Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Brian Skinn

@btskinn@fosstodon.org
mastodon 4.7.3
  • Open on fosstodon.org
100 Followers
107 Following
13 Posts
Joined November 15, 2022
GitHub:
https://github.com/bskinn
Open post
Brian Skinn @btskinn@fosstodon.org
· 5mo ago

RE: @andrewnez@mastodon.social

Everyone involved with open source needs to read this. It's a deep, on-point analysis of the methodological and data source gaps in security, health, etc. evaluation of open source projects/tools.

There might not be anything most can do about it, but everyone should be aware of what they're seeing ... and, more importantly, *not* seeing ... when they look at these sorts of stats/metrics/rankings.

mastodon.social

Andrew Nesbitt: "The Mismeasure of Open Source: https://nesbitt.io…" - Mastodon

6
2
7
0
Open post
Brian Skinn @btskinn@fosstodon.org
· 5mo ago

RE: @yossarian@infosec.exchange

I never knew how much I should have been appreciating the comparative simplicity of Python on this until I was faced with the 'npm ls' and 'npm why' output from a substantial project for the first time. 😵‍💫

infosec.exchange

yossarian: "people somewhat frequently complain about Python …" - Infosec Exchange

5
1
1
0
Open post
Brian Skinn @btskinn@fosstodon.org
· 3mo ago

A feature I'd like to see on LLM chat bots is toggles for color coding the text output based on underlying per-token inference metrics.

A heatmap of prediction confidence.

The weighting of RAG sources vs pretrain data vs raw speculative generation.

A metric of extent of extrapolation vs interpolation from pretrain/RAG corpus.

I bet only the first is actually technically feasible, though, and even so probably would just make the things burn money even faster...

2
0
0
0
Open post
Brian Skinn @btskinn@fosstodon.org
· 3mo ago

RE: @distrowatch@mastodon.social

Oh, man. After all the thought and decisions I've put into my PyPI and NPM security over the last few months, just the past week or two I started wondering about vulns in Linux distro packaging systems. (Dockerhub images, too.)

Another paranoia proved justified. ☹️

mastodon.social

DistroWatch: "Today would be a good day to avoid installing new…" - Mastodon

2
1
0
0
Open post
Brian Skinn @btskinn@fosstodon.org
· 3mo ago

Has anyone else had ChatGPT referencing malicious, forged, or other bad-actor web sources in its outputs recently?

Yesterday it answered a @pydantic@fosstodon.org question with a link to the genuine Pydantic docs sitting right next to a link to a copycat forgery of the Pydantic docs at pydantic[dot]com[dot]cn. The "ads" splashed everywhere really confused me, until I looked at the address bar and realized what had happened.

1
0
0
0
Open post
Brian Skinn @btskinn@fosstodon.org
· 6mo ago

More good dev and maintainer security advice from Docker:

https://www.docker.com/blog/defending-your-software-supply-chain-what-every-engineering-team-should-do-now/

Defending Your Software Supply Chain: What Every Engineering Team Should Do Now | Docker
Docker

Defending Your Software Supply Chain: What Every Engineering Team Should Do Now | Docker

The latest supply chain attack wave is not a single incident to respond to. It is a permanent shift in the threat landscape. In this blog by the Docker CISO Mark Lechner, we share the recommended best practice we use to protect ourselves.

1
0
0
0
Open post
Brian Skinn @btskinn@fosstodon.org
· 6mo ago
Replying to
For JS, I'm pretty much exclusively using npm and npx. For local npm installs, a simple broad-spectrum approach is putting "min-release-age=3" in ~/.npmrc. User-global, and easily overridden in individual cases where very new packages are needed. As best I can tell, this covers local use of npx as well.
0
2
0
0
Open post
Brian Skinn @btskinn@fosstodon.org
· 6mo ago
Replying to
A local ~/.npmrc doesn't help in CI, though. npm ci invocations *should* be working from a package-lock.json, so they're not at issue here. npx is a major gap here, though. I think the options boil down to either duplicating the min-release-age setting in each per-repository .npmrc, or remembering to do this every time in workflows: npx --min-release-age=3 I think I prefer the /.npmrc approach, because that's fewer times I need to remember to include the option.
0
1
0
0
Open post
Brian Skinn @btskinn@fosstodon.org
· 6mo ago
Replying to
For Python, I primarily use three tools: pip, pip-tools, and uv. I'll occasionally use pipx, too. No help from me on other Python tools. pip does support configuration files: https://pip.pypa.io/en/stable/topics/configuration/#configuration-files But, the locations and names of these files are not consistent cross-platform, which makes them inconvenient to manage. So, my current preference is to use environment variables, at least on Linux and in Git Bash.
pip.pypa.io

Configuration - pip documentation v26.2.1

0
1
0
0
Open post
Brian Skinn @btskinn@fosstodon.org
· 6mo ago

RE: @btskinn@fosstodon.org

Might be interested in this, @pythonbytes@fosstodon.org - I'm interested in hearing about as many folks' approach to this as I can.

fosstodon.org
0
0
0
0
Open post
Brian Skinn @btskinn@fosstodon.org
· 2mo ago

RE: @ancoghlan@mastodon.social

I wonder if this is behind the spate of reports of AI PRs deleting CI config to make the pipelines pass.

mastodon.social

Alyssa Coghlan: "Is "bots will be bots" the new "boys will be boys…" - Mastodon

0
0
1
0
Open post
Brian Skinn @btskinn@fosstodon.org
· 3mo ago

@jscalzi@threads.net I wonder where they got the notion from ... https://www.theguardian.com/world/2026/jun/12/china-spy-turtles-spy-fish-monitor-waters-claims

theguardian.com
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 07:49:57 UTC