<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Facundo Tuesca on The Trail of Bits Blog</title><link>https://miscreants.github.io/blog.trailofbits.com/authors/facundo-tuesca/</link><description>Recent content in Facundo Tuesca on The Trail of Bits Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 12 Dec 2025 00:00:00 -0500</lastBuildDate><atom:link href="https://miscreants.github.io/blog.trailofbits.com/authors/facundo-tuesca/index.xml" rel="self" type="application/rss+xml"/><item><title>Catching malicious package releases using a transparency log</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/12/12/catching-malicious-package-releases-using-a-transparency-log/</link><pubDate>Fri, 12 Dec 2025 07:00:00 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/12/12/catching-malicious-package-releases-using-a-transparency-log/</guid><description>We’re getting Sigstore’s rekor-monitor ready for production use, making it easier for developers to detect tampering and unauthorized uses of their identities in the Rekor transparency log.</description></item><item><title>PyPI now supports archiving projects</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/01/30/pypi-now-supports-archiving-projects/</link><pubDate>Thu, 30 Jan 2025 09:00:22 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/01/30/pypi-now-supports-archiving-projects/</guid><description>PyPI now supports marking projects as archived. Project owners can now archive their project to let users know that the project is not expected to receive any more updates. Project archival is a single piece in a larger supply-chain security puzzle: by exposing archival statuses, PyPI enables downstream consumers to make more […]</description></item></channel></rss>