https://twitter.com/seldo/status/712417019686100992
https://blog.npmjs.org/post/141905368000/changes-to-npms-unp...
504 karma · joined November 15, 2021
https://twitter.com/seldo/status/712417019686100992
https://blog.npmjs.org/post/141905368000/changes-to-npms-unp...
For example, one of the first trojans was: https://en.wikipedia.org/wiki/EGABTR
I suspect this is how it played out as well. In fact, there was a lot of people on Twitter who were questioning whether the author really got suspended since he was posting to github a day or two after he posted his suspension picture.
whether or not those packages should have been affected is another discussion, but it appear it probably had more of an effect on other open source packages and perhaps the work of small mom and pop companies rather than huge corporations.
To me, this is like the left-pad incident and npm. There was a vocal minority who denounced npm for looking after the greater good, maintaining continuity and transferring the project to someone else.
In this case, since the author also deleted the project, the proper way to maintain continuity for the sponsors seems to transfer it to the new community of folks who are interested in maintaining the project. Sponsoring the old deleted project does nobody any good.
Personally, I don't see anything wrong with what OC did.
Now, all things considered, having used bgfx in various languages, I think the Orthodox C++ approach leads to quite clean code.
I would say statistical rethinking is a great way to compare and contrast different ppl impls and languages, I've been using it with Turing, which is pretty great.
this is from bgfx
I don't think time to first plot is that bad anymore.
Time to first gradient can be bad in Zygote/Flux.
The ecosystem in Julia is quite strong for MCMC libs because people do not have to lower something to C++ to develop such a library: https://discourse.julialang.org/t/mcmc-landscape/25654/
Of course, for users, they might prefer something like Turing, but I think the Julia tends to blur the differences between user and developer more so than in most other languages (for good or worse) since everything is in one language.
I think one of the nice thing about Julia's "just ahead of time" monomorphization/devirtualization is that it allows a level of dynamism that also works on GPUs/TPUs. This post and linked paper help me understand a little bit of it: https://discourse.julialang.org/t/julia-inference-lattice-vs...
Is this level of dynamism required for conventional ML? Probably not. For physics-informed ML and probabilistic languages? Probably more likely.
https://malisper.me/an-algorithm-for-passing-programming-int...
of course, it's important (for better or worse) to just grind out a representative sample until you understand most common patterns, e.g: https://seanprashad.com/leetcode-patterns/
https://alan-turing-institute.github.io/MLJ.jl/dev/about_mlj...
mathematics is partially a language (maybe one of the most universal ones), once you learn common conventions, it becomes easier.
Obviously it's no problem for human minds to learn huge numbers of symbols, just like some CJK languages with a large number of ideographs that have to be understood in context.
I do think auto-annotation, as well as other types of interactivity are great, though!
The repo, gh/npm accounts and such are just metadata and metadata of metadata, which is hosted and distributed based on the terms of service of gh/npm. The thing that matters most is what the npm project points to, since it is relied on by other packages and apps.
The only thing this guy "owns", according to the law, is the copyright for the part of the codebase he wrote. Not that it matters much since it is MIT licensed.
I believe this is akin to not driving dangerously on the road. There is obviously a social contract. This what living in a society is all about. Just because someone can do something doesn't mean we can't expect otherwise.
His work benefited from the work of many other people who also released open source software. That not only includes the packages that he released, of which he had other contributors, some of which actually wrote more of the package than he did (colors.js) as well as packages that he more or less did a direct port from (faker.rb and CPAN::faker). He also benefited from the entire npm/node ecosystem.
People have every right to be pissed.
The guy who actually wrote more of colors.js (by lines of code) than marak actually got npm to nuke the offending releases: https://github.com/Marak/colors.js/issues/317
right now they are reviewing a request to change the npm target to his repo
apps generated via create-react-app have more than 2000+ transitive dependencies.
at least that seems to be quite common in the npm/js world.
and faker.js seems to be more or less a port of a ruby library which was a port of a perl library.
which seems like very much akin to what they are doing now.
github user "DABH" actually had more lines of code than marak did: https://github.com/Marak/colors.js/graphs/contributors
npm and github both have terms of service that you agree to when you choose to distribute something over those systems. npm in particular has had a long policy of unrolling malicious changes to the registry of packages ever since left-pad.
I think it's just a matter of proliferation of these types of programs, as well as a large supply of students.
Also, the average qualification of people working in ML is probably no longer a Ph.D, like it used to be. This is arguably because deep learning techniques require less involved math to understand, and are more focused on computational methods that work well.
So the field has probably saturated. When I got involved with ML for the first time (well, really, statistical signal processing) in the mid 2000s, the field was kind of dead, and very high qualified postdocs had tough time finding jobs.
But I agree, a lot of MLE roles don't get asked such things.
I think the OP's guide is closer to interviews I've seen for phd programs.