A stream of malicious npm and PyPi packages have been found stealing a wide range of sensitive data from software developers on the platforms. The campaign started on September 12,2023, and was first discovered by Sonatype, whose analysts unearthed 14 malicious packages on npm. Phylumreports that after a brief operational hiatus on September 16 and 17, the attack has resumed and expanded to the
In thisblog post, we’ll take a high-level tour of what’s inside the Mojo SDK. First, let’s quickly review what Mojo is and howit can benefit you. Mojo: a high performance 'Python++' language for computeMojo is a newprogramming language forAI developers that will grow into being a superset ofPython over time.It already supports integrating with arbitraryPython code seamlessly and has ascala
TL;DR: I’ve started a company, Astral, to continuebuilding high-performance developer tools for thePython ecosystem — to keepbuilding Ruff, and tobuild more Ruff-like things. We’ve raised $4m in seed funding led by Accel, with participation from Caffeinated Capital,Guillermo Rauch (Vercel), Solomon Hykes (Docker), David Cramer (Sentry), and others. I built Ruff to test a theory: thatPython t
An update on our findings, the actions we’ve taken, andtechnical details of the bug. We tookChatGPT offlineearlier this week due to a bug in an open-source library which allowed some users to see titles from another active user’s chat history.It’s also possible that the first message of a newly-created conversation was visible in someone else’s chat history if both users were active around the
IntroductionFastAPI is a highly popularPython web framework. On November 23rd,2022, the DatadogSecurity Labs team identified a third-party utilityPython package on PyPI related toFastAPI,fastapi-toolkit, that has been backdoored by a malicious actor. The attacker inserted a backdoor in the package, adding aFastAPI route allowing a remote attacker to execute arbitrarypython code andSQL qu
N.B. Ruff now supports over 200lint rules and is used in major open-source projects likeFastAPI, Bokeh, Zulip, and Pydantic.It’s also about ~50% faster than the benchmarks advertised in thisblog post. Tryit today! Over the past few years, there’s been a mindset shift inJavaScript ecosystem, best summarized as: “our tools should be extremely fast”. As projects grew in complexity, andbuilds s
Dagster is a cloud-native data pipeline orchestrator for the whole development lifecycle, with integratedlineage andobservability, a declarativeprogramming model, and best-in-class testability.It is designed for developing and maintaining data assets, such as tables, data sets,machine learning models, andreports. With Dagster, you declare—asPython functions—the data assets that you want to
リリース、障害情報などのサービスのお知らせ
最新の人気エントリーの配信
処理を実行中です
j次のブックマーク
k前のブックマーク
lあとで読む
eコメント一覧を開く
oページを開く