Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
SethMLarson
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
61.
▲
by
SethMLarson
2y ago
I'm saying that by moving towards explicit "search" and "linking to sources" they have set the stage for being able to charge to be recommended by their search features (ie, ads and pay-to-rank, same as Google searc
62.
▲
by
SethMLarson
2y ago
Hah, OpenAI is becoming an ads business too. So much for something new, same old funding model for every centralized platform on the web.
63.
▲
How to Export OPML from Omnivore
(sethmlarson.dev)
1 points
by
SethMLarson
2y ago
|
0 comments
64.
▲
by
SethMLarson
2y ago
Hello! Great question. I tried to cover this in PEP 761, this comes down to a few things: Python release managers don't want to use PGP due to the ergonomic burden. They are volunteers too, after all. This is the key point, and we are
65.
▲
by
SethMLarson
2y ago
Potential solution? Works for me but some folks like history: https://sethmlarson.dev/youtube-without-youtube-shorts
66.
▲
by
SethMLarson
2y ago
I've authored a proposal to deprecate the expectation of PGP signatures for future CPython releases. We've been providing Sigstore signatures for CPython since 3.11. https://peps.python.org/pep-0761/
67.
▲
by
SethMLarson
2y ago
Happily using pip, venv, and pip-tools for every project and still finding them more than suitable. They might not have the marketing budget or pizazz of others, but if you're looking for effective and boring tools that get the job don
68.
▲
by
SethMLarson
2y ago
Was great getting to meet you in person Kati! :) This is an awesome recap of PyCon US, so much happened!!
69.
▲
GitHub Artifact Attestations public beta
(github.blog)
1 points
by
SethMLarson
2y ago
|
0 comments
70.
▲
Thanks Andres Freud
(github.com)
3 points
by
SethMLarson
2y ago
|
0 comments
71.
▲
by
SethMLarson
3y ago
Love the "on a business card" format, thank you for creating this and sharing!
72.
▲
Software Bill-of-Materials documents are now available for CPython
(pyfound.blogspot.com)
2 points
by
SethMLarson
3y ago
|
0 comments
73.
▲
The paradox of open: Policies for the Digital Commons
(paradox.openfuture.eu)
1 points
by
SethMLarson
3y ago
|
0 comments
74.
▲
by
SethMLarson
3y ago
Enshittification is a possible outcome for all platforms.
75.
▲
by
SethMLarson
3y ago
Oh wow, thanks for this story! Would love to hear more if you have time :) Good luck with testing it out. Note that we found an issue w/ emitting an InsecureRequestWarning by default. The request is perfectly secure, it's just we
76.
▲
by
SethMLarson
3y ago
Correct! The examples we used were making requests to httpbin.org, but I also was able to query GitHub's API :) `data = urllib3.request("GET", " https://api.github.com").json ()`
77.
▲
by
SethMLarson
3y ago
Browsers limit the ability for these platforms to use raw sockets, there simply is no API for it. The best that can be done /today/ is to use WebSockets, which are not the same thing and can't be used for HTTP requests withou
78.
▲
by
SethMLarson
3y ago
Lead maintainer of urllib3 here: We're tracking all the options for how we can make the experience better for folks looking to use Python in the browser. Today our biggest blocker is that there's no socket or TLS APIs for Emscript
79.
▲
Python HTTP library 'urllib3' now works in the browser
(github.com)
108 points
by
SethMLarson
3y ago
|
32 comments
80.
▲
by
SethMLarson
3y ago
Nice! This is similar to the solution here: https://github.com/python-trio/unasync
81.
▲
Platform Tilt
(mozilla.github.io)
404 points
by
SethMLarson
3y ago
|
111 comments
82.
▲
by
SethMLarson
3y ago
Isolation and ephemerality can still be accomplished using virtualization while providing the benefits of self-hosted resources.
83.
▲
by
SethMLarson
3y ago
The recommended guidance is either vendoring dependencies or pinning to hashes (pip --require-hashes, poetry.lock, pipfile). When updating your dependencies you should review the actual file getting downloaded. Compiled binaries are harder,
84.
▲
by
SethMLarson
3y ago
Great write-up! There's a few things you can do as either a producer or consumer to thwart this sort of attack: Producers: * Self-hosted infrastructure should not be running anonymous code. PRs should be reviewed before code executes o
85.
▲
Security Developer-in-Residence Weekly Report #24
(sethmlarson.dev)
2 points
by
SethMLarson
3y ago
|
0 comments
86.
▲
AI and Wonder
(sethmlarson.dev)
1 points
by
SethMLarson
3y ago
|
0 comments
87.
▲
Mahjong tiles and Unicode variation selectors
(sethmlarson.dev)
2 points
by
SethMLarson
3y ago
|
0 comments
88.
▲
Python listed as memory-safe language in latest CISA recommendations
(sethmlarson.dev)
2 points
by
SethMLarson
3y ago
|
3 comments
89.
▲
by
SethMLarson
3y ago
Python itself is memory-safe, but you're right that a good chunk of the packaging ecosystem uses memory unsafe languages for performance and interop. The Python Software Foundation noted this in our response to the US Government RFI on
90.
▲
by
SethMLarson
3y ago
I am looking forward to PyPI's "answer" to this class of malicious packages with automated third-party reporting (and hopefully long-term, quarantining or even deletion). Hopefully this project will swing the narrative closer
More ›