Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
slimslenders
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
slimslenders
10mo ago
I think this is very true. Tool search tools can be model agnostic. And programmatic tool calling really just needs a code sandbox tool. We've provided some examples of these patterns on top of a local docker engine (oss project is her
2.
▲
by
slimslenders
1y ago
Community MCP servers available as Docker images are also being listed here https://hub.docker.com/catalogs/mcp
3.
▲
by
slimslenders
5y ago
... chiming in as one of the co-creators of this feature. The ability to quickly ascertain whether a change will increase security debt ends up having a positive impact on code reviews too. It's useful to have a spotlight shining on
4.
▲
by
slimslenders
5y ago
Indeed, there's this curious fact that you can update the FROM instruction to be repos:tag@sha256:... In other words, you can leave the tag in the name even though the next docker build will use the digest sha. I do agree with you -
5.
▲
by
slimslenders
5y ago
Feel free to get in touch if you want to try out our tool. The support for pinning versions in run layers is just being released but happy to send you a breakdown of how that works.
6.
▲
by
slimslenders
5y ago
Just took a look. Very cool! The generate/verify/rewrite phases are very familiar :). I guess we sort of moved rewrite/verify into a PullRequest/CheckRun. Would it make sense to run verify and rewrite as a pre-commit
7.
▲
by
slimslenders
5y ago
will send when we've got some data. Had been wanting to reach out to you about an idea for an automated check anyway.
8.
▲
by
slimslenders
5y ago
I came across your article on security updates when I was researching this. Thanks for writing it - it was super helpful. One of the sub goals for us is to quantify the lag that you've observed here. We're also reviewing an aut
9.
▲
by
slimslenders
5y ago
Keeping the FROM readable is indeed a challenge. We thought about a Dockerfile comment to add the context that developers need. There's this peculiar aspect of docker image naming where you can include both a tag and a digest (reposi
10.
▲
by
slimslenders
5y ago
Thanks! And ya, we found the spec! We are in the middle of adding a feature to help devsecops teams notice when org.opencontainers.image.revision and org.opencontainers.image.source labels are missing (those were the first two which we con
11.
▲
by
slimslenders
5y ago
Thank you, and yes. I love that idea of a distance metric. I think you're also pointing out that distroless images can end up increasing this developer distance, right? I was originally drawn to the idea of distroless images as a wa
12.
▲
by
slimslenders
5y ago
Ya, it's similar. We needed to add an initial pinning PR, a vulnerability and change log comparison, and scanning for unsupported tags. We also added support for private registries so that we could use the same pattern for non-offici
13.
▲
Keeping Up with Docker Official Images
(blog.atomist.com)
57 points
by
slimslenders
5y ago
|
21 comments