Tweet fixado
Daniel Hepper
2.6K posts

Daniel Hepper
@danielhepper
CTO @userlike 🐍 Pythonista 🏃♂️ Amateur runner 👨👩👦 Dad
Cologne Entrou em Mart 2008
673 Seguindo739 Seguidores

@ReimarBauer We have an SBOM of our dependencies across all languages with dependency track. But that doesn‘t tell me which of our dependencies used Trivy as part of their CI pipeline, meaning they were potentially compromised. Haven heard of Pixi, since we are not in the Conda ecosystem.
English

@danielhepper You do have a full SBOM by the pixi.lock file. This includes any dependency.
Consider for a future issue.
English

Is there a list of packages that used a compromised version of Trivy in their CI? I can check my dependency graph, but I can‘t check the Github workflow history of all our dependencies.
Daniel Hnyk@hnykda
@Callum_McMahon_ @karpathy @simonw PyPI quarantined it in 46 minutes, but that was enough for 47k downloads. 2,337 packages on PyPI depend on litellm. 88% had no version pin. We analyzed that, check if you were exposed: futuresearch.ai/blog/litellm-h…
English

@RyanHoliday How do you cure „the slows“? Asking for a friend.
English

@arvidkahl I was quite impressed by Shannon: github.com/KeygraphHQ/sha…
It will happily use up half your weekly quota though
English

@d4m1n We are using @withgraphite Diamond. It catches issues on a regular basis, but there are also many false-positives.
English

@jasonfried @adamjcolvin Your designers write HTML/CSS, right? Our designers use Figma, frontend devs write React/TS, and backend devs use Python. Without a common workpiece, collaboration between design and frontend is challenging. As a result, designers sometimes don‘t get involved at all.
English

@adamjcolvin Our teams are one designer and one programmer. That’s the split you’re describing. No one waits - they work together. It’s a dance. Someone leads, but both are moving.
English

@forgebitz I was thinking in terms of security, but if you think of competition, absolutely.
English

@arvidkahl “experienced open-source developers working on their own repositories” - I’d argue that’s not representative of most software development.
English

Okay this is pretty wild:
"When developers are allowed to use AI tools, they take 19% longer to complete issues—a significant slowdown that goes against developer beliefs and expert forecasts. This gap between perception and reality is striking: developers expected AI to speed them up by 24%, and even after experiencing the slowdown, they still believed AI had sped them up by 20%.
Source: metr.org/blog/2025-07-1…
English

Last day of PyCon DE & PyData 2025 being kicked of by @lvwerra giving a glimpse into the future of AI

English

@GergelyOrosz I agree that 16 GB should be enough, but it really isn’t anymore. Unless you are very disciplined with your open apps (and tabs!), you just have to bite the bullet and upgrade to >32 GB. Our dev machines have been 32 GB for a few years now.
English

On my way home from PyConWeb. Thanks for the team putting together a great event and getting me back on the conference bandwagon. Looking forward to next year!
PyConWeb@pyconweb
The wrap-up of our #PyConWeb 2035 full of insights, discussions, coffee, lightning talks and fun. A huge thanks you from our team to each of you who was with us on-site and online 🙌✨
English

@CristianRus4 Is it possible to customize the special events in the life view?
English

hey 👋 I made an app!
Meet Left, a new way to visualize time
inspired by @waitbutwhy, I decided to build an app to see the time left as dots
it's completely free and now available on the App Store

English

@nikitabier Don’t forget that someone has to push the fuel rods into the nuclear power plants. So many opportunities!
English












