Rust

12.5K posts

Rust banner
Rust

Rust

@amureki

Software Engineer at https://t.co/kKULM3H3vT | OSS maintainer

Berlin, Germany Katılım Kasım 2009
386 Takip Edilen563 Takipçiler
Sabitlenmiş Tweet
Rust
Rust@amureki·
Rust tweet media
ZXX
0
0
11
0
Rust
Rust@amureki·
@ppleqlshit @Marat_Galiev У меня друг будучи в Вене ищет работу с опытом на стеке Python/Typescript/Rust. Куда писать? :)
Русский
1
0
0
229
Igor
Igor@ppleqlshit·
редкий зверь в эпоху AI: вакансия! есть тут Python/JS разрабы из EU? в идеале — Польша. есть работёнка для вас🙂
Русский
3
4
12
3.9K
Rust
Rust@amureki·
@dutch_dispatch Если пользователь при этом счастлив и двигает ползунок - проблема решена, причём без дорогих инженеров? :) А уязвимости сейчас везде есть, такой положняк. Если что, свалим на плохой AI. Ну и насколько страшно что взломают ползунок?
Русский
1
0
1
628
The Dutch Dispatch 🌷🪆
The Dutch Dispatch 🌷🪆@dutch_dispatch·
Наблюдаю рассвет вайбкодинга в неинженерном департаменте компании. Сегодня мне показали ПРИЛОЖЕНИЕ которое по движению ползунка анимированно вычитает 20 из введенного пользователем числа. Чем дальше тянешь ползунок, тем больше раз вычетает.
The Dutch Dispatch 🌷🪆 tweet media
Русский
8
1
118
7.4K
Rust
Rust@amureki·
I don't see at the moment how we can "manually" update dependency, since NPM does not allow package exclusion to the `min-release-age`: github.com/npm/cli/issues… CVEs are still important to handle, and patches are being released regularly across all popular frameworks and packages.
English
0
0
0
30
Low Level
Low Level@LowLevelTweets·
I would go longer than 2 days, probably a week or two, but this is great advice
🇮🇹 Massimo De Luisa@massimodeluisa

Easier way to protect yourself (if you are not infected yet) is to set a minimum release age in your package manager. For @npmjs: `npm config set min-release-age=2d` For @pnpmjs: `pnpm config set minimumReleaseAge 2880` For @bunjavascript: ``` # In bunfig.toml [install] minimumReleaseAge = 172800 ``` For Yarn: `yarn config set npmMinimalAgeGate "48h"`

English
41
76
1.4K
220.1K
Rust
Rust@amureki·
But dependency cooldowns have their own downsides, so we'd rather not do them blindly. Imagine a maintainer creating a new release that addresses CVEs. Would we still wait 2, 3, or 7 days before installing it? Maybe the better rule is to delay routine updates, but fast-track verified security fixes.
English
0
0
2
55
Gergely Orosz
Gergely Orosz@GergelyOrosz·
Yes, dependency cooldowns are a good one x.com/jangiacomelli/…
Jan Giacomelli@jangiacomelli

@GergelyOrosz You could add a dependency cooldown. e.g., never install versions that are less than 1 week old. Also, I think that for more and more things, it makes more sense to simply implement it yourself. But that's not true for everything - e.g., building an HTTP server from scratch

English
3
3
54
11.1K
Gergely Orosz
Gergely Orosz@GergelyOrosz·
Supply chain attacks are happening left and right with npm, PyPI and so many other places. It seems to be getting worse, everyone agrees. But what can you do about it? Some thoughts on possible approaches (all have tradeoffs). What did I miss? And what vendors actually work?
Gergely Orosz tweet media
English
97
46
526
50K
Rust
Rust@amureki·
Like what the actual F >The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran.
English
0
0
0
51
Rust
Rust@amureki·
@din_alt1 Японские небось?
Русский
0
0
0
228
Stessi
Stessi@din_alt1·
Получила письмо от Амазон о том, что они отзывают презервативы, которые я заказывала в 2024 году. Говорят, не пользуйтесь, они не соответствуют требованиям безопасности. Отправила обратно.
Русский
8
0
58
4.9K
Rust
Rust@amureki·
That feeling when you want to play Marathon, but Battlefield 6 season ends next week and you still need to finish the season pass.
English
0
0
0
37
Rust
Rust@amureki·
Python friends: I built pypigraph 🕸️ A small browser-only tool for exploring Python package dependency graphs. Paste `pyproject.toml` contents or a URL; inspect transitive deps, freshness, licenses, and package sizes.
English
1
0
1
62
Rust
Rust@amureki·
@meln1k Did you set up any plugins/extensions for pi? I find it horrifying but liberating that it has no gating/permissions out of the box.
English
1
0
0
61
Nikita M.
Nikita M.@meln1k·
before: codex / after: pi
Nikita M. tweet media
English
1
0
1
206
Rust
Rust@amureki·
Do we trust them, chat?
Rust tweet media
English
0
0
2
83
Igor Kotenkov
Igor Kotenkov@stalkermustang·
Good lord, I'm glad we're actually at 96% (s4.5, not opus4.6-7), which means we can solve climate change and cure cancer. But I'm a bit sad that AP from RL Labs can't even do multi-turn reasoning to dive into what they're commenting on.
Igor Kotenkov tweet media
Natasha Jaques@natashajaques

LLMs will supposedly solve climate change and cure cancer, but in fact they can't even do multi-turn reasoning tasks effectively (SOTA models are < 10% on this benchmark). Interestingly, this work directly compares how much extra performance you get when you add an agentic harness (figure 7): a lot for simple optimization problems, 0% for math and chemistry.

English
2
0
9
1.3K
Rust
Rust@amureki·
@moraes_c_ Huhu 👋 On Github notifications page, hover over the item to see a summary of the content for a quick look/action.
English
0
0
0
137
Camilla Moraes
Camilla Moraes@moraes_c_·
👋 I'm the PM on GitHub's Maintainer Love team, and we're focused on making your life easier. If you could wave a magic wand, what is the #1 feature you'd want us to ship? No idea is too tiny - the smallest changes often have the biggest impact. Drop your wishes below. 👇
English
104
33
112
36.1K
Rust
Rust@amureki·
Yesterday I attended a great @glazeapp Berlin event from @raycast crew. Fascinating team enabling people to build great stuff and exercise their imagination. Very well done, would love to see more events like this!
Rust tweet media
English
0
1
12
657