PSF Meeting Minutes for Aug. 12, 2026
Title: 2026-08-12 PSF Board Meeting Minutes Encoding: utf-8 Author: psf at python.org Content-Type: text/x-rst
A regular meeting of the Python Software Foundation ("PSF") Board of Directors was held over Group Conference Call via phone and Internet Relay Chat/Slack beginning at 13:00 UTC, on August 12, 2026. Olivia Sauls took notes/minutes.
All votes are reported in the form "Y-N-A" (in favor-Y‚opposed-N‚abstentions-A; e.g. "5-1-2" means "5 in favor, 1 opposed, and 2 abstentions").
- 1 Attendance
- 2 Minutes of Past Meetings
- 3 Board and Staff Monthly Reports for August 2026
- 3.1 Deb Nicholson
- 3.2 Oliva Sauls
- 3.3 Laura Graves
- 3.4 Loren Crary
- 3.5 Marie Nordin
- 3.6 Seth Larson
- 3.7 Mike Fiedler
- 3.8 Jaime Barrera
- 3.9 Jacob Coffee
- 3.10 Maria Ashna
- 3.11 Kelly Ragland
- 3.12 Abigail Mesrenyame Dogbe
- 3.13 Sheena O'Connell
- 3.14 Denny Perez
- 3.15 Cristián Maureira-Fredes
- 3.16 Simon Willison
- 3.17 Jannis Leidel
- 3.18 Georgi Ker
- 3.19 KwonHan Bae
- 3.20 Tania Allard
- 3.21 Cheuk Ting Ho
- 3.22 Chris Neugebauer
- 4 Work Group Reports
- 5 PSF Board Votes Approved by Email
- 6 Votes Approved by Working Groups
- 7 Consent Agenda Resolutions
- 8 New Business
- 9 Discussions
1 Attendance
The following members of the Board of Directors (10 of 12) were present at the meeting: Jannis Leidel, Cristián Maureira-Fredes, KwonHan Bae, Georgi Ker, Simon Willison, Abigail Mesrenyame Dogbe, Sheena O'Connell, Cheuk Ting Ho. Christopher Neugebauer joined at 13:39 UTC.
Olivia Sauls (Program Director), Laura Graves (Controller), Marie Nordin (Community Communications Manager), Jaime Barrera (Community Events Coordinator), Loren Crary (Deputy Executive Director), Seth Larson (Python Security Developer in Residence), Jacob Coffee (Director of Engineering) and Mike Fiedler (PyPI Safety & Security Engineer) were also in attendance.
2 Minutes of Past Meetings
Minutes from prior meeting July 8, 2026:
RESOLVED, that the Python Software Foundation approve the minutes at https://mail.python.org/archives/list/psf-important@python.org/thread/YBQ6AB6SJJTL57UU6ND2NAZOQOEP2UO5/ as representing a true and accurate record of the July 8, 2026 meeting.
Approved, 9-0-0
3 Board and Staff Monthly Reports for August 2026
3.1 Deb Nicholson
- Support various hiring processes that are happening in the org
- Work with Accounting team (both internal and fractional) to get caught up and streamline processes
- Continue to support Packaging Council and PSF Board election work
- Respond to administrative legal emails
- Discuss ongoing open source policy issues with peers at other orgs
- Attend EuroPython, gave a talk on global open source at this moment, present at packaging summit, meet with sponsors and community members.
- Get ready to keynote at PyCon Korea
3.2 Oliva Sauls
- PyCon US 2026 budget wrap-up
- Working with business counsel on Westin attrition damages
- PyCon US 2026 recording review and edits
- PyCon US 2026 recap report
- PyCon US 2027 design planning
- 2028/2029 city selection RFP work
- Managing Community Events Coordinator
3.3 Laura Graves
- Ongoing accounting activities
- Historic review of google summer of code invoicing/expensing with Kelly
- Grants refresh documentation review
- Communication with Meetup regarding account permission and payment issues
- Private benefit analysis related to strategic plan membership goals
- Gift Acceptance Policy review/rework for sponsorship limitations
- Ramp onboarding for Sutro Li AP migration
- 12/31/25 balance sheet account review
- PEX transaction review from 10/25 through current
- Removing prior controller’s personal address from PEX shipping
- Updating PEX card balances post PyCon to mitigate fraud risk
- Ongoing work with Bank of America to update signers on the account
- Fiscal Sponsorship
- BAPyA venue contract review and insurance coverage
- PyBay vendor contracts review/negotiation
- PyBay sponsor agreement negotiations (Bloomberg, JetBrains, Meta)
- PyPI
- Work with Deb/Loren/Jacob around pricing increase
- Legal and accounting concerns around pricing increase and general taxability
- Research and analysis on PyPI revenue compliance
- Started VAT counsel selection (Bird & Bird vs. Bristows)
- Calls with legal regarding paid features/ubit
- Comms review for pricing increase
- PyCon US
- PyLadies auction reporting with Marie and Kelly
- Documentation follow up re: PyCon 2026 keynote issue
- Insurance policy coverage issues
- Reviewing PAAG agreement for PyCon 2028/2029
- Reporting
- Discussions with JustWorks about which reports are now being handled by them and what I need to continue to cover
- Discussions with Kelly, Sutro Li, and Eisenkraft about 990 prep timeline and scheduling
- Starting 990 prep with CPA firm
- Closing Vermont employee withholding taxes account
- Human Resources
- Work with BCBS/ADP on health insurance renewal
- 401k contribution review
- Cancellation of workers comp policies now being handled by Justworks
- State of Washington Employment Security Billing Notice
- Annual Business Survey conducted by the U.S. Census Bureau (response required by law)
- California 2026 Statement of Information
- Colorado Periodic Report
- Reviewing contract for DevOps Engineer
- Reviewing hiring plan for 2026+
- Reviewing JDs for open roles and jr sponsorship hire
- Compensation calculating and budgeting for COLA/raise decisions
3.4 Loren Crary
- Correspondence with current and prospective sponsors
- Contract negotiation with current and prospective sponsors
- Assessing and pursuing grant opportunities
- Including applied to Internet Society Foundation’s Common Good Cyber Fund
- Drafting and revising strategic public communications
- PyCon US planning support
- Board relations
- Strategic Planning support
- Strategic team management and support
- Policy review support
- Managing Programs Director & Community Communications Manager
- Working on planned hire to support fundraising
3.5 Marie Nordin
- Program Administration
- Fellows
- Community Partner Program
- Meetups
- Office hours
- PSF Board & Python Packaging Elections
- Project management
- Communications
- Promotion of nomination period
- Resolving individual membership issues
- Grants
- Launch of special funding round
- Communications development, reviews, editing, & publications
- Additional office hours
- Preparation for review period
- Answering many emails re: eligibility inquiries
- Starting proposal for next funding round/next steps for the program
- Launch of special funding round
- Meetups
- Gathering 2025 data for 990
- Review of all groups for Codes of Conduct & activity levels
- Communications & promotion
- Supporting staff communications (blog posts, social posts)
- Python Typing Survey
- Sponsor benefits communications
- Python Developers Survey
- Coordination of review/analysis of 2026 data
- Laying groundwork with stakeholder for updates to the Python Survey
- PyCon US/PSF Booth
- Reporting on budget for PSF Booth
- D&I WG
- Supporting D&I WG office hours
- Review of contributions to organizers toolkit
- Strategic Plan
- Follow ups on publication & promotion on finalized plan
- Review of plan against Community Communications role
3.6 Seth Larson
- EuroPython
- Seth attended EuroPython 2026 to speak in multiple sessions and to attend summits and sprints. Seth attended and was the blogger for the Python Language Summit and attended the Python Packaging Summit.
- Seth delivered a talk titled “[Learning from the “not‑so‑secret” Python security cabal](https://sethmlarson.dev/europython-2026-security-talk)” which discussed how LLMs were affecting open source security teams, what individual contributors can do to start their journey to joining and contributing to an OSS security team, and how projects can start thinking about this period of experimentation we're all in.
- This talk is a continuation of a talk I gave a year ago: “Security Work isn’t Special” as the keynote for OpenSSF Community Day NA where I lamented on how security work didn't match other Open Source contribution models like documentation, community, or code contributions.
- Seth was also a member of the AI, Cybersecurity, and Ethics panel along with Mike Fiedler and three other experts. This panel recording is [now published to YouTube](https://www.youtube.com/watch?v=4cfgbo912rg).
- [Python.org](http://Python.org) Security Fixes
- Following the report on mitigating an API authentication bypass for python.org, we received the expected uptick in scrutiny from other security researchers. Seth responded to the reported issues and applied the fixes:
- [Sanitize the HTML descriptions](https://github.com/python/pythondotorg/pull/3075) imported from trusted iCalendar/ICS files prior to displaying them on event detail pages. This prevents a malicious takeover of a remote event calendar from being able to inject malicious HTML into an event detail page.
- [Restrict editing of nominations outside a nomination window](https://github.com/python/pythondotorg/pull/3074).
- [Community posts that are private should not be returned in the API](https://github.com/python/pythondotorg/pull/3073).
- [Blog excerpt text still requires escaping](https://github.com/python/pythondotorg/pull/3072), even after striptags filter is applied.
- [Sanitize MarkupField content](https://github.com/python/pythondotorg/pull/3067) to a restricted list of tags and attributes using nh3. This affected many user-editable full-text fields including event descriptions and nominations.
- Upgraded dependencies ([Django, idna](https://github.com/python/pythondotorg/pull/3071) [Pillow](https://github.com/python/pythondotorg/pull/3068)) that were affected by vulnerabilities.
- A longer-term project is [adding a strict Content-Security-Policy HTTP header](https://github.com/python/pythondotorg/pull/3042) to python.org, but this will take a bit of time to avoid breaking the website while others are using the service. For now a Report-Only HTTP header is in place and the plan is to monitor the violations using Sentry before making the switch to enforce violations if no impact is detected.
- Following the report on mitigating an API authentication bypass for python.org, we received the expected uptick in scrutiny from other security researchers. Seth responded to the reported issues and applied the fixes:
- Restricting Open Ended Releases on PyPI - The Python Package Index (PyPI) now rejects new files being uploaded to releases that are older than 14 days. This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised. As far as we are aware this has not yet been abused, but there is no technical reason beyond that attackers weren't aware it was possible. - This work was done after [restarting a conversation](https://discuss.python.org/t/restricting-open-ended-releases-on-pypi/43566/34) (following the LiteLLM/Telnyx compromises) that started [back in January 2024](https://discuss.python.org/t/restricting-open-ended-releases-on-pypi/43566). With help from data gathered by Mike Fiedler and Hugo van Kemenade and through discussing the issue at the PyCon US 2026 Packaging Summit we were able to come to a rough consensus and move forward with the restriction. - Seth [made the changes to PyPI](https://github.com/ossf/alpha-omega/blob/main/alpha/engagements/2026/Python%20Software%20Foundation) and then [published a blog post](https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/) to the PyPI blog detailing this change and the journey to get there. Seth also [fixed a small bug](https://github.com/pypi/warehouse/pull/20260) in the implementation which broke an existing benign workflow using twine upload --skip-existing.
- Security Developer Hiring
- The Python Software Foundation is hiring another Security Developer to work on the Python Security Response Team and PyPI malware handling. Seth is the hiring manager for this role and has been preparing the role description, screening, and interview pipeline.
- Other items
- Applying to the Common Good Cyber Fund grant with Loren Crary.
- Working on the Python Security Response Team report queue.
- Nominated Tania Allard to the PSRT.
- Published the advisory for pip (CVE-2026-13346) and Python's HTML parser (CVE-2026-15308).
- Interviewed by IEEE Spectrum about slopsquatting and LLMs effects on open source security.
- Recorded an episode of Talk Python about "Everything Security at PyCon US 2026" with Juanita Gomez and Mike Fiedler.
- Published a blog post with a [wrap-up for United Nations Open Source Week 2026](https://sethmlarson.dev/un-open-source-week-2026).
3.7 Mike Fiedler
- Malware Response
- July brought 202 malware reports across 173 unique packages. 153 were confirmed and the releases removed, 13 were false positives, and 36 remain open, for 93.2% accuracy on closed reports. Another 60-plus reports from prior periods are still queued. Corroboration held steady at 53 reports (26.2%) carrying two or more independent observers, and auto-quarantine restricted 108 of the 173 reported packages before anyone looked at them, so most user-facing exposure was contained ahead of manual review.
- Response times slipped. Of 264 email conversations, 26% closed within 4 hours and another 29% within a day, but the 21% that ran past 4 days pulled the office-hours average to 2 days 5 hours. Two of five working weeks went to EuroPython and travel, and reports arriving during a conference week wait for someone to reach a keyboard.
- Mike closed out the "Hades" wave of the Shai-Hulud campaign https://www.endorlabs.com/learn/shai-hulud-hades-wave-hits-six-pypi-bioinformatics-packages that dominated June with three more advisory batches (one https://github.com/pypa/advisory-database/pull/333, two https://github.com/pypa/advisory-database/pull/336, final https://github.com/pypa/advisory-database/pull/344). Each entry covers phantom releases published from stolen credentials. On import, those releases ran a bundled JavaScript payload that harvested credentials and tried to spread itself further. Mike also pinned all GitHub Actions references https://github.com/pypa/advisory-database/pull/332 in that repository.
- Security Fixes and Hardening
- Mike reviewed and shipped a fix for session re-authentication accepting another account's credentials https://github.com/pypi/warehouse/pull/20126. The re-auth form carried a hidden username field; editing it before submission let a stale session be re-authenticated with a different user's password. The fix drops the field and validates against the session's own user ID, with a follow-up filed https://github.com/pypi/warehouse/issues/20321 to keep the two validation paths from drifting apart.
- A late-month vulnerability report yielded three false positives and one real finding, percent-encoded dots accepted during URL verification https://github.com/pypi/warehouse/pull/20333, fixed the same day. Mike also reviewed a proposed change to reject PyPI tokens found in uploaded files https://github.com/pypi/warehouse/pull/19994, and reviewed a public disclosure about incidents surfaced during cybersecurity evaluations, collecting evidence on a related PyPI project.
- Using GitHub's new controls over what can trigger a workflow https://github.blog/changelog/2026-06-18-control-who-and-what-triggers-github-actions-workflows/, Mike blocked pull_request_target across the pypi organization. Nothing used it, so the policy guards against someone adding one later. Other organizations publishing to PyPI should consider the same setting.
- Email handling is less silent about its own failures now. Warehouse re-sends the unrecognized-login notice on repeated attempts https://github.com/pypi/warehouse/pull/20323 instead of going quiet after a soft bounce, emits a reason whenever a send is skipped https://github.com/pypi/warehouse/pull/20320, and has steadier MX validation coverage [https://github.com/pypi/warehouse/pull/20306](https://github.com/pypi/warehouse/pull/20306).
- Trusted Publishing
- CircleCI as a Trusted Publisher https://github.com/pypi/warehouse/pull/19349 is in a second round of review, it's taking a while since there's a lot going on. Mike helped debug token expiration behavior on GitHub Actions https://github.com/sigstore/sigstore-python/issues/1729#issuecomment-5070474146 and published a standalone workflow that dumps the OIDC token payload https://github.com/miketheman/trusted-publishing-debugger/pull/1, so maintainers can inspect the claims their CI provider emits. A EuroPython session on Trusted Publishing prompted him to open conversations with external publishing providers about the security posture of the claims they issue. Some of that may turn into changes on their side to further secure Trusted Publishing.
- Observability
- Mike moved warehouse logging onto structlog https://www.structlog.org/, unifying rendering through a single ProcessorFormatter https://github.com/pypi/warehouse/pull/20341 and then migrating module loggers https://github.com/pypi/warehouse/pull/20343. Within a day the new logs made clear that a third-party crawler was generating a large volume of 404s, and the vendor confirmed they will work on a fix once Mike sent the evidence.
- In linehaul he retired the legacy v1 and v2 payload formats https://github.com/pypi/linehaul-cloud-function/pull/306 and stabilized the hypothesis tests in CI https://github.com/pypi/linehaul-cloud-function/pull/307, which unblocks the extra fields needed to measure downloaded bytes.
- Admin and Platform
- Rebuilt the journals admin pages on Tabulator https://github.com/pypi/warehouse/pull/20258, closing a long-open request for a view admins can work in
- Added project lifecycle status to admin project lists https://github.com/pypi/warehouse/pull/20345 and segmented archived projects on the manage page [https://github.com/pypi/warehouse/pull/20242](https://github.com/pypi/warehouse/pull/20242)
- Added a trigram index on usernames https://github.com/pypi/warehouse/pull/20250 and deferred heavyweight gcloud imports [https://github.com/pypi/warehouse/pull/20261](https://github.com/pypi/warehouse/pull/20261)
- Added a warehouse db seed command https://github.com/pypi/warehouse/pull/20342 so provenance work has realistic development data, and took on review of Release.provenance_status https://github.com/pypi/warehouse/pull/20326 alongside Kris, Dustin, and Nicole
- Continued retiring the pretend test-double library (https://github.com/pypi/warehouse/pull/20238, https://github.com/pypi/warehouse/pull/20241, [https://github.com/pypi/warehouse/pull/20262](https://github.com/pypi/warehouse/pull/20262))
- Opened pyramid_components https://github.com/pypi/warehouse/pull/20263 for review, a typed props contract plus co-located template for HTML components, tried out in admin views first
- Shipped Dependabot batches carrying security updates
- Community Engagement and Conferences
- Mike spent a full week at EuroPython in Kraków. At the Packaging Summit [https://ep2026.europython.eu/session/packaging-summit](https://ep2026.europython.eu/session/packaging-summit) he walked through upcoming changes to the PyPI user interface [https://hackmd.io/DZj3uo6eT_qyddBP0PZlDw?view#5-Mike-Fiedler-Upcoming-changes-to-PyPI-user-Interface](https://hackmd.io/DZj3uo6eT_qyddBP0PZlDw?view#5-Mike-Fiedler-Upcoming-changes-to-PyPI-user-Interface), and he sat in on the Language Summit to see where those decisions land on packaging. He delivered Anatomy of a Phishing Campaign https://ep2026.europython.eu/session/anatomy-of-a-phishing-campaign and joined a panel on Security and Ethics in the Age of Generative AI https://ep2026.europython.eu/session/security-and-ethics-in-the-age-of-generative-ai. Sprints covered staged-release lifecycle status with wheelnext https://wheelnext.dev/, operational questions for pytransparency.dev https://pytransparency.dev/, and a draft of API v3.
- Closer to home, Mike gave the NYU Secure Systems Lab a primer on PyPI and heard out their Secure Software Operations Center idea. He recorded a Talk Python episode on security, and attended Alpha-Omega and OpenSSF Securing Software Repositories sessions. He also tested a new Alpha-Omega threat modeling skill against a small Python project and sent feedback to its author.
- Ecosystem Contributions
- Outside PyPI, Mike merged five changes to pyramid_openapi3, including OpenAPI 3.2 support https://github.com/Pylons/pyramid_openapi3/pull/324, serving the spec as JSON https://github.com/Pylons/pyramid_openapi3/pull/323, and a fix so server prefixes respect path segment boundaries https://github.com/Pylons/pyramid_openapi3/pull/322. He also opened a proposal to consolidate that project's test authoring approach [https://github.com/Pylons/pyramid_openapi3/issues/319](https://github.com/Pylons/pyramid_openapi3/issues/319).
- In readme_renderer he enabled GFM alerts and shortcodes https://github.com/pypa/readme_renderer/pull/374, stopped RST's top-level heading from being dropped https://github.com/pypa/readme_renderer/pull/377, and handled expected test warnings https://github.com/pypa/readme_renderer/pull/373. He made the osv.dev search input reachable from the keyboard https://github.com/google/osv.dev/pull/5569, and kept stdlib-list and inspector current.
3.8 Jaime Barrera
- Helpscout inbox
- Recording and YouTube uploads
- Template Thank you email to Volunteers
- Template Thank you email to Sponsors
3.9 Jacob Coffee
- Hiring
- Infrastructure Engineer: round 2/3 complete, pending travel/OoO from Loren & Deb to finalize round 3.
- PyPI Sustainability Engineer (Google grant funded): initial screen candidates picked, 9 pre-selected.
- Short-term infra contractor: contract ready for signature
- Audit and generate reports on FTE capacity for PyPI support in the interest of hiring additional part-time staff
- Currently above capacity, no room for PTO or process improvements
- Internal Team
- Worked with Accounting team on various tasks
- Coordinating with team on PyCon US Startup Row refunds.
- Supporting the pricing-increase and revenue-compliance work Laura's running with legal/accounting.
- Various reports needed for IRS and other compliance reporting
- Supported Packaging Council and PSF Board election work
- Exploring final options for PSF-owned Wiki with Marie
- Various meetings for PyCon US 2026, preparing for PyCon US 2027
- Work with Loren on Sponsorship needs, including [Python.org](http://Python.org) changes
- Worked with Accounting team on various tasks
- External Team/Misc
- Worked with various legal counsel (Karl, Aaron, Archer & Greiner) on various tasks
- Subpoenas, MLAT requests, etc.
- Eligibility on PyPI-related offerings (are we allowed to offer XYZ as a nonprofit or not)
- 501(c)(3) scope concerns
- Tax concerns with regards to current PyPI service agreements
- Contract review, EU GDPR Review
- Attended EuroPython, gave a talk
- Talked with attendees about the open PyPI engineering role and met with Steering Council members on upcoming needs for benchmarking.
- Weekly check-ins with various teams including security, CPython, volunteers, staff, etc.
- Worked with various legal counsel (Karl, Aaron, Archer & Greiner) on various tasks
- PyPI
- Administrative work on reviewing PyPI org applications
- Engineering work on PyPI features including org workflow changes
- Met with Fastly regarding future PyPI plans and potential revshare agreements
- Worked with Loren and Laura on future PyPI interests
- PyPI service agreement templatization and splitting for taxable vs non taxable streams of work
- PyPI pricing changes: seat price increasing $5 to $10/month, moving to upfront billing, enabling annual billing option.
- Upcoming service agreement renewals
- Legal work
- Project management and roadmapping for PyPI in alignment with strategic plan and organization goals/needs around self-sustainability
- Review and triage of SLA customer requests
- Review of support requests from people representing large corporations that don’t utilize PyPI organizations.
- Preparing plan and comms for reasonable rate limits for users and organizations around project file size, project creation, etc. to enhance palatability of org accounts.
- Project management
- Map out in Linear and various other spreadsheets rough roadmaps for
- PyPI features, pricing, plans, legal review,
- General organization compliance
- Hiring
- Plan initial scopes of work for infrastructure engineer
- Plan initial scopes of work for DevOps contractor
- Lay out long term plans for PSF org as a whole for IT-related concerns
- Permissions and auth audits
- Various blog redesigns
- Reviewing currently used external software vendors
- Mainly looking at pricing and potential alternatives
- Platform migrations for cost savings (Heroku, DigitalOcean)
- Organizational hardening
- Enforcing SCIM where possible
- More automation for staff offboarding to ensure access controls and seat costs are kept in line
- MFA requirements
- Deployed a monitor-mode across GitHub enterprise to validate usage of dangerous GitHub action calls (including pull_request_target), enforcement mode enterprise-wide soon™
- Onboarding and offboarding documentation for Engineering and PSF-wide including instructions offboarding to IT so account access can be revoked until we are able to automate things
- Map out in Linear and various other spreadsheets rough roadmaps for
3.10 Maria Ashna
August report not provided.
3.11 Kelly Ragland
Note: This period included two weeks of vacation, so it reflects roughly a half work month. Before leaving, priority was given to bringing certian things as current as possible (like the wire-in account current and fully moderating the psf_donations@python.org inbox).
- COMPLETED & OPERATIONAL
- Fiscal Sponsoree Support
- Set up donation pages for two new PyLadies chapters (PyLadies Vancouver, NYC)
- Set up a Stripe account for a fiscal sponsoree program (PyLadies Vancouver)
- Financial Systems & Reconciliation
- Identified and corrected an accrual accounting issue in the Stripe pipeline — contributions and processor fees were being dated to the payout month rather than the transaction month; the script has been fixed going forward
- Identified donor-advised giving and employer matching funds sitting in a giving platform account; linked to the wire-in account with automatic monthly transfers now in place
- Reconciled Stripe Express accounts, including researching how those accounts are booked
- Imported a batch of checks related to Sutro Li's work; process surfaced some import errors, worked through on first pass
- Operations & Donor Support
- Took over moderation of the general donations inbox following Katie leaving
- Provided ongoing member and donor CiviCRM account support (more volume as elections near)
- Worked with Laura on a historic review of how Google Summer of Code transactions are booked and how amounts are determined
- Supported PyLadies auction reporting alongside Laura and Marie
- Fiscal Sponsoree Support
- IN PROGRESS & ONGOING
- Financial pipeline automation (New: PayPal Giving)
- Fiscal sponsoree financial reporting
- Credential and account migration across 20+ platforms — approximately 90% complete
- Retroactive accrual corrections to the Stripe pipeline, covering late 2025 through June 2026 — approach to be finalized with Sutro Li
- A booking issue identified in thanks.dev contributions — fix in progress
- 990 prep support — starting volunteer review and compilation of the >$5k donor list
- Fiscal sponsoree sponsor contracts and invoicing
- Sutro Li
- Onboarding with Finance Team
- Weekly Sutro Li and PSF Finance Team meetings
- Begin setup of Ramp app for Accounts Payable
- Establish workflow for bill entry and payment between PSF Finance team and Sutro Li accounting team
- Identify timeline for completion of 2025 accounting and 990 schedule preparation
- Modify SOPS for Earth Class Mail management and related recordkeeping tasks
- Modify SOPs for importing PEX credit card statements into QBO to allow for easier coding
- Establish Justworks access for accounting team; collect YTD 2026 payroll records
- Work with PSF Finance Team to establish capitalization and prepaid expense thresholds for 2025/2026
- Accounting and Finance
- Earth Class Mail management
- Payroll Accounting
- Complete 2025 payroll reconciliation of books to quarterly 941s
- Accrue 2025 payroll liabilities, including 2025 wages paid in 2026 and vacation pay balances at year end
- Begin recording payroll transactions for 2026
- Stripe & Stripe Express Accounting
- Work with PSF Finance Team to true up Stripe and Stripe Express (GitHub) transactions through December 31, 2025, including shift from cash to accrual basis (in process)
- Bank Account Review and Reconciliation
- Continue coding uncoded bank lines for Jan-May 2026, including matching receipts to invoices and payments to bills
- Begin resolution of items in Undeposited Funds through December 31, 2025
- Begin bank reconciliations of cash and cash equivalent accounts for 2026
- Deferred Revenue Review
- Begin matching 2025 sponsorship agreements to invoices in QB0
- Obtain sponsorship payments tracker for 2026
- Begin comparison of agreements to invoicing in QBO, listing questions to resolve with PSF finance team
- Onboarding with Finance Team
3.12 Abigail Mesrenyame Dogbe
- Board meeting and office hour
- Elections committee participation
- Lightning talk at PyOhio about our upcoming elections
- Speaking with others to encourage them to run for the board
3.13 Sheena O'Connell
- Had to pull back from PyConZA planning (family health stuff ate capacity)
- Focusing only on Guild of Educators:
- Worked with Keith from Education and Outreach workgroup to inject life/energy into the community
- Started a book club
- Generally pulling in allies and community builders from all over
3.14 Denny Perez
August report not provided.
3.15 Cristián Maureira-Fredes
- PSF: Board and Executive committee meetings, and several Office hours events.
- PSF: Working on a community index initiative, feedback to survey, a few calls with community members
- PSF: A couple of sessions with people running for the board.
- Community: EuroPython - Part of the organization team, giving a tutorial, and helping on site during all the conference days. A few catch-up calls and other meetings around the event with key people around EPS and PSF.
- Community: PyLadiesCon - Different discussions and meetings around the possible 2026 version.
- Community: Python La Paz - Preparing and presenting a talk to the local community.
- Community: Python en Español - Working on improving the bot and website during a few days.
3.16 Simon Willison
August report not provided.
3.17 Jannis Leidel
August report not provided.
3.18 Georgi Ker
- PSF: Board and Executive Committee meetings
- PSF: Board Office Hours
- PSF (D&I Workgroup): Workgroup meetings
- PSF (D&I Workgroup): Inauguration D&I Workgroup Office Hour
- Community: Attended EuroPython and helped in the PyLadies booth
- Community: Conducted Open Community Leadership workshop
3.19 KwonHan Bae
- PSF - participated in board discussions via Slack and email
- PSF - attended board meeting
- COMMUNITY : Python Asia Organize
- COMMUNITY : PyCon KR 2026 Organize
- COMMUNITY : Draft Supply Chain Conference in Korea and Japan
3.20 Tania Allard
August report not provided.
3.21 Cheuk Ting Ho
August report not provided.
3.22 Chris Neugebauer
August report not provided.
4 Work Group Reports
4.1 Code of Conduct
- Nothing to report at this time.
4.2 Grants
- Nothing to report at this time.
4.3 Sponsors
- Nothing to report at this time.
4.4 Marketing
- Nothing to report at this time.
4.5 Jobs
- Of the 556 Job submissions created in August 2026:
- 163 have status approved
- 40 have status draft
- 157 have status expired
- 97 have status rejected
- 92 have status removed
- 7 have status review
4.6 Trademarks
- Nothing to report
4.7 Fellows
- Nothing to report
4.8 Packaging
- Nothing to report
4.9 Infrastructure
- Nothing to report
4.10 Scientific Python
- Nothing to report
4.11 Diversity & Inclusion Work Group
- Nothing to report
5 PSF Board Votes Approved by Email
- None at this time.
6 Votes Approved by Working Groups
6.1 Grants
- None at this time.
6.2 Sponsors
- None at this time.
6.3 Scientific Python
- None at this time.
7 Consent Agenda Resolutions
- None at this time.
8 New Business
The board discussed the management of the Foundation's accounts payable and related financial operations and voted on the following resolution:
RESOLVED, that the Python Software Foundation Board of Directors approves opening a checking account and any associated lending or credit products with Ramp Business Corporation (or its issuing bank partner) for the purpose of managing the Foundation's accounts payable and related financial operations. The Board authorizes Deb Nicholson, Executive Director; Kelly Ragland, Finance Manager; and Laura Graves, Controller, to represent the Python Software Foundation in opening said account(s) and to act as authorized signatories and executors on behalf of the Foundation with respect to such account(s).
Approved; 9-0-1, 2026-08-12
9 Discussions
- The board discussed an update on the PyCon US budget.
- The board discussed a report on the JetBrains survey plans.
- The board discussed the upcoming board election nominations and updates.
- The board discussed an update on the grants funding round.
- The board discussed an update on the strategic plan.
- The board discussed topics to discuss in this year's Board Training.
- The board discussed topics to discuss in this year's Board Orientation document.
- The board discussed the dissolution of the Infrastructure Working Group.
Meeting adjourned at 14:59 UTC
