634 karma · joined January 2, 2011
I do, regularly! In a repository where care has been taken, it can be super valuable when tracking down a bug or regression, and understanding the intent of the author
The PDF format is versioned, and in the past new versions have introduced things like new types of encryption. It’s quite probable that a v1.7 compliant PDF won’t open on a reader app written when v1.3 was the latest standard.
The website is quite extensive, but the gem only has ~1.5k downloads. It’s presumably very early on the adoption curve
The public docs site was managed and deployed via a private GitHub repository, and we had a public GitHub repo that mirrored it.
The link between them was an action on the private repo that pushed each new man commit to the mirror. Customer PRs on the public mirror would be merged into the private repo, auto synced to the mirror, and GH would mark the public PR as merged when it noticed the PR commits were all on main.
It was a bit of a headache, but worked well enough once stag involved in docs built up some workflow conventions. The driver for the setup was the docs writers want the option to develop pre-release docs discretely, but customer contributions were also valued.
I don't think the post mortem details whether the root access was on the org management account or an org member account.
Our power is very reliable and rarely goes out. Every few years a car hits a pole or something and we get a brief period of quiet time
On paper it’s awkward, but in reality convention and social norms make it rarely an issue.
The global namespace only supporting exactly one version of each gem encourages a health culture of stable ABIs and deprecation periods too. An absolute dream compared to some language ecosystems
It seems like it'd be useful in some cases, particularly because connection pooling to postgres is managed for you.
Is anyone using it production workloads? How have you found it?
Bummer that it can only query the writer and not readers.
None of our systems require perfect ordering of IDs generated across our distributed system. Most of the system was built with random UUIDv4 identifiers so no code assumes the ID ordering is significant.
However, in much of our system recent data is frequently accessed while old data is rarely accessed. In that world, just having the IDs *approximately* clustered in creation order has been a huge performance boost for many queries, and we've seen significant reduction in postgres Write Ahead Log rates, because writes to UID indexes happen in a smaller number of pages.
Maybe if we were starting from scratch ULIDs would have been an option, but given where we were UUIDv7 was a much easier transition.
No regrets, I learnt a lot and had fun messing with it for a while.
That way org admins can see the requested permissions and control exactly which repos are permitted. GitHub OAuth apps are an absolute nightmare to audit or control.
There's no JVM (or log4j) in our environment, but we received this notification listing 6 instance IDs as having done DNS lookups to suspect domains.
No trace of those instance IDs in our account over the past few weeks, and after following up with a ticket we were told they're actually the instance IDs that sit underneath some fargate tasks (no info on what tasks or ECS service of course, because that would be sensible).
We've rechecked the bits of our stack that run on Fargate and confirmed there's definitely no JVM, so we figure it must be a false positive. Maybe DNS lookups to customer controlled hostnames (which we support as part of a feature, and sandbox carefully).
Some progress updates are being posted to twitter: https://twitter.com/debian
It'd been parked for an hour or two, and the trigger was something electrical in the engine cavity.
> nothing to see here
> Cryptocurrency start-up Coinbase recently sought to restrict political speech by employees, a move many interpreted as a shift to the right because it came in reaction to internal discussions of Black Lives Matter.
That makes it sound like the Coinbase thing is less about the company holding a public political position, and more of a "leave your politics at home" thing.
Sounds like the corporate version of the recurring debate about whether open source projects should reject contributions from those with objectionable political views.
What does are some concrete examples of a company being political or apolitical? What are the kinds of things the Coinbase used to do and no longer does, which employees might leave over? Is it about the company donating to political compaigns, or openly participating in community debates and having a position on social issues (same sex marriage, abortion, Black Lives Matter, Trump, gun control, etc)?