Raúl R Pearson

757 posts

Raúl R Pearson banner
Raúl R Pearson

Raúl R Pearson

@raulrpearson

Electrical engineer, freelance software writer. Building things, placing small bets, solving problems.

Nomad Katılım Nisan 2010
2K Takip Edilen207 Takipçiler
Artem Zakharchenko
Artem Zakharchenko@kettanaito·
I might be stupid on this, but why aren't browsers sending the client's dimensions to the server so it can fine-tune the rendering strategy knowing where the fold is?
English
23
0
139
43.8K
Raúl R Pearson retweetledi
Feross
Feross@feross·
🤨 People keep asking how to protect yourself. #1: set min-release-age=7 in .npmrc #2: install Socket for GitHub (it's free!) to protect PRs from bad dependencies: socket.dev/features/github #3: install Socket Firewall (also free!) to protect your laptop: socket.dev/features/firew…
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
57
286
2.4K
343.8K
Raúl R Pearson
Raúl R Pearson@raulrpearson·
@G_S_Bhogal @razibkhan a long time ago, pre-social media, I lived alone without a TV for a while, some of my friends remember that time as me always wanting to hang out
English
0
0
1
44
Gurwinder
Gurwinder@G_S_Bhogal·
@razibkhan I think a key reason friendships are more fragile today is that there are always so many things competing for people's attention. We got so good at distracting ourselves that we're also distracted from each other.
English
6
4
91
3.2K
𓀡 ɐʇǝɯ - 𝚄𝚗𝓉𝓇𝓊𝓁𝒾𝑒 𓀬
1. learning what a secure relationship looks like (rec: Wired for Love book) 2. learning if u tend to push people away or lack boundaries (rec: Attached book) 3. learning about commitment (“committed” means never doing something that hurts ur partner even if it’s unreasonable)
English
4
0
54
9.9K
Raúl R Pearson
Raúl R Pearson@raulrpearson·
I fell asleep and my Jira tickets were done
English
0
0
0
8
David Wong
David Wong@cryptodavidw·
choose your adventure: US state tax form or Chinese airline form
English
2
0
4
567
@levelsio
@levelsio@levelsio·
Are we entering the permanent underclass soon?
English
97
2
141
171.9K
Raúl R Pearson
Raúl R Pearson@raulrpearson·
Mitchell Hashimoto@mitchellh

AI eliminated the natural barrier to entry that let OSS projects trust by default. People told me to do something rather than just complain. So I did. Introducing Vouch: explicit trust management for open source. Trusted people vouch for others. github.com/mitchellh/vouch The idea is simple: Unvouched users can't contribute to your projects. Very bad users can be explicitly "denounced", effectively blocked. Users are vouched or denounced by contributors via GitHub issue or discussion comments or via the CLI. Integration into GitHub is as simple as adopting the published GitHub actions. Done. Additionally, the system itself is generic to forges and not tied to GitHub in any way. Who and how someone is vouched or denounced is up to the project. I'm not the value police for the world. Decide for yourself what works for your project and your community. All of the data is stored in a single flat text file in your own repository that can be easily parsed by standard POSIX tools or mainstream languages with zero dependencies. My hope is that eventually projects can form a web of trust so that projects with shared values can share their vouch lists with each other (automatically) so vouching or denouncing a person in one project has ripple effects through to other projects. The idea is based on the already successful system used by @badlogicgames in Pi. Thank you Mario. Ghostty will be integrating this imminently.

QME
1
0
0
33
Zach Daniel
Zach Daniel@ZachSDaniel1·
LLMs have increased the number of PRs that aren't so great and/or crap I have to deal with. But also I can say "fix this bug <github link>" and do something else for a while and have like a solid shot that its either fixed or I've got a lead. So... on balance I'm here for it.
English
3
0
30
1.7K
Raúl R Pearson retweetledi
José Valim
José Valim@josevalim·
Here is my take on why Elixir is the best language for AI: immutability, documentation, stability, and tooling for coding agents. It builds on the recent study in which Elixir had the highest completion rate across models among 20 different languages. Link in the thread below.
José Valim tweet media
English
17
98
399
33.8K
Steve Ruiz
Steve Ruiz@steveruizok·
Has anyone used their AI agents to come up with a personally-optimized learning flow? I feel like with enough context about how I learn and what I already know, I should be able to CRISPR myself
English
7
1
33
4.5K
Raúl R Pearson
Raúl R Pearson@raulrpearson·
@nestersk Maybe net adaptive to be wrong often so that we can be right occasionally.
English
1
0
1
18
Nesters Kovalkovs
Nesters Kovalkovs@nestersk·
We tend to attribute success to our actions more than random events that 'happen to us'. Why is that?
English
4
0
6
146
Fede’s intern 🥊
Fede’s intern 🥊@fede_intern·
Elixir is objectively the language current LLMs tend to code most reliably. It is also my favorite. Some people assume we are Rust maximalists at Lambda. The reality is simpler: we are deeply biased toward the Erlang ecosystem, including Erlang, Elixir, and Gleam, and we use Rust where it is the right professional tool. If you want to understand why this stack is unusually powerful, I recommend starting with Learn You Some Erlang. I also published a short guide on my GitHub called SaaS guidelines. I have built dozens of SaaS products over my career, reaching dozens of millions of users. I use that guide both to train LLM based workflows and to help teammates who have not built SaaS before learn the fundamentals quickly.
Fede’s intern 🥊 tweet media
English
13
0
31
3K
Heidi Priebe ⛰️☀️
Heidi Priebe ⛰️☀️@HeidiPriebe1·
Feeling like this might be the mantra for the whole middle portion of my life.
English
5
0
36
2.2K
Heidi Priebe ⛰️☀️
Heidi Priebe ⛰️☀️@HeidiPriebe1·
Slow is smooth, smooth is fast Slow is smooth, smooth is fast Slow is smooth, smooth is fast Slow is smooth, smooth is fast Slow is smooth, smooth is fast Slow is smooth, smooth is fast Slow is smooth, smooth is fast Slow is smooth, smooth is fast Slow is smooth, smooth is fast
English
4
18
210
5.8K