Live data from Hacker News

Viewing profile — gred

gred

HN member
Joined
Thu, Oct 03, 2013, 1:00 AM UTC
HN karma
1,408
Public activity
357 items

About gred

No profile information was provided.

Recent public activity

  1. comment
    Comment #49214542

    Not too different from the recently-announced Rust guidelines at https://blog.rust-lang.org/inside-rust/2026/08/05/rust-langr...

  2. comment
    Comment #49061993

    There is indeed a "draft" release (I think they call it a "deployment"), but AFAIK your choice is then to either publish it or delete it. If you review it and it looks good, you pu…

  3. comment
    Comment #49050363

    Yeah, I think that's the difference. In Maven, the entire set of files which compose a release is immutable. You can't add to or remove from the set of files once you've published.…

  4. comment
    Comment #49050315

    In the Java world, Maven has a "publish" step. Published artifacts (groups of files) are immutable, so publish == finalize.

  5. comment
    Comment #48916678

    Emergent product roadmap in action.

  6. comment
    Comment #48770343

    Do you mean A&E the television channel?

  7. comment
    Comment #48741019

    [flagged]

  8. comment
    Comment #48739797

    [flagged]

  9. comment
    Comment #48738745

    > Conservative bias in the media. Depending on how you count, something like 96%, 94%, 65% or 87% of mainstream media employees lean left. Of course this matters less and less as c…

  10. comment
    Comment #48358976

    Thanks for the link. However, a 7x size differential does not fully explain a 100x security incident differential -- although I'm sure it's part of it. Some of the root causes are …

  11. comment
    Comment #48358162

    Days since last malicious packages in NPM: 0 (evergreen) Days since last malicious packages in PyPI: 30 Days since last malicious packages in Maven: 120 I'm sure this isn't 100% ac…

  12. comment
    Comment #48299961

    We're halfway there!

  13. comment
    Comment #48296733

    New PR: revert GitHub software and infrastructure to version of June 1st, 2018. New PR: disable new user signups for 6 months HR initiative: all future KPIs automatically require t…

  14. comment
  15. comment
    Comment #48199015

    > The thing keeping maven safe for now is that most people pin [...] versions Yes, and also the signing of JARs that are uploaded to the repository, and the fact that most release …

  16. comment
    Comment #48194674

    Your example of security issues in Maven is... npm guys setting up processes to auto-publish infected npm packages into the Maven Central repository? Wake me up when the daily npm …

  17. comment
    Comment #48101795

    There are npm supply chain exploits in the news every other day. I'm honestly surprised that something as decentralized as Go Modules is more reliable, but here we are. The fact th…

  18. comment
    Comment #48061144

    The future may be distributed quite unevenly here, as they say, with a divergence between a small amount of "responsible" code in systems which leverage AI defensively, and a large…

  19. comment
    Comment #47990558

    They should have had the UTF-8 guys tackle IPv6. Talk about elegant.

  20. comment
    Comment #47742891

    > run your systems outside of Spain So much for digital sovereignty :-)

  21. comment
    Comment #47708554

    Disagree with so much here. But if, in your mind, the US is turning authoritarian, this is a "cut off your nose to spite your face" move. They should be taking the fight where it m…

  22. comment
    Comment #47708105

    > they have been silenced by the platform Where do you see that? All I see is a claim that it no longer makes sense from a financial standpoint (but no comparative numbers provided…

  23. comment
    Comment #47707646

    He's saying that they have ideological concerns beyond the ideological concerns you would tend to associate with the EFF (digital privacy, open source, patent trolling, etc). I for…

  24. comment
    Comment #47676248

    > this obviously doesn't make any sense That's debatable, but it's a moot point; it's pastiche, so it doesn't have the same goals or motivations as the original. https://en.wikiped…

  25. comment
    Comment #47460688

    Three years too late, in my case. I've moved on.