Florian Apolloner
florian.apolloner.eu
Florian Apolloner
@florian.apolloner.eu
Dabbling in many things. Mostly Ops and Python stuff.
Afaik becoming a CNA will allow you to prevent such CVEs in the first place.
May 10, 2025 at 6:04 PM
So basically a "get or create"? Haki has a great article about the ups and downs of the individual approaches: hakibenita.com/postgresql-g...
How to Get or Create in PostgreSQL
And why it is so easy to get wrong...
hakibenita.com
May 10, 2025 at 5:59 PM
Certainly "as we know it". I am so sorry, I just couldn't resist.
December 9, 2024 at 4:54 PM
Thanks, that brings me to my next question: would you recommend NATS or rather not use it again (independent of Channels). It looks really great, but I don't have any experience with it yet.
November 25, 2024 at 6:21 AM
I wonder why that often happens? I think Kubernetes really seems off-putting at first due to the sheer size. Docker Swarm and Hashicorp Nomad seem so much simpler in comparison (but also offer less I guess).
November 24, 2024 at 4:05 PM
I nearly spilled my coffee 😂 Funny enough we are just working out a plan to start using k8s. I think I still hate it but one cannot deny the benefits.
November 24, 2024 at 3:43 PM
No argument on cibuildwheel which is why I was explicitly asking about stage 1 -- ie source bundling. downloadLocation might be indeed an answer but most likely means using all the security analysis you'd get otherwise
November 22, 2024 at 9:39 PM
And while I agree that a name & version is better than nothing, it is pretty much close to nothing imo. Maybe it helps someone looking at the SBOM manually but I do not have the feeling that it will help any software using that SBOM.
November 22, 2024 at 8:39 PM
But do Package URLs actually work? I mean if I embed libpq what would be the correct purl for it -- there doesn't seem to be a scheme for the actual source without having a repository (might miss something). I am trying to use purls over CPE where possible due to all the false positives with CPEs :/
November 22, 2024 at 8:38 PM
Nice post, some questions though. Stage 1: what are suitable identifies for bundled software (purl/packageUrl)? Stage 2: Even without extra dependencies like Maturin etc shouldn't the build backend inject itself as well?
November 22, 2024 at 8:13 PM
Uff, can't wait to read that. Will it have tooling advice as well? All the generators I tried till now seem to have issues one way or the other. 🙈 So I am kinda afraid of even trying to merge sboms 😂
November 22, 2024 at 6:34 AM