Yarn

Recent twts in reply to #mna5wlq

Open Source Developer Intentionally Corrupts His Own Widely-Used Libraries
“Users of popular open-source libraries ‘colors’ and ‘faker’ were left stunned after they saw their applications, using these libraries, printing gibberish data and breaking..” reports BleepingComputer.
“The developer of these libraries intentionally introduced an infinite loop that bricked thousands of projects that … ⌘ Read more

⤋ Read More

@movq@www.uninformativ.de That’s actually not a bad thing though. Static linking has its advantages really and the belief that dynamic linking makes security patching easier is really quite rubbish.

You are right though it all comes down to how good your processes are (or not)

⤋ Read More

politics is a really complicated topic, to not say dirty. Needed but dirty at the end, so we delegate that kind the people to manage the public life.
That oversimplification said, we are surrounded by power, violence, rights violations and such. Simple fixes for complicated problems don’t work, and the last question is: What are we going to do as individuals and as a community?

⤋ Read More

@movq@www.uninformativ.de Yeah I get your points. I used to maintain hundreds of packages for the CRUX distro once upon a time, so I get it. Your points about having a “2nd pair of eyes” are somewhat valid, but I say that because I’ve been a maintainer myself, we don’t often do the “right” things as a maintainer and we sometimes get sloppy/lazy….

⤋ Read More

@movq@www.uninformativ.de I think overall there are two issues at play here we can agree on, whether or not it’s “managed” by a distro (I think that’s kind of irrelevant here, I use/develop on macOS for example and use brew but I don’t want my deps to come from Homebrew uggh yuck) – Anyway There are two issues I see:

  • Supply Chain – Being able to vet, validate and verify everything that goes into a piece of software or product/service
  • Library hygiene – Being prudent about libraries as a Library author and reducing or eliminating “transitive” dependencies.

⤋ Read More

@eaplmx@twtxt.net Yeah I agree! 👌 One of my greatest hopes is that as Yarn.social continues to grow, that each Pod and it’s Pod Owner/Operator (we seem to be calling Poderator thanks to @ullarah) will create and nature small communities. The “network” as such will basically be an interconnected network of Yarn pods + Twtxtv2 feeds.

⤋ Read More

Participate

Login to join in on this yarn.