Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gred
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
gred
7d ago
I'm sure somehow it's George W. Bush's fault.
2.
▲
by
gred
1mo ago
Not too different from the recently-announced Rust guidelines at https://blog.rust-lang.org/inside-rust/2026/08/05/rust-langr...
3.
▲
by
gred
2mo ago
There is indeed a "draft" release (I think they call it a "deployment"), but AFAIK your choice is then to either publish it or delete it. If you review it and it looks good, you publish it and can't change it therea
4.
▲
by
gred
2mo ago
Yeah, I think that's the difference. In Maven, the entire set of files which compose a release is immutable. You can't add to or remove from the set of files once you've published. You have to release a new version if you wan
5.
▲
by
gred
2mo ago
In the Java world, Maven has a "publish" step. Published artifacts (groups of files) are immutable, so publish == finalize.
6.
▲
by
gred
2mo ago
Emergent product roadmap in action.
7.
▲
by
gred
3mo ago
Do you mean A&E the television channel?
8.
▲
by
gred
3mo ago
> Conservative bias in the media. Depending on how you count, something like 96%, 94%, 65% or 87% of mainstream media employees lean left. Of course this matters less and less as customers tune out and their influence wanes. https:/
9.
▲
by
gred
4mo ago
Thanks for the link. However, a 7x size differential does not fully explain a 100x security incident differential -- although I'm sure it's part of it. Some of the root causes are very hard to address (e.g. a very limited standard
10.
▲
by
gred
4mo ago
Days since last malicious packages in NPM: 0 (evergreen) Days since last malicious packages in PyPI: 30 Days since last malicious packages in Maven: 120 I'm sure this isn't 100% accurate, and there are probably better metrics (ave
11.
▲
by
gred
4mo ago
We're halfway there!
12.
▲
by
gred
4mo ago
New PR: revert GitHub software and infrastructure to version of June 1st, 2018. New PR: disable new user signups for 6 months HR initiative: all future KPIs automatically require three-nines availability; all bonuses are forfeited, regardle
13.
▲
by
gred
4mo ago
> The thing keeping maven safe for now is that most people pin [...] versions Yes, and also the signing of JARs that are uploaded to the repository, and the fact that most release processes are not fully automated, and the batteries-incl
14.
▲
by
gred
4mo ago
Your example of security issues in Maven is... npm guys setting up processes to auto-publish infected npm packages into the Maven Central repository? Wake me up when the daily npm security breach headlines are typosquatting stories, not RCE
15.
▲
by
gred
4mo ago
There are npm supply chain exploits in the news every other day. I'm honestly surprised that something as decentralized as Go Modules is more reliable, but here we are. The fact that we're not seeing these stories about e.g. Maven
16.
▲
by
gred
4mo ago
The future may be distributed quite unevenly here, as they say, with a divergence between a small amount of "responsible" code in systems which leverage AI defensively, and a larger amount of vibe-coded / prompt-engineered co
17.
▲
by
gred
5mo ago
They should have had the UTF-8 guys tackle IPv6. Talk about elegant.
18.
▲
by
gred
5mo ago
> run your systems outside of Spain So much for digital sovereignty :-)
19.
▲
by
gred
5mo ago
Disagree with so much here. But if, in your mind, the US is turning authoritarian, this is a "cut off your nose to spite your face" move. They should be taking the fight where it most needs fighting. They should not be making do
20.
▲
by
gred
5mo ago
> they have been silenced by the platform Where do you see that? All I see is a claim that it no longer makes sense from a financial standpoint (but no comparative numbers provided for the other platforms they are keeping, which is sus,
21.
▲
by
gred
5mo ago
He's saying that they have ideological concerns beyond the ideological concerns you would tend to associate with the EFF (digital privacy, open source, patent trolling, etc). I for one am sad to see that this is the case. There are f
22.
▲
by
gred
5mo ago
> this obviously doesn't make any sense That's debatable, but it's a moot point; it's pastiche, so it doesn't have the same goals or motivations as the original. https://en.wikipedia.org/wiki/
23.
▲
by
gred
6mo ago
Three years too late, in my case. I've moved on.
24.
▲
by
gred
8mo ago
Madrid, Spain. It's theoretically very EV-friendly. These days I tend to rent hybrids. I don't even care if the battery actually works. They check the "green" legal checkbox which allows you to go downtown without gettin
25.
▲
by
gred
8mo ago
> Practicality beats enthusiasm for 95% of car use. About two years ago I rented an electric car for a few days. I felt like I wasted a ton of time finding a charging station, jumping through phone app hoops to get the charging process s
26.
▲
by
gred
8mo ago
> It's the Supreme Court that has expanded the powers of the President Sort of, but Congress also wrote a bunch of pretty broad, vague laws, delegating a significant amount of power to the executive via agency rulemaking, and it tur
27.
▲
by
gred
9mo ago
> AbstractCommandlineParserFactoryBeanServicePatternFactory ...Locator
28.
▲
by
gred
9mo ago
Thanks for the links. Regarding "real presence", and speaking only for myself as a Christian who doesn't believe this -- my attitude to this is similar to my attitude to disagreements on creation in 6 days vs 6 eras, disagree
29.
▲
by
gred
9mo ago
It's a little ironic to label a call to "stop adding new things" as a "new thing" itself, no?
30.
▲
by
gred
9mo ago
Many Catholics believe that Mary was born without sin (immaculate conception), never died (assumption into heaven), can advocate to Jesus for believers (intercession) and has been crowned the Queen of Heaven. This goes well beyond "adm
More ›