Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
greysteil
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
91.
▲
by
greysteil
8y ago
They do, yep - only post 1.x releases are included.
92.
▲
by
greysteil
8y ago
So much this. SemVer isn't perfect but it's a lot better than nothing. In addition, generally speaking folks are pretty good at sticking to it. I've analysed the number from all the updates Dependabot makes to build SemVer co
93.
▲
by
greysteil
8y ago
Big +1 for this. The only criticism I have of Indie Hackers is that sometimes discussion can get a little spammy (lots of people looking for early adopters). Not every conversation is like that, but some posts are. As someone building a sta
94.
▲
by
greysteil
8y ago
The version resolution algorithm is very similar to NuGet's "lowest applicable version" logic, which has been around since 2010. I've seen surprisingly little discussion of the fact they're so similar. https:/
95.
▲
by
greysteil
8y ago
This is about to get better - check out https://github.com/pypa/pipenv/pull/3304 .
96.
▲
by
greysteil
8y ago
You might want to check out https://github.com/pypa/pipenv/pull/3304 , which Dan is actively working on to solve that.
97.
▲
by
greysteil
8y ago
FWIW, resolution in Python is significantly harder than for Ruby, JS or Elixir because it requires cloning down each dependency. To really speed it up, what's needed is a registry API that provides all of the details for resolution. Th
98.
▲
by
greysteil
8y ago
Sometimes, improvements don't happen in a straight line. There's been a lot of work on Pipenv over the the last 6 months, predominantly by Dan Ryan and Tzu-Ping Chung, and it's getting stronger and stronger with each release.
99.
▲
by
greysteil
8y ago
Haha, thanks, I guess that's one place where Dependabot shows its side-project roots - I just want as many people to use it as possible, and am less fussed about capturing the biggest share of value.
100.
▲
by
greysteil
8y ago
About 6 months and it was tough! 2 months of that (part time) was the initial build and the rest was hustling to get initial users. GitHub wouldn't put it in the GitHub Marketplace (which drives pretty much all signups now - I don'
101.
▲
by
greysteil
8y ago
I built https://dependabot.com to be passive, but ended up going full time on it (the startup I was working on feel through). Generates $9k/month passively, but I put my full-time energy into growing it (adding new language
102.
▲
by
greysteil
8y ago
This is exactly what we do with Dependabot. We have support for dep right now (along with other languages) and will be adding modules support in the next few days.
103.
▲
by
greysteil
8y ago
I had a similar experience getting Dependabot onto the front page of HN as a "Show HN"[1], all be it with less attention than this post (congrats on that!). - Made it to #10 or thereabouts, and hung around on the front page for ~2
104.
▲
by
greysteil
8y ago
So much love for everyone who received an "accepted" email in error. Don't let it get you down. I just got rejected with https://dependabot.com despite $6k MRR and 2,000 active users. I'm sure there are lots
105.
▲
by
greysteil
8y ago
Thanks Kacy! Had been looking forward to having others to learn from, but I'm pretty confident that Dependabot is going to be OK. Would love to hear from all the companies that got accepted!
106.
▲
Ask HN: Who got on to Startup School?
20 points
by
greysteil
8y ago
|
15 comments
107.
▲
by
greysteil
8y ago
Getting to $200k ARR is an amazing achievement, particularly in just one year and without funding. I can't advise you on pursuing an acquisition, but I'm in the same boat as you - I run a one-person company making $65k ARR after 1
108.
▲
by
greysteil
8y ago
So much this. If you want to build a business then there will be a lot of non-technical things to learn along the way. Keep the tech familiar so you can focus on those.
109.
▲
by
greysteil
8y ago
One of the nicest additions to the GitHub Marketplace is a bot that will optimise your images automatically: https://github.com/marketplace/imgbot (No connection to me - just think it's a great idea, and totally f
110.
▲
by
greysteil
8y ago
FWIW, I'm not sure I'd recommend that. For things outside your control, you've got to deal with the world as it is, not how you would like it to be. Slack own the game for chat bots right now - I think the advice you got from
111.
▲
by
greysteil
8y ago
Before patents, copyright law, and all that, secrecy was the only way to stop people copying your stuff. That was kinda crappy, and people went to great lengths to obfuscate their IP, expending lots of effort on something that had no benefi
112.
▲
by
greysteil
8y ago
That's not what I'm saying, and I don't think I'm spreading any falsehoods about free software licenses here. Building a business is about distribution as well as product. My product is pretty good, but my distribution,
113.
▲
by
greysteil
8y ago
Totally agree on licenses and transparent pricing in general, but I think you've missed the context here. If a commercial entity wants to add the core functionality of my product to their offering then there's definitely going to
114.
▲
by
greysteil
8y ago
Great blog post - thanks for writing it. I've had the same experience with people asking for an MIT license on dependabot-core (the public repo that holds the core logic for my SaaS business, but which has no license and a comment sayi
115.
▲
by
greysteil
8y ago
For us (Dependabot) the best advice I ever got was that your initial customers should come from sales, not marketing, even for a really low-price SaaS product. I was literally giving Dependabot away for the first 6 months of its existence,
116.
▲
by
greysteil
8y ago
Seriously? Where is the “congratulations” message?
117.
▲
by
greysteil
8y ago
You’re totally right - I was thinking of Composer, which does flat resolution for git sources so has to go through the above. Cargo sidesteps that issue completely by taking the head commit or whatever’s asked for :-)
118.
▲
by
greysteil
8y ago
Cargo performs dependency resolution, so fetching from git would (and does) significantly slow it down - it wound need to perform git operations to get the tags for each dependency (quick) and then checkout each tag to look for the subdepen
119.
▲
by
greysteil
8y ago
I worked with @iarna over at npm to get a very similar bug fixed - https://github.com/npm/npm/pull/20198 . I'm pretty sure this is just a special case of that bug - if you're not on npm 6.1.0 it migh
120.
▲
by
greysteil
8y ago
I built Dependabot to automate keeping dependencies up-to-date / responding to security vulnerabilities at GoCardless. Spun it out into its own business. https://dependabot.com My best automating stuff story, though, is aut
More ›