Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
shanipribadi
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
shanipribadi
1y ago
had something similar happened a few years back.. basically the go binaries i compiled and run would get deleted every time I try to run it. usually just downloading the newer version of go compiler and recompile with that solves it (I thin
2.
▲
by
shanipribadi
1y ago
In addition to the managed PG cloud being shutdown, it seems that pgt.dev (Trunk, a Postgres package manager and extension registry) is also being shutdown, "We are sunsetting Trunk and ending active maintenance. The site and packages
3.
▲
Tembo: Pivot to Autonomous Software Maintenance; Managed PG Is Shutting Down
(tembo.io)
1 points
by
shanipribadi
1y ago
|
2 comments
4.
▲
by
shanipribadi
1y ago
The new Tembo is a superhuman junior developer, It polls your database, reads your stack traces, analyzes your monitoring tools, understands your codebase, and turns noisy alerts into production-ready pull requests. Previously this was laun
5.
▲
by
shanipribadi
3y ago
Looking forward to the time when Meta will make https://github.com/facebookincubator/zstrong.git public found it mentioned in https://github.com/facebook/proxygen/blob/main/build
6.
▲
by
shanipribadi
4y ago
think BI tools, analytics dashboards for exploratory analysis, or even just exploratory analysis on the terminal with it's rich query capabilities. you can keep analytics data in SQLite, but DuckDB will process it faster/easier
7.
▲
by
shanipribadi
4y ago
https://en.wikipedia.org/wiki/Online_analytical_processing as opposed to https://en.wikipedia.org/wiki/Online_transaction_processing DuckDB is when you need to do OLAP analysis, and the data fits
8.
▲
by
shanipribadi
4y ago
@smhx are you sure? at the time of this comment, I was still able to download 2.0.0.dev20221230 pip3 download torch==2.0.0.dev20221230+cpu --extra-index-url https://download.pytorch.org/whl/nightly/cpu and on
9.
▲
by
shanipribadi
4y ago
Alex Birsan actually published his findings for this vulnerability in Feb 2021 [1], and collected a bunch of bug bounties from various companies (Apple, Microsoft, Paypal, Yelp, Tesla, Shopify, Uber, Netflix). He was able to steal package
10.
▲
by
shanipribadi
4y ago
hashes would also need to be specified for all dependencies (transitives) in case they were needed, and all dependencies need to be pinned to specific versions as well. hence this would only work when users are making use of venvs, instead
11.
▲
by
shanipribadi
4y ago
For comparison, iOS and Android's security model would not allow a Python package to steal SSH keys. But the best solution would be to implement least privileges principle and do not grant unnecessary privileges to programs. I think
12.
▲
by
shanipribadi
4y ago
there's a few factors here that allow dependency confusion attack to happen here 1. pytorch publishes their nightly package on their repo which depends on a custom triton build provided on their repo, but using a package name they don&
13.
▲
by
shanipribadi
4y ago
the 3.0.0 version that is available on pypi is now an empty package with updated description of This is not the real torchtriton package but uploaded here to discover dependency confusion vulnerabilities the compromised version is still a
14.
▲
by
shanipribadi
4y ago
it still has the javascript limitation of ieee float for json numeric (hence rounding once you have bigger than 2^53) :-(
15.
▲
by
shanipribadi
4y ago
could also be zero if it doesn't have any chairs at all because it's either a t-bar or standing gondola type.
16.
▲
by
shanipribadi
5y ago
Both postgres timestamptz and timestamp are the same, they both store timestamp as UTC epoch time. Also timestamptz does not store the timezone given by the client, the only thing it stores is the UTC epoch time, so you'll lose the ori
17.
▲
by
shanipribadi
6y ago
mixed active content was why the browser blocked it. the cdnjs link is http, while the site is https.
18.
▲
by
shanipribadi
7y ago
``` Surely there are other more important features delivery business value to be done rather than re-inventing (and then scaling and supporting) the delivery of mobile notifications. ``` the business value the service provided is that this
19.
▲
by
shanipribadi
7y ago
The title of the blog is actually a click-bait. The point of the article was more that when you have multiple teams, each owning multiple products, having a single well-defined abstractions over external dependencies provided as a service t
20.
▲
by
shanipribadi
8y ago
Hello, I'm curious how do you guys operate the flink cluster, do you have a single huge shared flink cluster where people can submit any kind of jobs for various applications/streams. Or do you have multiple smaller flink clusters