yossarian.net / blog.yossarian.net
https://blog.yossarian.net/2025/09/22/dear-github-no-yaml-anchors
#programming #rant
https://blog.yossarian.net/2025/09/22/dear-github-no-yaml-anchors
#programming #rant
- RubyCentral have managed this exceptionally poorly in many ways including removing literally the most active member of the RubyGems organisation by mistake who has declined to return
- RubyCentral have managed this exceptionally poorly in many ways including removing literally the most active member of the RubyGems organisation by mistake who has declined to return
https://blog.yossarian.net/2025/09/14/one-year-of-zizmor
#devblog #programming #rust #zizmor
It's got internal runtime update, housekeeping, also diagnostic messages and security improvements from @yossarian.net!
github.com/pypa/gh-acti... / github.com/pypa/gh-acti...
#python #Packaging
It's got internal runtime update, housekeeping, also diagnostic messages and security improvements from @yossarian.net!
github.com/pypa/gh-acti... / github.com/pypa/gh-acti...
#python #Packaging
securitycryptographywhatever.com/2025/08/22/s...
securitycryptographywhatever.com/2025/08/22/s...
blog.pypi.org/posts/2025-0...
blog.pypi.org/posts/2025-0...
How I think about it is as a way to deflake tests by simulating an infinitely fast processor (because time doesn’t move until all work is done), and then shorten them by compressing time (because time jumps once it moves).
📝 Release notes: https://go.dev/doc/go1.25
⬇️ Download: https://go.dev/dl/#go1.25.0
#golang
How I think about it is as a way to deflake tests by simulating an infinitely fast processor (because time doesn’t move until all work is done), and then shorten them by compressing time (because time jumps once it moves).
https://blog.yossarian.net/2025/08/14/Fun-with-finite-state-transducers
#devblog #programming #rust #zizmor
https://blog.yossarian.net/2025/08/14/Fun-with-finite-state-transducers
#devblog #programming #rust #zizmor
We think of pyx as an optimized backend for uv: it’s a package registry, but it also solves problems that go beyond the scope of a traditional "package registry".
We think of pyx as an optimized backend for uv: it’s a package registry, but it also solves problems that go beyond the scope of a traditional "package registry".
this release comes with one new audit (unsound-condition), support for auto-fixing three more finding classes, plus much more in the way of general enhancements and bug fixes.
full details here:
docs.zizmor.sh/release-note...
this release comes with one new audit (unsound-condition), support for auto-fixing three more finding classes, plus much more in the way of general enhancements and bug fixes.
full details here:
docs.zizmor.sh/release-note...
marketplace.visualstudio.com/items?itemNa...
full release notes here: docs.zizmor.sh/release-note...
marketplace.visualstudio.com/items?itemNa...
full release notes here: docs.zizmor.sh/release-note...
this is a *huge* new release: it exposes a new (experimental) auto-fix mode, more precise subspanning for fixtures, as well as a brand new pedantic audit (anonymous-definition)
read the full notes here: docs.zizmor.sh/release-note...
this is a *huge* new release: it exposes a new (experimental) auto-fix mode, more precise subspanning for fixtures, as well as a brand new pedantic audit (anonymous-definition)
read the full notes here: docs.zizmor.sh/release-note...
The Geomys Certificate Transparency logs are on their way to become the first trusted Static CT API logs! 🎉
The Geomys Certificate Transparency logs are on their way to become the first trusted Static CT API logs! 🎉
(and also thank you @mosi.bsky.social and other folks at Grafana who've been sending me patches -- the next few releases are going to have a lot of really great new features)
(and also thank you @mosi.bsky.social and other folks at Grafana who've been sending me patches -- the next few releases are going to have a lot of really great new features)
Stop using encrypted email.
www.latacora.com/blog/2020/02...
Stop using encrypted email.
www.latacora.com/blog/2020/02...
https://blog.yossarian.net/2025/06/11/github-actions-policies-dumb-bypass
#security
https://blog.yossarian.net/2025/06/11/github-actions-policies-dumb-bypass
#security
onceamaintainer.substack.com/p/once-a-mai...
onceamaintainer.substack.com/p/once-a-mai...