Guillermo Vayá

5.4K posts

Guillermo Vayá banner
Guillermo Vayá

Guillermo Vayá

@WillyFrog_

Figuring out how X works, for X being: - being a parent - managing amazing teams - Remote work - Open source - Photography - Jazz - Bass

Torrejón de Ardoz, Spain Se unió Ağustos 2009
686 Siguiendo267 Seguidores
Guillermo Vayá retuiteado
Mario Zechner
Mario Zechner@badlogicgames·
People of pi.dev. Supply-chain hardening release. Last week the mistralai package got shai huluded, which gave us a little scare (we were not affected, due to pinning). Starting today, we have the following safe-guards in place: - cut down dependencies to the absolute minimum. Sadly, Amazon Bedrock and Google GenAI SDK are ... not great in that regard. - direct external deps are pinned - the CLI ships an npm shrinkwrap for transitive deps - pi update --self disables lifecycle scripts - new dependency lifecycle scripts require explicit review if we add a new dependency to pi - lockfile changes are blocked pre-commit unless explicitly allowed - scheduled npm audit + registry signature checks run on GitHub, so we get to update dependencies as vulns are detected - 2fa releases, obviously While this is something, it can not prevent everything. If you use 3rd party extensions, you can get shai huluded, just like with any dependency installation that you haven't screened yet. That's not a pi thing, that's an "our industry is deeply fucked" thing. Enjoy the dystopia where everything is terrible!
Mario Zechner tweet mediaMario Zechner tweet media
English
38
56
785
46.4K
Guillermo Vayá
Guillermo Vayá@WillyFrog_·
El concepto de conocimiento tácito si lo tenía: esa intuición dada por el sufrimiento en un determinado campo que no puedes escribir en un libro El concepto de bancarrota del conocimiento tácito es nuevo para mí. Y muy interesante cekrem.github.io/posts/the-taci…
Español
0
0
0
15
Guillermo Vayá retuiteado
Antonio Ortiz
Antonio Ortiz@antonello·
Este vídeo de como un invidente utiliza el metro cada día para ir a trabajar de forma autónoma, con apps como Metrociego es espectacular. Me lleva a mucho optimismo a cómo con inteligencia artificial "verá y entenderá" mucho mejor el mundo alrededor dentro de poco.
Español
33
518
3.4K
104K
Guillermo Vayá retuiteado
Yehuda Katz
Yehuda Katz@wycats·
Yehuda Katz tweet media
ZXX
5
68
464
24.4K
Guillermo Vayá retuiteado
Bill Clerico
Bill Clerico@billclerico·
Claude Code is Farmville for 40 year old former software engineers
English
138
394
5.8K
592.4K
Guillermo Vayá retuiteado
Mario Zechner
Mario Zechner@badlogicgames·
People of pi.dev. Do not install.by via any method other than what's shown on the website and in the docs. E.g. we do not publish to brew and never will. Someone else did. We have zero control over what goes into the brew release.
English
18
54
417
26.8K
Guillermo Vayá retuiteado
Theo - t3.gg
Theo - t3.gg@theo·
Security things from the last few days: - CopyFail (linux pwn'd) - CopyFail 2/Dirty Frag - 13 advisories in Next.js - Over 70 CVEs addressed in MacOS 26.5 - ~50 CVEs addressed in iOS 26.5 - YellowKey (Windows Bitlocker pwn'd entirely) - GreenPlasma (Windows privilege escalation) - CVE-2026-21510 and CVE-2026-21513 confirmed to be used by Russia for Windows RCE - CVE-2026-32202 separately confirmed to be used by Russia for sensitive document access - Mini-Shai Hulud (over 300 JS and Python packages compromised via GitHub Action cache poisoning) - Google confirms they have identified AI-powered exploitation of zero days in an unidentified "open-source, web-based system administration too" - Canvas (popular LMS used in most schools) pwn'd entirely - PAN-OS (palo alto networks) pwn'd with a 9.3 severity CVE-2026-0300 Are you scared yet?
English
350
999
6.9K
777.1K
Guillermo Vayá retuiteado
Mitchell Hashimoto
Mitchell Hashimoto@mitchellh·
AI slop is good, actually. Slop is what enables fast parallel experimentation. The etiquette and skill is understanding the boundaries of where slop exists and the extent to which it should be cleaned up and how. A few examples: I’m working on the internals of some system right now. The API and GUI of this thing is fully zero shame slop. It’s horrible. But it lets me focus on the core quality while shipping a usable piece of alpha quality software to testers (transparent about the slop frontend). Similarly, this system has plugins. We sent agents in Ralph loops overnight to generate dozens of plugins. The plugins are slop. The quality is bad. The plugin API/SDK is absolutely not done. But we can test a full GUI with a full plugin ecosystem. When we change the API, we can regenerate them all. The cost of change is just tokens, the velocity is incomparable to before. I built Terraform. We tested and shipped TF 0.1 with about 3 very weak providers. Because we ran out of time. Building was slow. And when we changed our SDK the cost was immense. Totally different today, 10 years later. Today, I would’ve slop generated 100 providers (again, with transparency and cleanup later, but just to prove it out). As an anti example, I would not PR this (without prior warning) to another project. I would not throw this onto customers without full review or transparency (as I’m already doing). I would not accept first pass slop. It’s almost never right. Slop is a tool. And like anything else it’s not blanket bad or good. The context is everything.
English
106
221
2.7K
215K
Guillermo Vayá retuiteado
Robby Starbuck
Robby Starbuck@robbystarbuck·
Hantavirus is so insanely deadly that it would be criminal for anyone on that ship to be allowed off until they’ve conclusively found that no one has it anymore and that the virus hasn’t mutated to allow for easier human to human transmission. It’s the rare strain that already allows for human to human transmission but only with very close contact. If it somehow mutated to allow for easier transmission, it would be a nightmare the modern world has never seen. Simple solution is to send out another boat to act as a short term hospital and quarantine everyone until the threat has passed. We can’t take the chance of ever shutting down the world again. Just can’t happen. And it shouldn’t have happened with COVID, which is child’s play in terms of fatality rate in comparison.
Reuters@Reuters

The MV Hondius, carrying 150 people and hit by a deadly hantavirus outbreak that has killed three, is headed to the Canary Islands in Spain. The outbreak involves the Andes strain of hantavirus, which in rare cases can spread between people reut.rs/4w5h370

English
616
281
2.7K
494.1K
Guillermo Vayá
Guillermo Vayá@WillyFrog_·
Viendo el tema del ADN canino me surgen varias dudas que no veo respondidas ni en el articulo ni en la web de la empresa: - quien tiene acceso a esos datos? - por qué la web donde tengo que registrarlo ya me está ofreciendo un seguro de mascotas? - como van a asegurar que quien se salta la norma de recoger la caca no se va a saltar tambien la de registrarlo?
Guillermo Vayá tweet media
Ayuntamiento de Torrejón de Ardoz@Ayto_Torrejon

📌 Ya está disponible el número de mayo de la revista municipal Plaza Mayor #TorrejónDeArdoz 🔗 ayto-torrejon.es/revista-plaza-…

Español
1
1
0
110
Guillermo Vayá retuiteado
Kevin Tanaka
Kevin Tanaka@ItsKevinTanaka·
Gabor Maté on what trauma actually is: Asked "how do you define trauma?", Gabor Maté offers a definition that reframes how most people understand the word. "Trauma is a wound. The important distinction to make is that trauma is not what happened to you. It's what happened inside of you as a result of what happened to you." He illustrates this with his own story: "My trauma wasn't that my mother gave me to a stranger. The trauma was the wound which is that I perceive myself as not wanted. I perceive myself as abandoned. Who gets abandoned? Somebody who doesn't deserve to be loved." That internal wound, he explains, then shapes an entire life: "So then I developed this sense of not being good enough, not being lovable enough. Now that means I spend much of my life trying to prove that I'm good, that I'm lovable, that I am important, which then drives all kinds of behaviors which then create more problems." Gabor draws a sharp line between the event and the wound it leaves behind: "The trauma is not the event. That's the traumatic episode. The trauma is the wound that happens inside you."
English
5
51
220
22.4K
Guillermo Vayá retuiteado
Juan Carlos Amez
Juan Carlos Amez@juankaamez·
Personotecnia como CPS del factor X(v3) Agentes ventas,empresas y equipos Y UNA LOCURRENCIA(TM):EL VAU Durante años jugamos a algo cómodo+divertido: inventar personas en workshops con post-its de colores Spoiler:no eran personas Eran ficciones corporativas bien/mal diseñadas👇🧵
Juan Carlos Amez tweet media
Español
1
6
17
1.6K