963 karma · joined November 3, 2010
https://github.com/android-ndk/ndk/issues/2 https://github.com/android-ndk/ndk/issues/3
Absolutely. My preference for new modules is to use both newless and "this"-less Javascript. Newless via the technique outlined in this post (or encapsulated in a module: https://github.com/Mr0grog/newless), and this-less via the module pattern (see link in post).
This is the pattern followed by D3. It's easy to follow internally, gives you true private data and methods, and (IMHO) is a nicer interface for API consumers -- no `new`, `delete`, or `bind`'s necessary.
MapBox is looking for developers and designers, an Operations Manager, and a Business Development Lead.
We're a team of 30 or so artists, developers, designers and strategists working on an open platform for maps. Our platform powers everything from apps like Foursquare, GitHub and Evernote to news stories on NPR and USAToday to simple maps on personal blogs and wedding websites. Much of our work is powered by open source and open data and we're often in touch with folks at OpenStreetMap, the US Census Bureau, USGS, and NASA.
Check out what we have been working on lately on our blog:
The best UI for Overpass is http://overpass-turbo.eu/
http://www.mapbox.com/osmdev/2013/02/26/id-architecture-part... http://www.mapbox.com/osmdev/2013/02/27/id-architecture-part... http://www.mapbox.com/osmdev/2013/02/28/id-architecture-part...
http://tech.mit.edu/V133/N26/swartz/2.html
This is indeed much delayed from his initial statement on January 22 that he hoped the report would be ready "in a few weeks."
http://tech.mit.edu/V132/N63/abelson.html
It's disappointing that it's taken this long.
Two security issues were fixed:
* RubyGems did not validate SSL certificates (the dreaded OpenSSL::SSL::VERIFY_NONE problem).
* RubyGems allowed HTTPS-to-HTTP redirects. And in fact rubygems.org did redirect gem downloads from HTTPS to HTTP (also fixed).
Either of these mean that an attacker could MITM your `gem install` or `bundle install` and give you malicious gem contents. You'd be owned when you required the gem -- possibly sooner, in fact, because gem install itself provides mechanisms for arbitrary code execution.
It's also important to note that RubyGems does not default to HTTPS. I highly recommend using `source "https://rubygems.org` in your Gemfile and the following in your ~/.gemrc:
:sources:
- https://rubygems.orgI can definitely imagine cases where the time and effort required to get company approval to sign such an agreement would outweigh the benefits of submitting a change upstream; I've been in such a position myself.
If ruby-build refuses to compile with clang, you should open an issue. I've done so for rvm: https://github.com/wayneeseguin/rvm/issues/763
If you prefer HAML, check out https://github.com/9elements/haml-coffee
http://groups.google.com/group/rubyonrails-security/browse_t...