Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
carols10cents
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
carols10cents
4mo ago
How does a user become a Trusted User? Who is paying them to review everything?
2.
▲
by
carols10cents
6mo ago
If you're writing the tests after writing the code, you're not doing TDD though.
3.
▲
by
carols10cents
1y ago
Since Shai-Hulud scanned maintainers' computers, if the signing key was stored there too (without a password), couldn't the attackers have published signed packages? That is, how does signing prevent publishing of malware, exactly
4.
▲
by
carols10cents
1y ago
Yeah, npm has orders of magnitude more users than crates.io. This attack's success, or lack thereof, has no bearing on the savviness of JavaScript or Rust developers.
5.
▲
by
carols10cents
1y ago
So why are you upgrading?
6.
▲
by
carols10cents
1y ago
Who is requiring you to use large numbers of transitive dependencies? You can always write all the code yourself instead.
7.
▲
by
carols10cents
1y ago
Why wouldn't you knit a chicken???
8.
▲
by
carols10cents
1y ago
And the architect is a volunteer for Habitat for Humanity.
9.
▲
by
carols10cents
2y ago
who is going to pay for the review of packages and updates? how do we know we can trust the reviewers? github actions are name-spaced and that didn't help anything here...
10.
▲
by
carols10cents
2y ago
Do not try to equalize a maintainer guarding their time and energy from having to deal with an issue that has already been fixed and users that refuse to search or read with trying to cover up for gross negligence and bugs.
11.
▲
by
carols10cents
2y ago
No maintainer is obligated to maintain access to a discussion space for their users. > One now doesn't even know and cannot even estimate the number of other issues that must have gone unreported. It's not safe or wise to use a
12.
▲
by
carols10cents
2y ago
It's the Charles Anderson Bridge. https://engage.pittsburghpa.gov/charles-anderson-bridge
13.
▲
by
carols10cents
3y ago
What would prevent the sock puppet accounts from signing each others' keys?
14.
▲
by
carols10cents
3y ago
How are these two problems unique to Rust though?
15.
▲
by
carols10cents
3y ago
It looks like accounts can be entirely anonymous. How are you planning on handling moderation of comments? What happens if I post on a neighbor's house "jagoff who lets their dogs poop everywhere lives here, please evict"?
16.
▲
by
carols10cents
3y ago
Tell me you don't know anyone from Pittsburgh without telling me you don't know anyone from Pittsburgh.
17.
▲
by
carols10cents
3y ago
> these are the folks who do the Lawfare podcast, right? Yep, and they had a podcast episode with the author of this paper: https://www.lawfaremedia.org/article/the-lawfare-podcast-jim...
18.
▲
by
carols10cents
3y ago
I wish Bluey hadn't introduced the concept of a "bush wee" to my kid, I've had to explain that no, we can't pee in someone's yard in the middle of our busy neighborhood...
19.
▲
by
carols10cents
3y ago
Namespaces can't be typosquatted?
20.
▲
by
carols10cents
3y ago
Crates.io has publisher information-- namespacing is not required for that. For example, here are all the crates owned by the `azure` GitHub organization and published by the `azure-sdk-publish-rust` team: https://crates.io/
21.
▲
by
carols10cents
3y ago
How do namespaces measurably increase security?
22.
▲
by
carols10cents
3y ago
I'm one of the crates.io team members, and we're very grateful to Phylum for doing this analysis and alerting us! As a volunteer member, I'm also very thankful to the Rust Foundation for funding and hiring Walter Pearce, Adam
23.
▲
by
carols10cents
4y ago
Making crev part of the official Rust toolchain won't magically make enough time in the day for me to want to volunteer any of it doing code review.
24.
▲
by
carols10cents
4y ago
That's what TideLift's goals are too. https://tidelift.com/
25.
▲
by
carols10cents
4y ago
You're very welcome, I'm glad you like it! <3
26.
▲
by
carols10cents
4y ago
Hi! Book author here. I think the other comments were answering when the feature will be available in a stable release. No content has been written for this, and it's not entirely clear to me yet how best to work this into the book. Th
27.
▲
CrateDepression: Rust Supply-Chain Attack Uses Go Malware
(sentinelone.com)
27 points
by
carols10cents
4y ago
|
4 comments
28.
▲
by
carols10cents
5y ago
No. This was released yesterday: https://pittsburghpa.gov/press-releases/press-releases/5590
29.
▲
by
carols10cents
5y ago
> Hang your shingle out by publishing negative (vote-against) attestations of vulnerable versions of open source software and positive attestations (e.g. code-review) of the versions that mitigated the issues they disclosed. So you'
30.
▲
by
carols10cents
5y ago
Yup, this. And in places where logging companies aren't ruining forests, it's because of government regulation.
More ›