Raimo
mastodon 4.7.3Technical Coach, worker-owner crafted. tech collective. Short feedback loops, humans over tools, XP, CI/CD & TDD and all the good stuff. Runs @coderetreat@hachyderm.io, organizes @SoCraTes_Conf@mastodon.social – DEU/ENG
Aspiring old man yelling at clouds.
🌹🏴
There are only a few more satisfying chores in my work than adding renovate to a well-tested but abandoned codebase and watching it bump dependencies one-by-one, occasionally fixing a conflict.
Yelling into the void that putting the mortar next to the bowls and the pestle with the cutlery violates the high cohesion low coupling principle
Ursula würde ja fragen, was Alexander so zu verbergen hat, dass er das IFG abschaffen möchte. Andererseits verliert Ursula auch gerne SMS. Vielleicht in Zukunft mit Chatkontrolle ja nicht, aber vermutlich schon noch irgendwie.
EDIT: MUTMAẞLICH NATÜRLICH
Azure Key Vault Elevation of Privilege Vulnerability - CVSS 10.0
yo wtf I've been allow-listing my IP for the last 6 months so you can pretend that the azure portal isn't doing elevated Backend calls in the first place and then there are people who can just do all of this unauthenticated?! 😭 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62825
In a parallel universe these two statements can coexist, but in this one, I'm sure Deutsche Bahn means the same thing but can't agree with itself. Never change DB 🫂
Very happy to see Samsonite producing a successor to the best carry-on suitcase ever produced, the X-Blade 3.0 Upright: the respark upright 55 (https://www.samsonite.de/respark-upright-55-20-exp-midnight-blue/143312-1549.html)
It's one of these products where objectively, we could've just settled on the X-Blade years ago and just give people some color options, because it has:
- a cable lock that protects all pockets
- two indestructible wheels
- indestrucible, load bearing main zipper that never gets stuck
- a landscape handle and a portrait handle
- a zipper to expand the suitcase in case you're not flying
I challenge you to show me a product that does this and more (what else could you possibly need anyway!)
Thank you Azure, of course I need the "Geheimnisbeauftragter für Schlüsseltresore" role in order to manage the keyvaults I just created. 🥔
Forgive me
For I have miscounted
The ports we need and
the ports the router got.
Lights won't work until further notice.
Granted I'm ranting about elixir a lot, but it's so much fun to work on the SoCraTes lottery monolith. Especially the modeling is so much fun and so engaging, it might be worth a session by itself.
Some musings: this will be the first time we're modeling the rooms themselves as entities, not exactly the physical room (that assignment can only happen by the hotel), but a room that can be designated for a number of occupants matching the ticket. This will make double bookings impossible, and maybe even allow us to integrate with the hotel PMS.
Or that an application translates into a ticket, which can be returned, voided, expire, etc. We will be able to create tickets for trainers, account for family joining etc.
The straw on a Capri sun, a softdrink served in a PE pouch (formerly Aluminium), that comes wrapped in foil, is made of paper. The same universe has private jets. Can I have a non-desolving straw back?
Wow, Unifi!
For once, I'm actually impressed with a proprietary system that just abstracts Linux primitives.
Working around my newly acquired cgnat with a wire guard tunnel was straightforward, zone based policies make sense too. Tracing could be better.
I could stare at the dashboard for hours, which I will do today
After a recent follow spree, my home feed seems to have tilted towards people using and talking about BSD. I have never (knowingly, consciously) used a BSD. I'm now interested. Why would I want to use a BSD flavor?
"Would you like to update?" Hell no I'd like everyone in the supply chain of software that my computer runs to rotate their keys first after the last two weeks
The trivy heist cascading worries me greatly. It shows again how quick stolen credentials can be used to infect other packages and even ecosystems. Really seems a new magnitude from the npmjs worms back then.
Basically my conclusion has to be to not run packages, for which there is no attestation that's at least 30 days old, delegating the risk to others and hoping that maintainers notice in time.
Wow I bumped trivy today (to 0.69.3 already). We have cosign and I pin releases manually, but I don't see how I would've noticed the version was poisoned (0.69.4) if I would've bumped the dependency yesterday. Scary.
I think I need to more radically rethink how to create trustworthy releases for me and how I assess trust on any third party.
If compromising software is so easy and happens so quickly, would a second factor (a second human signing the release) help? And can supply chain security stay hidden behind enterprise subscriptions?
https://labs.boostsecurity.io/articles/20-days-later-trivy-compromise-act-ii/
Less than 5 days on Unifi and they drop a CVSS 10.0 on me lol 🫠 https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b
Quite surprised (not to say shocked) that installing a specific version/digest of a flatpak seems to not be a standard use case.
this seems reckless, considering that pinning versions and dependencies and not ignorantly auto-updating seems very important these days. An I missing something?
Tailwind is breaking me. I could almost get behind the whole "use components" concept, if it wouldn't be completely unusable without auto completion because it's entirely inconsistent and unpredictable with its naming:
- font-style: italic » italic
- font-weight: bold » font-bold
- text-decoration-line: underline » underline
- white-space: normal » whitespace-normal (lol this one is just spitefully evil)
- align-items: safe center » items-center-safe
Me: "The last few weeks have been wild, we should do something with security in the future"
@krys@hachyderm.io "You misspelled wood"
Any recommendations for a German domain registrar? I ordered a .net from strato on Saturday and I'm sure there's a fax machine in the process because they have yet to register it with verisign, so I want to see if I can snatch my own domain with another provider 🤣
(A recommendation must not be another IONOS Group registrar obviously. I'd like to avoid the fax machine)
Which QWERTZ/QWERTY ergonomical keyboard do I want? Split is ok.
My most used shortcuts are speakers-off,mic-mute, F2 and switch input layout. I'm not interested in dvorak.
Without going down the rabbit hole of custom mech keyboards, the Cherry KC 4500 sounds like a good default right now.
On the off chance that my "Linux-first" Tuxedo laptop won't last (the screen flicker is fixed, but now standby just doesn't work 🫠) I would probably consider the Thinkpad T14 Gen7 Intel next, but having a FullHD screen on 14" is almost a show-stopper. There's just no alternative 😭
Litmus test for my own safety: on a scale from 1-10, how likely are you to write a Linux filesystem driver in the next 3 months?
Two magic words that make every engineer happy:
```
--> Using cache 6ae[...]
```
A boy is subway-surf-babbling about dinosaurs while watching something on the ipad and a man is trying to tell him that pigeons are the nearest descendants to dinosaurs.
If there's one video that I hope is not staged it's https://www.youtube.com/watch?v=czK16UOanR4