↓ Skip to main content

This is a blog about information security, GRC, the software development lifecycle, mentorship, community building, DIY, judgment calls that don't fit a checklist, and inconvenient truths whenever they cross a certain inconvenience threshold. Open-source security is a recurring focus -- project health, secure development in the commons, and related craft. I write through the path I actually walked: systems and networks administration, SRE, DevOps, software development, and cybersecurity. Some posts are hands-on -- how we design, build, and ship securely. Others are reflective notes on craft, mentoring, and teams under pressure, or notes from events I visit and talks I give. Sometimes I write to untangle something for myself until the problem has a clearer shape. Take what helps, leave the rest.

New pieces land below -- roughly weekly, with gaps when life is loud. Opinions are my own.


WeAreDevelopers North America 2026 highlights

WeAreDevelopers brought its World Congress format to North America for the first time, September 23-25, 2026 at the San Jose McEnery Convention Center. Day 0 was badge pickup, partner stages, and workshops before the main Congress opened. Days 1 and 2 filled multi-track rooms with build-vs-buy panels, security stacks for AI, headless defense, performance engineering with Dash0, GitHub agent workflows, and a hiring panel that asked who we hire now. This post covers the European World Congress lineage, production quality and ticket cost, practical tips, the sessions I made and missed, and why student pricing matters when the room is full of people still in school.

Planning a Python 3.15 upgrade

PEP 790 schedules Python 3.15.0 final for 2026-10-09. The full What's New is long by design, so this post is the shorter upgrade list I would check first: explicit lazy imports, UTF-8 as the default encoding, unpacking in comprehensions, the new profiling package with Tachyon, and frozendict. Each section stays short -- what changed, why it shows up in day-to-day work, and a small example where one helps. Lazy imports get a concrete beat from years of chasing import cost in the Open World Holidays Framework. Everything else worth planning around still lives in the official What's New and Porting guides.

Attention tax: your Slack habits are other people's unread count

Communities get the Slack they tolerate. Large communities drown less often in obvious scam posts or clear code of conduct violations than in everyday attention tax. Wrong channel posts, top-level replies that should have been threads, and the `Also send to #channel` checkbox quietly multiply unread counts for people who never asked for the ping. This post is a practitioner etiquette essay from Slack-lived experience: pick the right room, consolidate before you hit Enter, trim link previews, prefer reactions over thanks-noise, and remember that deleted messages still leave footprints. It ends with a short checklist you can pin.

Maintainer, mentor, manager: why I fund contributors before programs do

A reflective note for contributors and mentees on three hats in open source -- maintainer, mentor, and manager -- learned in that order, with sponsorship as an optional bridge when someone is ready and the program is not. It sketches a soft maturity ladder from Foundations through Hire-ready, and when personal funding keeps a track record growing between cycles. It includes a sponsorship path after a GSoC rejection so the work does not pause for a calendar, and another where a consistent public track record leads through sponsorship to an internship and a permanent role. Organization stipends can become GitHub Sponsors support when orgs pass them through. The numbers are a funnel: hundreds of contributors, dozens of mentees and sponsored people, and a rare hire.

PSF Board Candidates 2026

The 2026 PSF Board election fills four seats under Approval Voting through September 15. This post walks every nominee A-Z with links to nomination statements, AMAs, and PSF blog interviews, plus a short evaluative paragraph on each. I have no personal affiliation with any candidate. Facts and links are a best-effort snapshot from those public sources and may be incomplete or wrong. Read the primary materials before you vote, and contact me if something needs a correction.