previous permissions or roles can be restored.&lt;/p&gt;
&lt;h2 id="what-github-orgs-does-this-apply-to"&gt;What GitHub orgs does this apply to?&lt;/h2&gt;
&lt;p&gt;All GitHub orgs hosting repositories for &lt;a href="https://jupyter.org/governance/list_of_subprojects.html#official-subprojects-with-ssc-representation"&gt;official Jupyter Subprojects&lt;/a&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ipython/"&gt;IPython&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jupyter/"&gt;Jupyter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jupyterlab/"&gt;JupyterLab&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jupyterhub/"&gt;JupyterHub&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/voila-dashboards/"&gt;Voilà&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jupyter-server/"&gt;Jupyter Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jupyter-widgets/"&gt;Jupyter Widgets&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jupyter-xeus/"&gt;jupyter-xeus&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content><category term="GitHub"/><category term="security"/></entry></feed>