Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
collinmanderson
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
collinmanderson
7mo ago
Yes, for me I think it was around Nov/Dec 2025, along with harness improvements, and hearing about lots of successes with agenic programming. Having the agent managing its own context and doing the full software engineering loop with w
32.
▲
by
collinmanderson
7mo ago
I think they emailed everyone about this, but I might be wrong. Maybe they only emailed people who actually use copilot.
33.
▲
by
collinmanderson
7mo ago
uv has "exclude-newer" https://news.ycombinator.com/item?id=47513932
34.
▲
by
collinmanderson
7mo ago
If you lock your dependencies, it should fail if the hash doesn't match.
35.
▲
by
collinmanderson
7mo ago
uv also has --exclude-newer-package which I think can be used for overriding just a certain package. https://docs.astral.sh/uv/reference/cli/#uv-run--exclude-new... https://docs.astral.sh/uv&#
36.
▲
by
collinmanderson
7mo ago
There are more apps, fewer libraries. You don't need as many libraries when functionality can be vibe-coded. You don't need help from the open source community when you have an AI agent. The apps are probably mostly websites and n
37.
▲
by
collinmanderson
7mo ago
> "Red/green TDD" is apparently the nomenclature From your link: > what "red/green" means: the red phase watches the tests fail, then the green phase confirms that they now pass. > Every good model und
38.
▲
by
collinmanderson
7mo ago
I agree using the preferred city name works just fine for USPS, though maybe not for UPS/Fedex. What I want to know is: Why isn't this preferred city+state mapping dataset for zip codes publicly available from USPS? It would be li
39.
▲
by
collinmanderson
8mo ago
I suspect they have generic SVG drawing that they focus on.
40.
▲
by
collinmanderson
9mo ago
Yes, this is super annoying. I keep getting SMTP errors like: 334 VXNlcm5hbWU6 UGFzc3dvcmQ6 Authentication unsuccessful [BL1PR13CA0304.namprd13.prod.outlook.com 2026-01-22T20:59:23.476Z 08DE59C2EA6C3D25] and: '550 (x.x) [x.x.x.x]:xxxx
41.
▲
by
collinmanderson
9mo ago
Yes, this is super annoying. I keep getting SMTP errors like: 334 VXNlcm5hbWU6 UGFzc3dvcmQ6 Authentication unsuccessful [BL1PR13CA0304.namprd13.prod.outlook.com 2026-01-22T20:59:23.476Z 08DE59C2EA6C3D25] and: '550 (x.x) [x.x.x.x]:xxxx
42.
▲
by
collinmanderson
9mo ago
Yes. This is super annoying. I keep getting SMTP errors like: 334 VXNlcm5hbWU6 UGFzc3dvcmQ6 Authentication unsuccessful [BL1PR13CA0304.namprd13.prod.outlook.com 2026-01-22T20:59:23.476Z 08DE59C2EA6C3D25] and: '550 (x.x) [x.x.x.x]:xxxx
43.
▲
by
collinmanderson
9mo ago
> it could not be more unpopular right now to tell people to stop eating meat If we phrased it from a carbon perspective that would probably help it be more popular, at least for beef which is a huge methane emitter. https://o
44.
▲
by
collinmanderson
9mo ago
Yeah that seems phrased wrong, but here's xkcd visual: https://xkcd.com/1338/
45.
▲
by
collinmanderson
10mo ago
Can you rsync a repo from GitHub?
46.
▲
by
collinmanderson
10mo ago
I consider apt kinds slow. I wish it were much faster.
47.
▲
by
collinmanderson
10mo ago
Some issues I noticed were: > PEP 658 went live on PyPI in May 2023. uv launched in February 2024. uv could be fast because the ecosystem finally had the infrastructure to support it. A tool like uv couldn’t have shipped in 2020. The sta
48.
▲
by
collinmanderson
10mo ago
Using the -S (“isolated”) flag can maybe cut startup in half.
49.
▲
by
collinmanderson
10mo ago
> I agree the email module is atrocious in general Hah. Yes sounds like we are very much on the same page here. Python stdlib could really use a simple generic email/http header parser. > It's unusual that you actually need
50.
▲
by
collinmanderson
10mo ago
> the conversation here keeps collapsing back to "Rust rewrite good/bad." That feels like cargo-culting the toolchain instead of asking the uncomfortable question: why did it take a greenfield project to give Python the pa
51.
▲
by
collinmanderson
10mo ago
If it’s running code outside of a normal browser sandbox then, yes it’s a RCE. Because it can now access to nearly everything on the user’s computer, including their browser, email, etc. XSS is limited to accessing just that one website.
52.
▲
by
collinmanderson
10mo ago
Yes, it's generally a "full account takeover" for a given discord user. But RCE usually means ability to run any code on the web server, and would generally get you access to _everything_ including full direct access to the d
53.
▲
by
collinmanderson
10mo ago
with http-only they can't _steal_ the cookie, but they can still _use_ the cookie. It reduces the impact but doesn't fully solve it.
54.
▲
by
collinmanderson
10mo ago
with http-only they can't _steal_ the cookie, but they can still _use_ the cookie. It reduces the impact but doesn't fully solve it.
55.
▲
by
collinmanderson
10mo ago
Generally code execution within browser/client-side javascript sandbox is just "XSS". RCE usually implies server-side code execution (or breaking out of browser sandbox).
56.
▲
by
collinmanderson
10mo ago
> But you can use an `img` tag (`<img src="evil.svg">`) and that'll basically Just Work That doesn't help too much if evil.svg is hosted on the same domain (with default "Content-Type: image/svg+xml&qu
57.
▲
by
collinmanderson
10mo ago
Yes. It's hard to explain the experience of hosting a website since 2023. A crazy amount of really dumb bots loading every url on the website in a full headless browser, with default Chrome user-agent string. All different ip addresses
58.
▲
by
collinmanderson
10mo ago
I've always assumed it was something like: ruff - "RUst Formatter". ty - "TYpe checker" uv - "Unified python packaging Versioner"? or "UniVersal python packaging"
59.
▲
by
collinmanderson
10mo ago
Thanks. I really need better generics support before ty becomes useful. Currently decorators just make all return types unknown. I need something this to work: _F = TypeVar("_F", bound=Callable[..., Any]) def my_decorato
60.
▲
by
collinmanderson
10mo ago
> worst thing they've shipped since Internet Explorer IE6 was a really good browser when it shipped in 2001, especially compared to Netscape 6. The problem was it didn't improve for the next 5 years.
More ›