Coordinating security across 350+ Jupyter repositories
Jupyter has an unusual attack surface among data projects: it runs arbitrary user code by design, with broad access to user resources, and spans 350+ repos across 22 GitHub organizations.
This talk shares the challenges encountered at this scale, along with tools and workflows that could apply to other open-source projects.
The Jupyter project spans 350+ repos across 22 GitHub organizations that often depend on each other. It also has a wide attack surface because components like Notebook and JupyterLab execute user code by design. It runs in a web environment that can quickly turn an XSS into a remote code execution vulnerability.
Coordinating security in this ecosystem gave us some interesting challenges:
- building the tools that allow us to oversee security advisories across repos and organizations
- handling AI-generated reports
- securing the supply chain among hundreds of published npm and PyPI packages
We will explore the solutions, tools and workflows built as part of a 6-month security mission funded by the Linux Foundation, that can apply to other open-source projects.
This is a practical experience report, no security expertise is required; basic familiarity with open source and package managers is enough to follow along.
This talk is aimed at open-source maintainers and contributors and at anyone curious about security at ecosystem scale.
Yann works on security for the Jupyter project. He moved into open source recently, after 8 years in French software startups such as MakiPeople and Graneet.