Sam Rose

11K posts

Sam Rose banner
Sam Rose

Sam Rose

@SamRose

Postgres Manager @ Supabase, Complex systems science, Foresight practice, Research, Nix/Nixos, Elixir/BEAM, Julia, Clojure, Go, Postgresql, PostgREST, Scala

Lansing, MI Katılım Şubat 2007
2K Takip Edilen1.6K Takipçiler
Sabitlenmiş Tweet
Sam Rose
Sam Rose@SamRose·
I'm now able To push those spirits outside My thought is free And forever lives in me Psychic transfer I've stolen their unique power Nothing can stop the evacuation Nothing can stop the psychic vacuum
Sam Rose tweet media
English
0
0
6
2.8K
jordi
jordi@jordienr·
we have to bring back the SQL propaganda
English
1
0
8
436
Turk
Turk@gitpush_gitpaid·
the only guarantees in life death, taxes, and me clicking resume on my free tier supabase project
Turk tweet media
English
2
0
16
519
jordi
jordi@jordienr·
@SamRose i heard pg rewrite in rust
English
2
0
0
27
jordi
jordi@jordienr·
pumped for what we're shipping at supabase this year, everyone is heads down working on great stuff
jordi tweet media
English
3
1
13
534
Sam Rose retweetledi
José Valim
José Valim@josevalim·
The whole Anthropic kerfuffle would have gone much smoother if they had been upfront about it. "Hey, we know this is unpopular, but we are moving programmatic access to API pricing. To easen the transition, we are giving API credits that match your subscription value. We also expect this change to increase capacity, so we are doubling the limits throughout Claude products for the next 2 months". The reason they made it sound like an upgrade was because the announcement was not for developers. It was for investors and enterprise customers. Impacting devrel is just collateral damage, which is on par for a company which believes coding is going away any time now. And this is extremely disapointing because they want to position themselves as a company that we should trust. But if they can't be honest about pricing changes, it is really hard to believe them on anything else.
English
28
47
535
28.3K
Sam Rose
Sam Rose@SamRose·
@grhmc The same way gas stations do it.
English
0
0
0
68
Graham Christensen
How does AWS's spot market actually do pricing?
Graham Christensen tweet media
English
4
0
6
2.5K
Sam Rose retweetledi
Jeff Martens
Jeff Martens@Jmartens·
Have you seen all of the software supply chain security issues recently? I don’t think this is a spike that will die down. This is the new reality, and it points to a simple truth: teams need more control over what runs in production.
English
2
2
2
456
Sam Rose
Sam Rose@SamRose·
@grhmc They should have listened when told nix fixes this
English
0
0
1
54
Sam Rose retweetledi
José Valim
José Valim@josevalim·
Elixir v1.20.0-rc.5 is out with our latest batch of typing and performance improvements. We are really close to the final release, so please give it a try and report what you find! elixirforum.com/t/elixir-v1-20…
English
2
37
246
13.4K
Sam Rose retweetledi
Supabase
Supabase@supabase·
Heads up: there's currently a typosquatting package on npm pretending to be related to Supabase: 𝗌​​​​𝗎𝗉𝖺𝖻𝖺𝗌𝖾-𝗃𝖺𝗏𝖺𝗌𝖼𝗋𝗂𝗉𝗍 This is not an official Supabase package. Always verify package names before installing dependencies, especially when using AI/codegen tools that may hallucinate package names. Official packages are published under the @𝗌𝗎𝗉𝖺𝖻𝖺𝗌𝖾/* 𝗌𝖼𝗈𝗉𝖾. We're actively working to get this package taken down.
English
16
44
213
32.6K
Sam Rose retweetledi
Danila Poyarkov
Danila Poyarkov@dan_note·
As a response to the ongoing npm supply-chain attacks, I released npm_ex 0.7.0. npm_ex is a pure Elixir npm package manager: resolve, fetch, cache, and link npm packages from Mix without Node.js. This release tightens the default security model: - lifecycle hooks are not auto-run - transitive git/url/file deps blocked by default - direct exotic deps require allowlisting - registry policy checks - OSV/OpenSSF malicious-package audits Also finally added proper HexDocs: getting started, dependency workflows, CI, supply-chain safety, audit docs, config + CLI cheatsheets. github.com/elixir-volt/np…
English
2
11
71
4K
Sam Rose retweetledi
Danila Poyarkov
Danila Poyarkov@dan_note·
Reach 2.3 Since 2.0, the smell engine went from 30 patterns to 80+, now covering most of what Credence (hex.pm/packages/crede…) detects plus IR-based analysis that AST-only tools can't do. New in 2.1–2.3: • Repeated traversal — flags Enum.max + Enum.min + Enum.count on the same list • Nested O(n²) — Enum.member? inside Enum.map on the same variable • ++ [item] in recursion — with auto-suggested prepend+reverse fix • Multiple Enum.at with literal indices — suggests pattern matching • Piped Regex.replace — catches the subtle argument swap bug • 20+ new pipeline/collection patterns: Map.keys/values waste, identity _by functions, redundant separators, Python idiom ports Every pattern corpus-tested against 500 top Hex packages. github.com/elixir-vibe/re…
English
0
2
33
1.2K
Sam Rose retweetledi
Vic 🌮
Vic 🌮@VicVijayakumar·
how I’m getting work done without freaking out about the npm supply chain today: ❯ go run hello_world.go hello world
English
7
4
169
7.1K
Sam Rose retweetledi
José Valim
José Valim@josevalim·
We have just wrapped up the meta-issue which tracked type inference of all Elixir constructs: github.com/elixir-lang/el… It includes typing of the construct themselves and features like occurrence typing, to provide a high-degree of precision. Expect a new RC soon as we will continue measuring performance on our way to Elixir v1.20.
English
3
30
197
10.9K
Sam Rose retweetledi
jordi
jordi@jordienr·
My plans for the week vs a supply chain attack on npm
English
1
6
41
5.1K