
This is a critical moment for open source software. AI enables new contributors in new ways, but maintainers are also faced with an unprecedented volume of contributions and security reports. This speed also puts pressure on maintainers and the processes that keep projects secure and reliable.
At the same time, there have been significant recent advances in tooling for:
- dependency analysis
- vulnerability scanning
- supply chain security
- automated security checks in CI pipelines
But many open source software projects still struggle to evaluate and integrate these tools into their workflows.
The Security Tooling Sprint
To help address this challenge, the Linux Foundation and the Berkeley Institute for Data Science (BIDS) are hosting the Security Tooling Sprint on March 31st. This sprint will bring together maintainers, security experts, and contributors to explore how security tooling can better support the secure development of Project Jupyter.
Participants will work to understand what tools exist, what problems they solve, and how they can be used in real projects.
What We Will Do
During the sprint, participants will work together to explore the current landscape of security tooling and apply it to real workflows.
- identifying common maintainer pain points
- reviewing the modern security tooling ecosystem
- experimenting with tools in real project environments
- sharing results and ideas with the group
The event focuses on collaboration and hands-on exploration in order to derive actionable recommendations back as issues and pull requests.
Why This Matters for Jupyter
Project Jupyter is used by millions of people in research, education, and industry. Like many open source projects, it relies on a global community of maintainers and contributors volunteering their time, energy, and expertise.
Improving security practices helps protect users while reducing maintainer burden and strengthening trust in the ecosystem.
Join Us
If you are interested in open source security, developer tooling, or the future of the Jupyter ecosystem, we encourage you to participate.
Learn more and register here. We hope you will join us in Berkeley and help improve how to evolve how open source communities approach security.
<hr /><p>Jupyter Security Sprint March 31st was originally published in Jupyter Blog on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>