![](/static/253f0d9b/assets/icons/icon-96x96.png)
![](https://programming.dev/pictrs/image/8140dda6-9512-4297-ac17-d303638c90a6.png)
Usually I use glob patterns for test selection.
But I did use reges yesterday to find something else. A java security file definition.
Usually I use glob patterns for test selection.
But I did use reges yesterday to find something else. A java security file definition.
I dunno about stdx as a solution. It’s just not a big enough list.
At work we build a big java thing and we:
It’s still not enough. But it helps.
Maybe a web of trust for audited dependencies would help. This version of this repo under this hash. I could see stdx stuff being covered by the rust core folks and I’m sure some folks would pay for bigger webs. We pay employees to audit dependencies. Sharing that cost via a trusted third party or foundation or something feels eminently corporate. Maybe even possible.
Amazon is certainly interesting for open source. They’ve caused me and my friends a fair bit of trouble but they have made some real contributions. I feel like they only do it when they have to though. They are quite happy to take others work and give nothing back.
They just feel very disingenuous. Opportunistic. A bit sleezy. But some of my favorite open source hackers work there and do good work. It’s hard.
I really thought the idea was, “You like mecha? You like kids piloting mecha? This is how it’d go down.” I loved it so much. Shinji’s a broken, abused shell child. He lives with a broken human who drowns her sorrows in drink. His father is just evil. He’d have to be to let his kid pilot the mecha.
The only real father figure we ever see for shinji is a spy. Who gets killed. He’s in love with a girl that hates him. Because he’s broken. But he has no one else. Except those friends at school who I think they take away. Don’t remember. And that angel who he has to kill or something. Damn, it’s been like 25 years. I have no idea what happened. But in my memory it’s terrible. Wonderful stuff.
Is that the Mac only one?
Pre-merge code review should stop that kind of thing. I honestly haven’t seen anything like this in years.
Chrono Trigger. The Magus Fight. The music.
FF6. Magitech Factory. Also music.
Metal Gear Solid. Psycho Mantis. Late at night. Tired.
Eternal Sonata. Last Fight. Intro line.
Hades. Final boss. Extreme measures 4.
NES Tetris. Crashing.
Windows -> RedHat -> Windows -> Gentoo -> Ubuntu -> RHEL -> Ubuntu -> Debian -> Arch
Do folks still use logstash here? Filebeat and ES gets you pretty far. I’ve never been deep in ops land though.
The point of the license combination they use is to allow the enterprise version to be open and live in the same repo as everything else. Dunno if that’s what they do, but that’s why the elastic license exists.
The only surefire way is to read it all. And understand it all. That ain’t happening though. So you decide how much to do.
You should figure out how many people are landing patches and get a rough sense of why. Same for folks filing issues or talking about the project in general. Maybe you trust one of the contributors for some reason. Either way, you want to know how alive the project is.
You could land a patch.
You could spot check parts of the code.
You could run vulnerability scanners on it.
I dunno. It’s hard.
I’m not sure I’d attach any meaning to real names online. There’s a whole group of us whose online names are just things they thought were neat when they were 12. And they’ve just stuck forever. There’s lot of reasons.
But otherwise, yeah. I’ll spend ten minutes looking up someone’s online profile. Mostly for GitHub if I can find it. If someone’s commenting on public prs and seems nice that’s a big signal.
I agree. Light touch until you have a bunch of changes landed.
I was a professional open source contributor for a while. Still have the same job, but the license changed. Culture still quite similar though.
We squash. I’m not really interesting in your local journey to land the change. It’s sometimes useful during review, but after that it’s mostly the state of the main branch I care about. It’s what I need to bisect anyway.
I don’t like commits that are just references to issues. Copy the issue into the commit message so git blame
tells you something useful. Unless it’s just closing a simple big. Then the title and issue reference are plenty.
Depends on the project I imagine.
I wonder what my last commit at each job was. I’ll bet it was boring. About 10% of my commit messages are genuinely interesting.
I review a ton of code and have a bunch reviewed in turn. I don’t remember that last time I’ve had this come up. Either direction really. I guess I’m lucky. We just split naturally in similar places.
I think it’s a bad analogy because it’ll distract some people.
It just doesn’t come up all that much. Folks live without knowing they are different.
And it is on a spectrum. Some folks is nothing others are can force a few pictures if they have to but aren’t clear. I dunno.
Yeah! Like that!