Coordinated Disclosure: 1-Click RCE on GNOME (CVE-2023-43641)
CVE-2023-43641 is a vulnerability in libcue, which can lead to code execution by downloading a file on GNOME.
The post Coordinated Disclosure: 1-Click RCE on GNOME (CVE-2023-43641) appeared first on The GitHub Blog. ⌘ Read more
Prompting GitHub Copilot Chat to become your personal AI assistant for accessibility
GitHub Copilot Chat can help you learn about accessibility and improve the accessibility of your code. In this blog, we share a sample foundational prompt that instructs GitHub Copilot Chat to become your personal AI assistant for accessibility.
The post [Prompting GitHub Copilot Chat to become your personal AI assistant for accessibility](https://github.blog/2023-10- … ⌘ Read more
[47°09′19″S, 126°43′19″W] Transponder still failing – switching to analog communication
@prologic@twtxt.net that would make me proud. Ill add more description and screenshots to the readme so that people can see more easily what it looks like etc. I also want to make ready packages for it, and see if I can crosscompile for windows as well.
@prologic@twtxt.net I do that now, and all that works, it’s just that I do not (currently) check it multiple times, in the test I did it completed as soon as the image was uploaded. But yeah I have to do some more with that for bigger files for sure. I’ll look into that next.
Skilling African developers through All In Africa
All In Africa is a gateway to growth, learning, and meaningful connections within the African open source ecosystem and beyond.
The post Skilling African developers through All In Africa appeared first on The GitHub Blog. ⌘ Read more
No polling yet, but that part is important as you say, I will need to implement that. Now I have the pieces I need at least :)
@prologic@twtxt.net I do similar. Though probably much more simple.. I have CGNAT and use wireguard to VMs to punch through for stuff like HTTP/SSH from external.
And for SMTP I have smart hosts on the VMs that will store anf forward to my mailbox if the connection goes down.
@prologic@twtxt.net I do similar. Though probably much more simple.. I have CGNAT and use wireguard to VMs to punch through for stuff like HTTP/SSH from external.
And for SMTP I have smart hosts on the VMs that will store anf forward to my mailbox if the connection goes down.
@prologic@twtxt.net I find the L2 mode where you have one interface and multiple hosts to be tricky. Its best if you are trying to make a full mesh style. But then all hosts need to be able to see one another.
I have had more success using point-to-point connections where there are only two ends to each interface. It means you have a ton of interfaces and udp ports. but you can share the host IP across the interfaces. Add to that a simple router proto ala OSPF or RIP and you can navigate around not having a full meshnet.
I have dozens of localnet wireguard connections and many more connections to others that use bgp for route propagation.
@prologic@twtxt.net I find the L2 mode where you have one interface and multiple hosts to be tricky. Its best if you are trying to make a full mesh style. But then all hosts need to be able to see one another.
I have had more success using point-to-point connections where there are only two ends to each interface. It means you have a ton of interfaces and udp ports. but you can share the host IP across the interfaces. Add to that a simple router proto ala OSPF or RIP and you can navigate around not having a full meshnet.
I have dozens of localnet wireguard connections and many more connections to others that use bgp for route propagation.
@prologic@twtxt.net we need to finally break away from twtxt URLs and embrace @nick@server to webfinger lookups.
@prologic@twtxt.net we need to finally break away from twtxt URLs and embrace @nick@server to webfinger lookups.
Need to share something with your smart phone?
qrcode "$(pbpaste)" | open -a Preview.app -f
Started on it tonight, got the file pick dialog to work, so now I just need to get the json stuff to work.
Run Threads on Desktop with Mac, Windows PC, Linux
Threads, the social network microblogging Twitter/X competitor launched by Meta (Facebook), is typically thought of as a mobile only experience, with users having the Threads app on their iPhone or Android device. But, if you have a Mac, Windows PC, or Linux computer, and you want to use Threads on your desktop computer, you can … Read More ⌘ Read more
@movq@www.uninformativ.de it worked yesterday, but today hes all over the place, not calming down much. We’re going to burgerking later today, so he’ll get some crate time in the car then (he always relaxes when he’s in the car).
[47°09′53″S, 126°43′16″W] Bad satellite signal – switching to analog communication
How to Stop Steam Pop-Up Ads on Launch
Steam, the popular gaming platform for Mac, Windows, and Linux, is great in that it offers a ton of really fun popular games, but it’s not without its annoyances. One of the most frustrating Steam annoyances are its popup ads on startup, or what it calls “Steam News”, that slowly launch in a new pop-up … Read More ⌘ Read more
moved my yarn to a new server.. will see if it still has the slow cache issue.
moved my yarn to a new server.. will see if it still has the slow cache issue.
@movq@www.uninformativ.de Nice! I just came home from a long walk myself. Walked through the forest, and then by the roads. Now the dog is sleeping. I like to wear him out a bit in the weekends so that we get some proper ‘time off’ in the evening etc :)
@prologic@twtxt.net - I do not want to nag about it - but did you find some way to post image through curl? (Or could you share the almost-working solution that you tried?), if you have not had time - then that’s fine too. I want to start looking into it again :)
@prologic@twtxt.net Yeah, so hard to just get along. It’s been conflict there for a long time, but still… What would it take for it to end?
Its nuts. Im a bit lost for words to be honest. Such a shock-attack, and taking civilians as hostages, shooting them, killing them, torture, kidnap kids and so on. Oooffff. Wonder what the response and aftermath will be..
Another day, another terror war breaks out. Sickening videos and images getting out of there. So glad I do not live in a shithole wartorn place to be honest, but feel bad for those who live that way. Innocent people getting murdered every day for nothing.
@prologic@twtxt.net not much planned. But tonight is family time, make nachos and see a movie together. Maybe Ill go biking with the dog to tire him out a bit, got a new place I want to go to (9km trail). :)
[47°09′34″S, 126°43′30″W] Storm recedes – back to normal work
[47°09′09″S, 126°43′04″W] Automatic systems disengaged due to thunderstorm
The XMPP Standards Foundation: The XMPP Newsletter September 2023
Welcome to the XMPP Newsletter, great to have you here again! This issue covers the month of September 2023.
Many thanks to all our readers and all contributors!
Like this newsletter, many projects and their efforts in the XMPP community are a result of people’s voluntary work. If you are happy with the services and software you may be using, please consider saying thanks or help these projects! Interested in supporting the Newsletter team? … ⌘ Read more
On my blog: Toots 🦣 from 10/02 to 10/06 https://john.colagioia.net/blog/2023/10/06/week.html #linkdump #mastodon #socialmedia #week
How to Install macOS Monterey/Ventura Updates Without Installing Sonoma
While many Mac users have already downloaded and installed MacOS Sonoma onto their Macs and are enjoying the great new features, not every Mac user wants to upgrade to Sonoma. In fact, many Mac users want to stay put with macOS Monterey, or MacOS Ventura, and not upgrade to MacOS Sonoma for now, or even … Read More ⌘ Read more
We all went to sit by the ocean tonight, was nice to sit down together and enjoy the view.
Get Over 5000 Free Icons & Symbols with SF Symbols
Apple has launched SF Symbols 5, a large collection of iconography for developers and designers to use in their apps for Apple experiences. If you’re a designer or developer, you’ll probably appreciate all the new symbols available that you can use in apps for the Apple ecosystem, whether for interface, toolbars, navigation, contextual menus, or … [Read More](https://osxdaily.com/2023/10/06/get-over-5000-free-icons-symbols-with-s … ⌘ Read more
I started working on a new scene (3D), I’ve wanted to make a short movie for a while, and I work on some of my ideas to get something started. Here is one of the scenes I made last weekend..
@prologic@twtxt.net I will stick around, after thinking about it. Im sure support for both will come. Maybe Ill check if I can make some support in snac2 for yarn, that would be a fun project. I also want to work some more on the yarn desktop client, I miss working on it, polish it and make it more feature complete, and then also make one for snac2/activitypub (or make it into a general client that supports both at the same time).
8 of the Best New Tips for iOS 17
iOS 17 includes a variety of new capabilities and features, and some in particular really stand out for iPhone. Let’s take a look at the best new features in iOS 17 and some tips to get started using the latest innovations in the world of iPhone software. From interactive widgets, to Standby Mode, new Messages … Read More ⌘ Read more
A developer’s guide to open source LLMs and generative AI
Open source generative AI projects are a great way to build new AI-powered features and apps.
The post A developer’s guide to open source LLMs and generative AI appeared first on The GitHub Blog. ⌘ Read more
Introducing a New GenAI Stack: Streamlined AI/ML Integration Made Easy
At DockerCon 2023, with partners Neo4j, LangChain, and Ollama, we announced a new GenAI Stack. We have brought together the top technologies in the generative artificial intelligence (GenAI) space to build a solution that allows developers to deploy a full GenAI stack with only a few clicks. ⌘ Read more
Erlang Solutions: Type-checking Erlang and Elixir
The BEAM community couldn’t be more varied when it comes to opinions about static type systems. For some they’re the most desired feature of other functional languages which we miss. Others shun them and choose our ecosystem exactly because, and not despite the fact that it doesn’t force the perceived overhead of types. Some others still worry whether static types could be successfully applied on the Erlang virtual machine at all.
Over the years, … ⌘ Read more
iOS 17.0.3 Released to Fix Overheating iPhone 15 Pro Problem
Apple has released iOS 17.0.3 for iPhone to address an issue where many iPhone 15 Pro users were experiencing overheating iPhones and slow performance sometimes along with rapid battery drain. The update is recommended for all iPhone users to install, even though apparently the overheating issue is limited to iPhone 15 Pro devices. While a … [Read More](https://osxdaily.com/2023/10/04/ios-17-0-3-released-to-fix-o … ⌘ Read more
How to communicate like a GitHub engineer: our principles, practices, and tools
Learn more about how we use GitHub to build GitHub, how we turned our guiding communications principles into prescriptive practices to manage our internal communications signal-to-noise ratio, and how you can contribute to the ongoing conversation.
The post [How to communicate like a GitHub engineer: our principles, practices, and tools](https://github.blog/2023-10-04-how-to-commu … ⌘ Read more
Announcing Udemy + Docker Partnership
Docker and Udemy announced a new partnership at DockerCon to give developers a clear, defined, accessible path for learning how to use Docker, best practices, advanced concepts, and everything in between. As the #1 rated online course platform (as ranked by Stack Overflow), Udemy will be the first to house Docker-accredited content and customized learning paths to provide developers with the latest training materials on how to best use Docker tools. ⌘ Read more
Announcing Docker Scout GA: Actionable Insights for the Software Supply Chain
We are excited to announce that Docker Scout General Availability (GA) now allows developers to continuously evaluate container images against a set of out-of-the-box policies, aligned with software supply chain best practices. These new capabilities also include a full suite of integrations enabling you to attain visibility from development into production. These updates strengthen Docker Scout’s position as integral to the software s … ⌘ Read more
[47°09′27″S, 126°43′22″W] Bad satellite signal – switching to analog communication
How to Install iPadOS 17 Update on iPad
Now that iPad users can update to iPadOS 17, have you done so? If not, you’re certainly not alone, as a lot of people sit on the sidelines with no particular rush to install the latest system software versions. But iPadOS 17 offers some nice improvements, like interactive widgets, FaceTime Video Voicemail, new Messages features, … Read More ⌘ Read more
Sponsors is expanding
GitHub Sponsors has partnered with Patreon. We’re also expanding to new regions.
The post Sponsors is expanding appeared first on The GitHub Blog. ⌘ Read more
3 strategies to expand your threat model and secure your supply chain
How to get the security basics right at your organization.
The post 3 strategies to expand your threat model and secure your supply chain appeared first on The GitHub Blog. ⌘ Read more
Announcing Docker AI/ML Hackathon
With the return of DockerCon, held October 4-5 in Los Angeles, we’re excited to announce the kick-off of a Docker AI/ML Hackathon. Join us at DockerCon — in-person or virtually — to learn about the latest Docker product announcements. Then, bring your innovative artificial intelligence (AI) and machine learning (ML) solutions to life in the hackathon for a chance to win cool prizes. ⌘ Read more
Announcing Docker Compose Watch GA Release
Docker Compose Watch, a tool to improve the inner loop of application development, is now generally available. We built Docker Compose Watch to smooth away these workflow papercuts. We have learned from many people using our open source Docker Compose project for local development. Now we are natively addressing common workflow friction we observe, like the use case of hot reload for frontend development. ⌘ Read more
Docker Desktop 4.24: Compose Watch, Resource Saver, and Docker Engine
With the release of Docker Desktop 4.24, we announce the official General Availability of Docker Compose Watch and Resource Saver. Combined with our new enhancements to managing Docker Engine in Docker Desktop, these updates will help you be more efficient and make your software development experience more enjoyable. ⌘ Read more
How to Install iOS 17 on iPhone
Installing iOS 17 onto your iPhone is easy to do, and you’ll gain access to the neat new features available in iOS 17. This includes everything from customizable contact cards, FaceTime Video voicemail, interactive widgets on your Home Screen, NameDrop easy contact sharing, new stickers features in Messages, new ringtones and text tones, new autocorrect … Read More ⌘ Read more
Cybersecurity spotlight on bug bounty researcher @inspector-ambitious
For this year’s Cybersecurity Awareness Month, the GitHub bug bounty team is excited to feature another spotlight on a talented security researcher who participates in the GitHub Security Bug Bounty Program—@inspector-ambitious!
The post [Cybersecurity spotlight on bug bounty researcher @inspector-ambitious](https://github.blog/2023-10-02-cybersecurity-spotlight-on-bug-bounty-researcher-inspector-a … ⌘ Read more
[47°09′20″S, 126°43′27″W] Transponder still failing – switching to analog communication
Hmm when I said “Wireguard is kind of cool” in this twt now I’m not so sure 😢 I can’t get “stable tunnels” to freak’n stay up, survive reboots, survive random disconnections, etc. This is nuts 🤦♂️
I’ll shut down this instance soon, I want to say thanks to all of you, especially @prologic@twtxt.net . It’s been fun here, but I do not spend much time here anymore - cutting down on the things I host and use \ spend time on etc.
I’ve been using activitypub more - since it’s more or less replaced ‘x’ for me, and can be reached at:
@stigatle@activitypub.stigatle.no
How to Fix “This iPhone is Open in Another Window” Error
Some iPhone users are experiencing an error message that says “This iPhone is open in another window” when attempting to sync music between their Mac and iPhone. Users may see the error message even when there is no other window open in the Music app on Mac, making this a peculiar error message that doesn’t … Read More ⌘ Read more
My September ‘23 in Review
Now September is over, and it’s time to take a brief look back at the past month. ⌘ Read more
Stuck in Big Picture Mode in Steam? Here’s How to Exit Big Picture Mode
Steam, the popular gaming platform for Mac, Windows, and Linux, has an optional Big Picture Mode that takes over the screen of their device or computer, and changes the interface quite a bit. If you’re like many Steam users, you may at some point accidentally enter into Big Picture Mode, and then wonder how to … Read More ⌘ Read more
On my blog: Toots 🦣 from 09/25 to 09/29 https://john.colagioia.net/blog/2023/09/29/week.html #linkdump #mastodon #socialmedia #week
How to Stop Getting Beta MacOS Updates in MacOS Sonoma
If you’ve already installed and updated to MacOS Sonoma, and you were previously in the beta testing programs (either public beta or developer beta), you may wish to no longer receive beta updates to your Mac. If you don’t do this, and you were previously enrolled in the MacOS Sonoma beta testing program, you will … Read More ⌘ Read more
Factorial Numbers
⌘ Read more
How to Remove iOS 17 Beta From Your iPhone & iPad
If you were part of the iOS 17 beta test or iPadOS 17 beta testing programs, and now you’re on the latest stable build (iOS 17.0.2), you may wish to remove the beta updates from your iPhone or iPad, so that you no longer receive beta updates and stay on the stable builds of system … Read More ⌘ Read more
The field near my second home… Walking here reminds me of when I walked here a year and a half ago, debating whether to accept the new job offer. It feels like an eternity ago. But it was a good decision! ⌘ Read more
Get Started with the Microcks Docker Extension for API Mocking and Testing
Read how running Microcks as a Docker extension enables developers to swiftly create, test, and iterate on APIs without leaving the Docker environment. ⌘ Read more
Erlang Solutions: Introducing Wardley Mapping to Your Business Strategy
Since it’s creation in 2005, Wardley Mapping has been embraced by UK government institutions and companies worldwide. This is thanks to its unique ability to factor both value and change into the strategising process. It’s a powerful, fascinating tool that far more organisations across the world should be implementing today to make key choices for their future growth.
Ahead of my wider Wardley Mapping st … ⌘ Read more
A better Postman alternative: Hoppscotch
I used to use Postman for both personal and work projects. It was great for making HTTP requests without having to create curl commands. But now, Postman requires a login, which I hate. I don’t understand why a login is needed for such a simple tool. ⌘ Read more
MacOS Sonoma 14.1 Beta Available to Download
Apple has issued the first beta version of MacOS Sonoma 14.1 beta to users enrolled in the beta testing program for Apple system software. The beta update arrives just a day after the final release and availability of MacOS Sonoma 14.0 became available to download and install for all Mac users. Separately, Apple has released … Read More ⌘ Read more
iOS 17.1 Beta & iPadOS 17.1 Beta Available Now
Apple has released the first beta versions of iOS 17.1 and iPadOS 17.1 for iPhone and iPad users enrolled in their respective beta testing programs. The beta builds arrive a day after iOS 17.0.2 and iPadOS 17.0.2 were released to the broader public for all users. Apple is working to bring additional features to iOS … Read More ⌘ Read more
Let’s DockerCon!
DockerCon 2023 will be hybrid — both live (in Los Angeles, California) and virtual. Our desire is to once again experience the live magic of the hallway track, the serendipitous developer-to-developer sharing of tips and tricks, and the celebration of our community’s accomplishments … all while looking forward together toward a really exciting future. And for members of our community who can’t attend in person, we hope you’ll join us virtually! ⌘ Read more
7 Best New Features in MacOS Sonoma
MacOS Sonoma includes some great new features and beautiful refinements to the Mac operating system, and if you just downloaded and installed MacOS Sonoma 14 you may be curious about what to explore with the upgraded system software version, or what is new. We’re here to help, covering the seven best new features of MacOS … Read More ⌘ Read more
How I used GitHub Copilot Chat to build a ReactJS gallery prototype
GitHub Copilot Chat can help developers create prototypes, understand code, make UI changes, troubleshoot errors, make code more accessible, and generate unit tests.
The post How I used GitHub Copilot Chat to build a ReactJS gallery prototype appeared first on The GitHub Blog. ⌘ Read more
[47°09′15″S, 126°43′41″W] Transponder still failing – switching to analog communication
Changes to How Docker Handles Personal Authentication Tokens
Docker is improving the visibility of Docker Desktop and Hub users’ personal access tokens. Specifically, we are changing how tokens are handled across sessions between the two tools. Learn more about this security improvement. ⌘ Read more
How GitHub uses GitHub Actions and Actions larger runners to build and test GitHub.com
Recently, we’ve been working to make our CI experience better by leveraging the newly released GitHub feature, Actions larger runners, to run our CI.
The post [How GitHub uses GitHub Actions and Actions larger runners to build and test GitHub.com](https://github.blog/2023-09-26-how-github-uses-github-actions-and-actions-larger-runners-to-build-and-test-github-com/ … ⌘ Read more
Your ultimate guide to the GitHub Universe ‘23 agenda
Get a sneak peek into the must-attend sessions, speakers, workshops, and GitHub certifications available at our global developer event.
The post Your ultimate guide to the GitHub Universe ‘23 agenda appeared first on The GitHub Blog. ⌘ Read more
Getting RCE in Chrome with incorrect side effect in the JIT compiler
In this post, I’ll exploit CVE-2023-3420, a type confusion in Chrome that allows remote code execution (RCE) in the renderer sandbox of Chrome by a single visit to a malicious site.
The post Getting RCE in Chrome with incorrect side effect in the JIT compiler appeared first on [The GitHub Blog](ht … ⌘ Read more
[47°09′44″S, 126°43′05″W] Bad satellite signal – switching to analog communication
Erlang Solutions: Our experts at Code BEAM Europe 2023
The biggest Erlang and Elixir Conference is coming to Berlin in October!
Are you ready for a deep dive into the world of Erlang and Elixir? Mark your calendars, because Code BEAM Europe 2023 is just around the corner.
With a lineup of industry pioneers and thought leaders, Code BEAM Europe 2023 promises to be a hub of knowledge sharing, innovation, and networking.
Erlang Solutions’ experts are working har … ⌘ Read more
Calling all teachers! Learn how to build new commands on the GitHub Classroom CLI
In this step-by-step tutorial, we’ll dive into how you can become the next open source contributor to the GitHub Classroom CLI, building commands that you can use to improve your workflow as an educator!
The post [Calling all teachers! Learn how to build new commands on the GitHub Classroom CLI](https://github.blog/2023-09-25-calling-all-teachers-learn-how-to-build-new-comma … ⌘ Read more
[47°09′10″S, 126°43′05″W] Storm recedes – back to normal work
Catching COVID-19
So far, I had been spared from COVID-19. “Had,” focusing on the past, because now it has affected me, or us, after all. We had to cut short our vacation, which I used to share little glimpses of here on the blog. We quickly went back home, wearing masks the whole time and hoping not to infect more people. ⌘ Read more
On my blog: Toots 🐘 from 09/18 to 09/22 https://john.colagioia.net/blog/2023/09/22/week.html #linkdump #mastodon #socialmedia #week
Urban Planning Opinion Progression
⌘ Read more
The GitHub Security Lab’s journey to disclosing 500 CVEs in open source projects
The GitHub Security Lab audits open source projects for security vulnerabilities and helps maintainers fix them. Recently, we passed the milestone of 500 CVEs disclosed. Let’s take a trip down memory lane with a review of some noteworthy CVEs!
The post [The GitHub Security Lab’s journey to disclosing 500 CVEs in open source projects](https://github.blog/2023-09-21-the-github-s … ⌘ Read more
Passkeys are generally available
All GitHub.com users can now register a passkey to sign in without a password.
The post Passkeys are generally available appeared first on The GitHub Blog. ⌘ Read more
GitHub Copilot Chat beta now available for all individuals
All GitHub Copilot for Individuals users now have access to GitHub Copilot Chat beta, bringing natural language-powered coding to every developer in all languages.
The post GitHub Copilot Chat beta now available for all individuals appeared first on The GitHub Blog. ⌘ Read more
How IKEA Standardizes Docker Images for Efficient Machine Learning Model Deployment
Learn the vital role Docker plays in MLOps (machine learning operations) at IKEA. We explore how Docker and Seldon-Core work together to turn a convoluted task into a streamlined, agile operation, and how you can harness real-time metrics for profound insights. ⌘ Read more
Erlang Solutions: Smart Sensors with Erlang and AtomVM: Smart cities, smart houses and manufacturing monitoring
For our first article on IoT developments at Erlang Solutions, our goal is to delve into the use of Erlang on microcontrollers, highlighting and exposing its capabilities to run efficiently on smaller devices. For our inaugural article, we have chosen to address a pressing issue faced by numerous sectors- including healthcare, r … ⌘ Read more
[47°09′20″S, 126°43′27″W] Transponder still failing – switching to analog communication
xkcd Phone Flip
⌘ Read more
How to Get Started with the Weaviate Vector Database on Docker
With Weaviate, you can build advanced LLM applications, next-level search systems, recommendation systems, and more. Discover features of the Weaviate vector database and learn how to install Weaviate on Docker using Docker Compose. ⌘ Read more
[47°09′59″S, 126°43′43″W] Bad satellite signal – switching to analog communication
Switching from Bitbucket Server and Bamboo to GitHub just got easier
Starting today, GitHub Enterprise Importer supports repository migrations from Bitbucket Server and Bitbucket Data Center, and GitHub Actions Importer offers CI/CD migrations from Bitbucket and Bamboo.
The post Switching from Bitbucket Server and Bamboo to GitHub just got easier appeared first on … ⌘ Read more
Snikket: State of Snikket 2023: Funding
As promised in our ‘State of Snikket 2023’ overview post, and teased at the end of our first update post about app development, this post in the series is about that thing most of us open-source folk love to hate… money.
We are an open-source project, and not-for-profit. Making money is not our primary goal, but like any business we have upstream expenses to pay - to compensate for the time and specialist work we need to implement the Snikket vision. To do that, we need income.
T … ⌘ Read more
Haunted House
⌘ Read more
garden: welcome PET01 to equipment/computers, also update chaos awakening act 3
The angle of the sun wasn’t perfect for this photo, but it turned out to be an unexpected highlight during our hike around Thurso today. ⌘ Read more
[47°09′48″S, 126°43′59″W] Transponder still failing – switching to analog communication