Bobinas P4G
  • Login
  • Public

    • Public
    • Groups
    • Popular
    • People

Notices by muesli (fribbledom@mastodon.social), page 32

  1. muesli (fribbledom@mastodon.social)'s status on Tuesday, 14-May-2019 17:40:28 UTC muesli muesli
    • lachs0r

    @lachs0r

    Well, yes, but what's the alternative you're suggesting?

    This is why it's important to depend on well-maintained libraries.

    If they have good reasons to depend on different versions, they can technically do that.

    If that means they're inheriting a security risk from one of their dependencies, though, then it becomes their issue (and yours by inheritance) to deal with.

    In conversation Tuesday, 14-May-2019 17:40:28 UTC from mastodon.social permalink
  2. muesli (fribbledom@mastodon.social)'s status on Tuesday, 14-May-2019 17:33:14 UTC muesli muesli
    • lachs0r

    @lachs0r

    There is no importing _random_ shit though. You pin _and_ checksum a dependency with Go modules.

    It refuses to build if there's a checksum mismatch.

    In conversation Tuesday, 14-May-2019 17:33:14 UTC from mastodon.social permalink
  3. muesli (fribbledom@mastodon.social)'s status on Tuesday, 14-May-2019 17:30:18 UTC muesli muesli
    • lachs0r

    @lachs0r

    But is it really? I think you underestimate how young the language and ecosystem is and ignore what they achieved with "dep" and Go modules in recent years.

    It gives you all the tools you need to achieve reproducible builds now.

    In conversation Tuesday, 14-May-2019 17:30:18 UTC from mastodon.social permalink
  4. muesli (fribbledom@mastodon.social)'s status on Tuesday, 14-May-2019 17:25:01 UTC muesli muesli
    in reply to

    We need a system that lets us reproduce a packager's work and confirm that whatever they release was indeed built from a specific source tree without any unintended or even malicious changes.

    To achieve that we require reproducible builds, so we can correlate a build with its source tree(s) and dependencies.

    Whenever a new package gets released, this would allow independent systems and entities to verify that its contents really match the expectations.

    In conversation Tuesday, 14-May-2019 17:25:01 UTC from mastodon.social permalink
  5. muesli (fribbledom@mastodon.social)'s status on Tuesday, 14-May-2019 17:24:25 UTC muesli muesli

    Thread:

    We need to talk about packaging, signatures, checksums and reproducible builds:

    On your system you have a keyring of packagers' GPG keys that you inherently trust.

    Releases get signed with a key, which verifies the packager as the author, and supposedly lets you and your system trust their contents.

    But do you really trust your packagers? How could you? Do you know them personally and monitor their packaging work?

    Would you even know if they release a package with malicious content?

    In conversation Tuesday, 14-May-2019 17:24:25 UTC from mastodon.social permalink
  6. muesli (fribbledom@mastodon.social)'s status on Tuesday, 14-May-2019 15:01:33 UTC muesli muesli
    • Yisrael Dov :emacs:

    @yisraeldov

    Thank you! Keep in mind this is really still a pre-release. It's nowhere near feature complete (obviously), but I thought it's fun to give everyone the chance to join in and provide feedback as early as possible.

    Updates rolling in on pretty much a daily basis right now 😊

    In conversation Tuesday, 14-May-2019 15:01:33 UTC from mastodon.social permalink
  7. YlBi (ylbi@mastodon.social)'s status on Tuesday, 14-May-2019 12:41:37 UTC YlBi YlBi

    came across these little fellows walking through the forest.

    #photography #forest #gnomes #fairytale

    In conversation Tuesday, 14-May-2019 12:41:37 UTC from mastodon.social permalink Repeated by fribbledom

    Attachments


    1. https://files.mastodon.social/media_attachments/files/014/585/948/original/31499d8636d0003e.jpeg

    2. https://files.mastodon.social/media_attachments/files/014/585/997/original/7a945385a189e4f5.jpeg

    3. https://files.mastodon.social/media_attachments/files/014/586/004/original/3c69d3125c6d598a.jpeg

    4. https://files.mastodon.social/media_attachments/files/014/586/006/original/112ddb19ed8eae5b.jpeg
  8. muesli (fribbledom@mastodon.social)'s status on Tuesday, 14-May-2019 02:42:00 UTC muesli muesli
    • jejune :abunhdhappy:
    • Ben Lubar

    @kaniini

    The problem isn't the ID, but the pagination response also doesn't use integer values, but generated ID strings. I'm already preparing a PR for go-mastodon.

    Hang tight.

    @ben

    In conversation Tuesday, 14-May-2019 02:42:00 UTC from mastodon.social permalink
  9. muesli (fribbledom@mastodon.social)'s status on Monday, 13-May-2019 22:14:55 UTC muesli muesli
    • jejune :abunhdhappy:

    @kaniini It's actually an issue in the upstream go-mastodon client, but I'm working on a pull request for it. Soon, real soon!

    In conversation Monday, 13-May-2019 22:14:55 UTC from mastodon.social permalink
  10. muesli (fribbledom@mastodon.social)'s status on Monday, 13-May-2019 21:36:24 UTC muesli muesli
    • The System Known as Alicia

    @KitsuneAlicia And I highly appreciate it! It's absolutely important to keep track of thsse things. Attention to detail is important. A constant feedback loop during development is an immensly useful tool to have. As such I'm really looking forward to seeing more tickets and feedback from you!

    In conversation Monday, 13-May-2019 21:36:24 UTC from mastodon.social permalink
  11. muesli (fribbledom@mastodon.social)'s status on Monday, 13-May-2019 21:31:14 UTC muesli muesli
    • The System Known as Alicia

    @KitsuneAlicia

    Awesome! Just keep in mind we're still at a really early stage in development. It's not expected to be feature complete and there will be bugs... but never hesitate to open tickets!

    In return you get the chance to watch a Mastodon client grow on a daily basis and you get to help shape it.

    I hope more people find that intriguing and fun, otherwise I wouldn't have published it just yet 😆

    In conversation Monday, 13-May-2019 21:31:14 UTC from mastodon.social permalink
  12. muesli (fribbledom@mastodon.social)'s status on Monday, 13-May-2019 21:10:36 UTC muesli muesli
    • The System Known as Alicia

    @KitsuneAlicia That probably just means you don't have the qt5-xmlpatterns(-dev) package installed. The bindings for that particular library would be missing, but I don't think Telepathy depends on it in any way. It should probably still build fine. Let me know!

    In conversation Monday, 13-May-2019 21:10:36 UTC from mastodon.social permalink
  13. Telephant (telephant@mastodon.social)'s status on Monday, 13-May-2019 20:58:08 UTC Telephant Telephant

    Go fetch the latest build of Telephant!

    It now supports adding (and removing) extra panes for hashtags, has improved mouse wheel scrolling and a bunch of other, smaller fixes.

    Find the links in the README:

    https://github.com/muesli/telephant/

    In conversation Monday, 13-May-2019 20:58:08 UTC from mastodon.social permalink Repeated by fribbledom
  14. muesli (fribbledom@mastodon.social)'s status on Monday, 13-May-2019 12:43:31 UTC muesli muesli
    • zatty

    @zatnosk Will eventually clean that up, but it's nothing to worry about. It's initializing a delegate with an empty model, which simply lacks its members.

    In conversation Monday, 13-May-2019 12:43:31 UTC from mastodon.social permalink
  15. muesli (fribbledom@mastodon.social)'s status on Monday, 13-May-2019 12:14:56 UTC muesli muesli
    • Seize the means of computation

    @brandon

    I guess the avatar gave it away 😆

    In conversation Monday, 13-May-2019 12:14:56 UTC from mastodon.social permalink
  16. muesli (fribbledom@mastodon.social)'s status on Monday, 13-May-2019 05:01:49 UTC muesli muesli
    • Dustin Wilson
    • Chucu

    @Chuculate

    You may have a point there.

    @dustin

    In conversation Monday, 13-May-2019 05:01:49 UTC from mastodon.social permalink
  17. muesli (fribbledom@mastodon.social)'s status on Monday, 13-May-2019 04:53:57 UTC muesli muesli
    • :debian: 𝚜𝚎𝚕𝚎𝚊 :fedora:
    • emsenn (climate strike friday)

    @emsenn

    I guess that's possible, I must admit I didn't try that just now. But I'm very certain that pressing the test button does not indicate any battery level whatsoever: it always just fakes the same alarm sound.

    @selea

    In conversation Monday, 13-May-2019 04:53:57 UTC from mastodon.social permalink
  18. muesli (fribbledom@mastodon.social)'s status on Monday, 13-May-2019 04:45:35 UTC muesli muesli
    • emsenn (climate strike friday)

    @emsenn

    I'm really confused now. That's not how any smoke detector works that I've ever seen.

    You press the button, it fakes the alarm sound. No matter how full or empty the battery is: same sound.

    Well, I guess unless it's completely empty, then it doesn't beep, but that's kinda expected 😆

    In conversation Monday, 13-May-2019 04:45:35 UTC from mastodon.social permalink
  19. muesli (fribbledom@mastodon.social)'s status on Monday, 13-May-2019 04:43:58 UTC muesli muesli
    • Jesse Watson :ugandaknuckles:

    @me

    If I'd replace all the smoke alarms in this place with Nests, I'd probably first need to get a mortgage 😂

    In conversation Monday, 13-May-2019 04:43:58 UTC from mastodon.social permalink
  20. muesli (fribbledom@mastodon.social)'s status on Monday, 13-May-2019 04:39:43 UTC muesli muesli
    • emsenn (climate strike friday)

    @emsenn

    Then I guess I have literally the cheapest smoke detector out there, because mine definitely doesn't do that...

    In conversation Monday, 13-May-2019 04:39:43 UTC from mastodon.social permalink
  • After
  • Before

User actions

    muesli

    muesli

    Software #developer with a passion for #opensource, who enjoys #golang way too much. Made glow, beehive, knoxite, duf and a bunch of other cool things.If it got a firmware, I'll flash it.

    Tags
    • (None)
    WebSub
    Pending

    Following 0

      Followers 1

      • Galip (Inactive)

      Groups 0

        Statistics

        User ID
        10562
        Member since
        7 Jul 2018
        Notices
        1080
        Daily average
        0

        Feeds

        • Atom
        • Help
        • About
        • FAQ
        • Privacy
        • Source
        • Version
        • Contact

        Bobinas P4G is a social network. It runs on GNU social, version 2.0.1-beta0, available under the GNU Affero General Public License.

        Creative Commons Attribution 3.0 All Bobinas P4G content and data are available under the Creative Commons Attribution 3.0 license.