Viewing profile — gred
gred
HN member- Joined
- Thu, Oct 03, 2013, 1:00 AM UTC
- HN karma
- 1,408
- Public activity
- 357 items
- HN profile
- View on Hacker News ↗
About gred
No profile information was provided.
Recent public activity
-
comment
Comment #49214542
Not too different from the recently-announced Rust guidelines at https://blog.rust-lang.org/inside-rust/2026/08/05/rust-langr...
-
comment
Comment #49061993
There is indeed a "draft" release (I think they call it a "deployment"), but AFAIK your choice is then to either publish it or delete it. If you review it and it looks good, you pu…
-
comment
Comment #49050363
Yeah, I think that's the difference. In Maven, the entire set of files which compose a release is immutable. You can't add to or remove from the set of files once you've published.…
-
comment
Comment #49050315
In the Java world, Maven has a "publish" step. Published artifacts (groups of files) are immutable, so publish == finalize.
-
comment
Comment #48916678
Emergent product roadmap in action.
-
comment
Comment #48770343
Do you mean A&E the television channel?
-
comment
Comment #48741019
[flagged]
-
comment
Comment #48739797
[flagged]
-
comment
Comment #48738745
> Conservative bias in the media. Depending on how you count, something like 96%, 94%, 65% or 87% of mainstream media employees lean left. Of course this matters less and less as c…
-
comment
Comment #48358976
Thanks for the link. However, a 7x size differential does not fully explain a 100x security incident differential -- although I'm sure it's part of it. Some of the root causes are …
-
comment
Comment #48358162
Days since last malicious packages in NPM: 0 (evergreen) Days since last malicious packages in PyPI: 30 Days since last malicious packages in Maven: 120 I'm sure this isn't 100% ac…
-
comment
Comment #48299961
We're halfway there!
-
comment
Comment #48296733
New PR: revert GitHub software and infrastructure to version of June 1st, 2018. New PR: disable new user signups for 6 months HR initiative: all future KPIs automatically require t…
-
comment
Comment #48278380
[dead]
-
comment
Comment #48199015
> The thing keeping maven safe for now is that most people pin [...] versions Yes, and also the signing of JARs that are uploaded to the repository, and the fact that most release …
-
comment
Comment #48194674
Your example of security issues in Maven is... npm guys setting up processes to auto-publish infected npm packages into the Maven Central repository? Wake me up when the daily npm …
-
comment
Comment #48101795
There are npm supply chain exploits in the news every other day. I'm honestly surprised that something as decentralized as Go Modules is more reliable, but here we are. The fact th…
-
comment
Comment #48061144
The future may be distributed quite unevenly here, as they say, with a divergence between a small amount of "responsible" code in systems which leverage AI defensively, and a large…
-
comment
Comment #47990558
They should have had the UTF-8 guys tackle IPv6. Talk about elegant.
-
comment
Comment #47742891
> run your systems outside of Spain So much for digital sovereignty :-)
-
comment
Comment #47708554
Disagree with so much here. But if, in your mind, the US is turning authoritarian, this is a "cut off your nose to spite your face" move. They should be taking the fight where it m…
-
comment
Comment #47708105
> they have been silenced by the platform Where do you see that? All I see is a claim that it no longer makes sense from a financial standpoint (but no comparative numbers provided…
-
comment
Comment #47707646
He's saying that they have ideological concerns beyond the ideological concerns you would tend to associate with the EFF (digital privacy, open source, patent trolling, etc). I for…
-
comment
Comment #47676248
> this obviously doesn't make any sense That's debatable, but it's a moot point; it's pastiche, so it doesn't have the same goals or motivations as the original. https://en.wikiped…
-
comment
Comment #47460688
Three years too late, in my case. I've moved on.