Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jacobian
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
jacobian
7y ago
Why?
32.
▲
by
jacobian
7y ago
My experience has been that the easiest method is to to upgrade one minor release at once (e.g. in your case I'd do 1.11 -> 2.0 -> 2.1 -> 2.2 -> 3.0). This has almost always gone quite smoothly, but it is somewhat tedious.
33.
▲
by
jacobian
7y ago
I would love to read a blog post covering how to do this! My experience has been that it's significantly more effort to meet my requirements with Docker, and that I spend a _lot_ of time waiting on Docker builds, or trying to debug fin
34.
▲
by
jacobian
7y ago
Ha, I'd forgotten about that. Thanks for the reminder. (Though, how'd you find that? Mildly creepy that you know more about my dotfiles than I do!)
35.
▲
by
jacobian
7y ago
> the feedback you get is minimal I've been in hiring roles for 15+ years and I've interviewed somewhere around 1000 candidates. I don't work at Stripe, but I can probably explain why you didn't get feedback. Giving c
36.
▲
by
jacobian
8y ago
Thank you! The new auto reloader is better by quite a bit. Many people have talked about doing this over the years, but nobody's been willing to do the grunt work and figure out all the corner cases, until you. Nice job!
37.
▲
by
jacobian
8y ago
Hi, former BDFL here. It's a crappy job. A crappy, unpaid job. I can't think of a single qualified person in the Python community who'd want the gig. (I can think of several unqualified people who would, and that's part
38.
▲
by
jacobian
8y ago
> It's hard to drive non-incremental innovation without a benevolent dictator model. Hmm, dunno that this is a universal truth. Most of the biggest improvements to Django came after Adrian and I stepped down and we moved to a more d
39.
▲
by
jacobian
9y ago
I assume you have some standards of behavior, though, right? If a member of your group, say, punched another member, you’d probably kick him out, right? If so: you have a code of conduct, you just don’t have a _written_ code of conduct. You
40.
▲
by
jacobian
10y ago
Can you expand on why donating to state offices is more effective? And, which states?
41.
▲
Tableflip dot club
(tableflip.club)
17 points
by
jacobian
12y ago
|
1 comments
42.
▲
by
jacobian
13y ago
You may want to check out Invoke ( https://github.com/pyinvoke/invoke); it's the successor to Fabric, and it's Python 3 compatible.
43.
▲
by
jacobian
13y ago
> IaaS providers don't do blog posts proudly declaring that they now support 3 year old technology. http://aws.typepad.com/aws/2013/07/elastic-load-balancing-ad...
44.
▲
by
jacobian
13y ago
How, exactly, is one supposed to cite unpublished research?
45.
▲
Join me in supporting the Ada Initiative
(jacobian.org)
4 points
by
jacobian
13y ago
|
0 comments
46.
▲
by
jacobian
13y ago
1) I know the difference between sessions and logging in. I didn't say anything about logging in; I said that our CSRF protection protects users without sessions . Not all sites use sessions (some for performance reasons, others for p
47.
▲
by
jacobian
13y ago
Again, we believe that sessions and CSRF protection can be orthangonal (and that there are benefits to doing so). If you can prove otherwise, let us know! There's also https://github.com/mozilla/django-session-csrf
48.
▲
by
jacobian
13y ago
Yes, that's correct, in theory BREACH can be used to target any sort of secret embedded in the body of an HTTP response. CSRF tokens are the most common type of secret in that category, but there are others. However, we can't spea
49.
▲
by
jacobian
13y ago
To your second point, security@djangoproject.com. It's documented in a bunch of places; where'd you look for it? I'll add it there, too :) To the first point, we believe that Django's CSRF protection is as strong as sess
50.
▲
by
jacobian
13y ago
I have anecdotes about how CoCs have improved communities, but I don't really want to play dueling anecdotes with you. It sucks that you've seen Coc's used as a bludgeon; I haven't. However, it's sorta irrelevant he
51.
▲
by
jacobian
13y ago
For the record: we reached out to Valerie, not the other way around. We did that because we value her opinion. It's interesting to me that you seem so angry about a group that's trying to bring more people into tech. What are you
52.
▲
by
jacobian
13y ago
You're completely right: these documents articulate a set of standards that we've essentially been following from day 1. Nothing's really changed except that now we've written down the unspoken rules that nearly everybod
53.
▲
by
jacobian
13y ago
Can you identify specifically what you find patronizing and CYA-ish? Neither were our intentions; help me understand how we've failed there?
54.
▲
No more verbal abuse [on LKML]
(sarah.thesharps.us)
3 points
by
jacobian
13y ago
|
0 comments
55.
▲
How fucked is SSL?
(gist.github.com)
19 points
by
jacobian
13y ago
|
1 comments
56.
▲
JavaScript in your Postgres
(postgres.heroku.com)
93 points
by
jacobian
13y ago
|
42 comments
57.
▲
by
jacobian
13y ago
Yup, we made a mistake. You could help by submitting a patch to fix it, or you could just choose to be a jerk and give some random person shit for making a mistake. Your choice.
58.
▲
by
jacobian
13y ago
Mmmm.... I mean, it would, I guess, but I wouldn't recommend using both unless you can show a marked speed improvement over just using pgbouncer. A real connection is (probably) better than persistent connections, so you probably only need
59.
▲
by
jacobian
13y ago
Not exactly. It's not proper connection pooling -- for that, you still should be using an external pool like pgbouncer. Instead this is a single persistent connection per thread. The speed improvement should be about the same, but you somet
60.
▲
by
jacobian
13y ago
We're trying to, yeah. For this release specifically we wanted to have it out before the end of summer so that we can be ready to merge Andrew's migration work and any GSoC code and turn around another release quickly.
More ›