Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
SethMLarson
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
91.
▲
by
SethMLarson
3y ago
CPython is evaluating the options in this guide: https://github.com/python/cpython/issues/112301#issue-200494...
92.
▲
Querying every file in every release on the Python Package Index (redux)
(ibis-project.org)
2 points
by
SethMLarson
3y ago
|
0 comments
93.
▲
Querying every file in every release on the Python Package Index
(sethmlarson.dev)
2 points
by
SethMLarson
3y ago
|
0 comments
94.
▲
by
SethMLarson
3y ago
The post is incorrect, only IPv6 addresses are meant to be put in brackets.
95.
▲
by
SethMLarson
3y ago
This is the way.
96.
▲
"For You" is not for me
(sethmlarson.dev)
3 points
by
SethMLarson
3y ago
|
0 comments
97.
▲
PyPI Security
(talkpython.fm)
50 points
by
SethMLarson
3y ago
|
21 comments
98.
▲
by
SethMLarson
3y ago
This doesn't change the Python language or packaging so wouldn't require a PEP, I'm working with release managers on this GitHub repo: https://github.com/python/release-tools
99.
▲
by
SethMLarson
3y ago
I believe the only differences were uid/gid and username/groupname values between the two tarballs. One had the information of Thomas Wouters, the release manager of 3.12, and the other had generic GitHub Action usernames/gro
100.
▲
by
SethMLarson
3y ago
You've got it right, SLSA build provenance in particular only tells you that the artifact you have came from X software repo, at Y commit/tag, built using Z workflow. SLSA doesn't make any mention of what is actually in the a
101.
▲
by
SethMLarson
3y ago
Great question! PyPI already supports Trusted Publishers [1], which gets you most of the benefits of SLSA build provenance (provable link between artifacts and a public software repository). Implementing Trusted Publishers is the recommende
102.
▲
by
SethMLarson
3y ago
Jake has written their experience elsewhere (and is linked to many times in the article, too) for example: https://jakeseliger.com/2023/08/27/on-being-ready-to-die-and...
103.
▲
by
SethMLarson
3y ago
Protocols with @runtime_checkable fit your description!
104.
▲
Python and SLSA
(sethmlarson.dev)
1 points
by
SethMLarson
4y ago
|
0 comments
105.
▲
Hi-Chew Pokédex
(sethmlarson.dev)
1 points
by
SethMLarson
4y ago
|
0 comments
106.
▲
by
SethMLarson
4y ago
In v2.0 urllib3 it's: import urllib3 urllib3.request("POST", "https://httpbin.org/post", json={"key": "value"})
107.
▲
by
SethMLarson
4y ago
This is part of what Spotify did to determine urllib3 as an award recipient: https://engineering.atspotify.com/2022/04/announcing-the-spo...
108.
▲
by
SethMLarson
4y ago
The name isn't straightforward, is it? :) The project name "urllib3" is an unfortunate joke on "urllib" and "urllib2" in the standard library, since it's made to supersede both of those modules in fun
109.
▲
by
SethMLarson
4y ago
I think it's less to do with a small number of companies making big donations like this, it'd be much nicer to have many organizations making even small contributions based on usage/complexity of the project. This is what Tid
110.
▲
by
SethMLarson
4y ago
Yeah the amount of financial support we receive is mostly dependent on individual organizations. For example in 2021 we didn't receive any large donations, only support from Tidelift.
111.
▲
Urllib3 in 2022
(sethmlarson.dev)
197 points
by
SethMLarson
4y ago
|
113 comments
112.
▲
Working on open source full-time for one week
(sethmlarson.dev)
2 points
by
SethMLarson
4y ago
|
0 comments
113.
▲
by
SethMLarson
4y ago
Great tip! Didn't even know this was a thing.
114.
▲
Help us test system trust stores in Python
(sethmlarson.dev)
8 points
by
SethMLarson
4y ago
|
0 comments
115.
▲
by
SethMLarson
4y ago
Thanks for raising this issue, you're right! There's no mechanism for making concurrent work impossible. We haven't had this problem of concurrent issues being worked on from start to finish in the past, maybe that will chang
116.
▲
by
SethMLarson
4y ago
You're right, this language is confusing. We'll change the names of the labels to be more clear.
117.
▲
by
SethMLarson
4y ago
If the issue is open it hasn't been paid for, we close issues when their completed. Let me know if you have other questions.
118.
▲
by
SethMLarson
4y ago
These are all great questions! Our team is collecting feedback and our own experience and hoping to publish a retrospective some time down the line about how things are going. Stay tuned!
119.
▲
by
SethMLarson
4y ago
We wish we could pay FAANG salaries for working on open source! That would be a great world to live in. Currently our funding comes from corporate sponsors and individual donators so is limited in what we're able to offer for now. Our
120.
▲
by
SethMLarson
4y ago
Where are you seeing this information? urllib, urllib3, and requests all support connection pooling, keep-alives, and re-use and have for a very long time. Maybe I'm not understanding part of your message?
More ›