Yitz Willroth™

41.7K posts

Yitz Willroth™ banner
Yitz Willroth™

Yitz Willroth™

@coderabbi

Coder & Rabbi, async. Former: StartupVet, DevBootCampGuru, Mentor, Consultant, Speaker, Author, ShorePHPFounder, NYPHPOrganizer. Now: Just trying to human well.

I refactor legacy coders.™ Katılım Aralık 2012
1.5K Takip Edilen5.3K Takipçiler
Sabitlenmiş Tweet
Yitz Willroth™
Yitz Willroth™@coderabbi·
@fuelventures Having as much time as I want to sleep, gym, leisure, etc. *is* success.
English
3
13
352
0
Yitz Willroth™
Yitz Willroth™@coderabbi·
@nicksdot For instance, I've never worked on a project/team that had any real semblance of stress testing -- six months ago I hadn't even heard of k6. 🤷‍♂️ Now, nothing hits production without load, stress, spike, and soak.
English
0
0
0
18
Yitz Willroth™
Yitz Willroth™@coderabbi·
@nicksdot Absolutely could have, but typically teams were too busy shipping features to create guardrails robust enough to trust fully.
English
1
0
0
21
Yitz Willroth™
Yitz Willroth™@coderabbi·
When I say that I don't review AI generated code directly, that doesn't mean that I trust AI generated code any more than you do. It means that I trust my ability to review it less than you trust yours.
English
1
1
1
142
Evan Sidery
Evan Sidery@esidery·
Nick Richards is a potential free agent option to monitor for the Sixers. With Philadelphia soon acquiring wing Kentavious Caldwell-Pope via buyout, Richards could become the primary backup big to complete their second unit: Labaron Philon Anfernee Simons KCP Dean Wade Richards
Evan Sidery tweet media
English
86
203
3.3K
484K
Yitz Willroth™
Yitz Willroth™@coderabbi·
@grousehaus @esidery If they cut Terry & Walker, and trade Broome (packaged with picks), they have enough to add another vet minimum contract, and re-sign Terry & Walker to 2-ways, while remaining under the first apron hard cap.
English
1
0
0
27
j becker
j becker@grousehaus·
@esidery 1. Nick Richards is not particularly good; and 2. Assuming they cut/trade 2 to 3 players to pay bron and KCP, they have no money and no roster spots
English
2
0
5
2.6K
Yitz Willroth™ retweetledi
Yitz Willroth™ retweetledi
Guillermo Rauch
Guillermo Rauch@rauchg·
The (software) factory is the product. Your product is only as good as the agents you set up to autonomously maintain it. This is what @elonmusk figured out about Tesla, and it's now true for the software world.
Guillermo Rauch tweet media
English
72
102
1.6K
215.3K
Yitz Willroth™
Yitz Willroth™@coderabbi·
@nicksdot Nick. You know that there isn't a "big boy company" on the planet that's going to do that.
English
0
0
0
9
Nick e/code
Nick e/code@nicksdot·
@coderabbi Nah, not my intention to be disingenuous. Then make your company make me sign an NDA - I’ll either find you where shit breaks for free or I will have a big aha moment for free.
English
1
0
0
7
Yitz Willroth™
Yitz Willroth™@coderabbi·
@nicksdot Now you’re just being disingenuous. You realize that isn’t possible — I’m not an indy-maker, the code is not mine to share.
English
1
0
0
12
Nick e/code
Nick e/code@nicksdot·
@coderabbi Let's go, anonymise your secret sauce and put up a repo.
English
1
0
0
11
Yitz Willroth™
Yitz Willroth™@coderabbi·
@nicksdot Oh, it is one hundred percent the latter. Have been doing it that way for ~1500 PRs over 90 days w/2 regressions, neither of which would have been caught by human code-review. I review plans and summaries thoroughly, but not code.
English
0
0
0
11
Nick e/code
Nick e/code@nicksdot·
> No one said that humans are completely out of the loop. > Still no line-by-line reivew. Where does my post say line-by-line? You are the one claiming you would not have done nothing. In this situation you *would* have been fkd without review. Either you actually still review but say otherwise in public or you are playing actual Russian roulette. I am calling it: the latter playing out over the next few months will be fun to watch! Already having my many "told you so" ready to spit. 😆
English
1
0
0
8
Nick e/code
Nick e/code@nicksdot·
@coderabbi Read the other comments. Show me your secret sauce! Otherwise I am not buying it. In theory I can also make everything sounds nice. 🫡
English
1
0
0
12
Yitz Willroth™
Yitz Willroth™@coderabbi·
@nicksdot "So you are now saying you *have to* control and review each dependency. Glad we agree!" No one said that humans are completely out of the loop. Decide the allowed change up front (control), update the allow list, and let CI block drift (review). Still no line-by-line reivew.
English
1
0
0
8
Nick e/code
Nick e/code@nicksdot·
> registry proxy + quarantine window Would not have helped. Literally a zero day; CVE I reported is even still not public. > SBOM + built-binary scan in CI SBOM locally? So the agent *cannot* do anything with your review? Or you mean locally it can do it and CI would catch it? If the latter, helps a lot when malicious code was added before it reaches CI. > lockfile CI: block on new package or hash change Now we are talking. So you are now saying you *have to* control and review each dependency. Glad we agree! --- Either I am bloody dumb af and don't get it or y'all not-looking-at-code-because-we-found-secret-magic-guardrails people close your eyes and sing la la la. Honestly, dunno. But as long it all is Twitter "trust me bro" I will not be deciding which it is. Show me your finished setup *right now* and I will *right now* admit that I am just too dumb to understand things. :)
English
1
0
0
32
Yitz Willroth™
Yitz Willroth™@coderabbi·
@nicksdot So the guardrail is an allowlist and a CI gate, no? You decide to add a dependency, it gets added in a discrete PR. Everything that follows in a second PR. If there is drift, CI blocks.
English
0
0
0
6
Nick e/code
Nick e/code@nicksdot·
A Go binary. > dependencies are part of the conversation up front It had clear instructions to never pull in anything without discussing it. Did it anyway; locally. They *do* "just" pull in things. If you now wanna tell me things I experience all the time don't happen, it's about getting absurd (no offence!).
English
1
0
0
6
Yitz Willroth™
Yitz Willroth™@coderabbi·
@nicksdot I’m not trying to be obtuse, but here’s where you lose me: "Yes, the project has commands for building dev and and production. And yes, it did *not* use it.” What belongs to Codex and what belongs to CI here?
English
1
0
0
15
Nick e/code
Nick e/code@nicksdot·
You are speaking in unclear, abstract language. What are these magic guardrails that cannot and are not bypassed? It is not skills, and it is not command wrappers for every possible command it could run. Because it bypasses those whenever it feels like. Yes, the project had clear instructions to always run `govulncheck`; and how to treat pulling in new dependencies. Yes, the project has commands for building dev and and production. And yes, it did *not* use it. It's me who had to do it manually, and who asked it whether it did. And when I did, it admitted that it ignored its clear instructions.
English
1
0
0
9
Yitz Willroth™
Yitz Willroth™@coderabbi·
@nicksdot Also, what exactly does "pulled in a dependency" mean here? Admittedly, probably simpler in the PHP ecosystem than in JS, but new dependencies are part of the conversation up front -- the agent doesn't have latitude to just pull something in.
English
1
0
0
18
Nick e/code
Nick e/code@nicksdot·
See below. Codex pulled in a dependency that itself was depending on an outdated, bundled, vulnerable binary. Only because I: A) don't allow it to run all kind of commands without approval, and B) review each dependency my environment was not at risk, and it did not end up in production. Now tell me again my carefulness "wouldn't have helped". 🤷‍♂️ x.com/nicksdot/statu…
Nick e/code@nicksdot

Submitted a responsible vulnerability report for a popular open-source toolkit today. Scan the actual built binary, not just your direct imports.

English
2
0
0
53
Yitz Willroth™
Yitz Willroth™@coderabbi·
@nicksdot - registry proxy + quarantine window - npm ci, --ignore-scripts - deny-by-default egress - SBOM + built-binary scan in CI - lockfile CI: block on new package or hash change
English
1
0
0
12
Yitz Willroth™
Yitz Willroth™@coderabbi·
@nicksdot You review, or a scanner reviews? Because "scan the built binary" isn't you. I may be missing something, but I'm just hearing an argument for establishing/maintaining the guardrails that make "humans for judgement & taste, AI for everything else" possible.
English
2
0
0
14
Yitz Willroth™
Yitz Willroth™@coderabbi·
@nicksdot Better plan: guardrail ingress and egress, establish containment, provide forensics, and keep mashing the merge button.
English
0
0
0
29
Yitz Willroth™
Yitz Willroth™@coderabbi·
@nicksdot Honest answer: nothing, on the day of, and reviewing the diff wouldn't have helped, either (nobody reads a minified postinstall payload).
English
2
0
0
42