HNHacker News
TopNewBestAskShowJobs

kdeldycke

700 karma · joined November 5, 2010

submissionscomments
kdeldycke··on AURpocalypse now: a look at the recent AUR attacks
The thing is that hook is not enough: `UpgradeSelect` only applies to `yay -Syu` so it only filters the upgrade list.

Nothing protect you from a `yay -S foo` install and its dependencies. So this is not a guarantee or enforcement of a minimum release-age.

Actually writing this reply I went ahead and pointed that out in an issue at: https://github.com/Jguer/yay/issues/2883

kdeldycke··on Package managers that package package managers
I have you covered: https://kdeldycke.github.io/meta-package-manager/install.htm...

(this is mpm, a Meta Package Manager)

kdeldycke··on Open source security at Astral
I maintain `repomatic`, a Python CLI + reusable workflows. It bakes most of the practices from this post into a drop-in setup for Python projects (uv-based, but works for others too). The goal is to make the secure default the easy default for maintainers who just want to ship packages. Also addresses a lot of GitHub Actions own shortcomings.

But thanks to the article I added a new check for the fork PR workflow approval policy.

More at: https://github.com/kdeldycke/repomatic

kdeldycke··on Show HN: Extra-Platforms, Python library to detect OS, arch, shell, CI, AI
For the moment I consider that only one agent can be active. If multiple are detected, I raise an error. That is intentional to gather more context and feedback from users. I will change this behavior as soon as someone report me a use-case.

See the implementation at: https://github.com/kdeldycke/extra-platforms/blob/ecbe740bf7...

kdeldycke··on Falsehoods programmers believe about aviation
I did: https://github.com/kdeldycke/kevin-deldycke-blog/blob/main/c...
kdeldycke··on Understanding the PURL Specification (Package URL)
I have a project called Meta Package Manager that supports pURLs, so you can:

$ mpm install pkg:npm/left-pad@1.2.3

Other commands allows you to export the SBOM of all packages installed on your machine. More info at: https://github.com/kdeldycke/meta-package-manager

kdeldycke··on Rust library for building no-boilerplate CLI apps
> My holy grail will still be landing on a good multi-layer configuration setup for Rust CLIs. Ideally CLI flags merged over top of environment variables merged over top of configuration files.

I did that for Python if you are interested: https://github.com/kdeldycke/click-extra

You create your CLI with Click as usual, then Click Extra introspects your "--parameters" to build up support for a corresponding configuration file in either TOML, YAML, JSON, INI or XML.

kdeldycke··on Engineers do not get to make startup mistakes when they build ledgers
> When I decided to write a post on ledgers, I already knew there were a few good resources out there to help me.

One that's not referenced in this article and compile all of them is: https://github.com/kdeldycke/awesome-billing#readme

kdeldycke··on Show HN: We created the most comprehensive global sales tax/VAT/GST index
Yes you're right. It is not complete and had plan to fix all that a couple of years ago but put it on the back-burner. I'm still happy to merge PRs upstream from motivated contributors! :)
kdeldycke··on Show HN: We created the most comprehensive global sales tax/VAT/GST index
They can scrap my CSV at: https://github.com/kdeldycke/vat-rates
kdeldycke··on Tantivy – full-text search engine library inspired by Apache Lucene
I ‘m using https://stork-search.net for my static website search, but it’s no longer maintained. So yeah, Tantivy would be a great candidate to replace it! :)
kdeldycke··on Ask HN: Did you encounter any leap year bugs today?
Billing. It always has to be the billing. For a list of all other edge cases, you have: https://github.com/kdeldycke/awesome-falsehood#readme
kdeldycke··on Ask HN: What are the best articles on managing people?
I compiled a list of these articles at: https://github.com/kdeldycke/awesome-engineering-team-manage...

For each one I tried to extract the key point or Tl;Dr in the description.

kdeldycke··on Microsoft is bringing Python to Excel
We were discussing about Resolver One 6 months ago at: https://news.ycombinator.com/item?id=34819682

One mystery we did not resolve (pun intended) was why it did not find its audience. Was it too early? Was data science not established enough as a field? Was it because it was not Excel (i.e. the dominant tool)?

kdeldycke··on Writing a Package Manager
Something like Meta Package Manager? https://github.com/kdeldycke/meta-package-manager
kdeldycke··on Ask HN: Could you share your personal blog here?
https://kevin.deldycke.com - Refresh in progress. A static site generated in Python thanks to Pelican, from MyST content, hosted on CloudFlare.
kdeldycke··on Why use OpenID Connect instead of plain OAuth2?
You can start with: https://github.com/kdeldycke/awesome-iam . But beware of the rabbit hole!
kdeldycke··on Everything that uses configuration files should report where they're located
If you maintain a Python CLI, you can use Click-Extra [1].

It provides a ready-to-use --config option which reports how it sources the configuration file [2]:

  $ my-cli --verbosity DEBUG subcommand
  debug: Load configuration matching ~/.config/my-cli/*.{toml,yaml,yml,json,ini,xml}
  debug: Pattern is not an URL.
  debug: Search local file system.
  debug: No configuration file found.
  (...)
It also adds an auto-magic --show-params [3] to help you see where parameters are coming from:

  $ cli --int-param1 3 --show-params
  ╭─────────────────┬─────────────────────────────────────────┬─────────────────────────────────────────┬──────┬──────────────────┬─────────┬─────────────────┬─────────────────────────────────────────────────────────┬─────────────────────────────────────────────────────────┬─────────────╮
  │ ID              │ Class                                   │ Spec.                                   │ Type │ Allowed in conf? │ Exposed │ Env. vars.      │ Default                                                 │ Value                                                   │ Source      │
  ├─────────────────┼─────────────────────────────────────────┼─────────────────────────────────────────┼──────┼──────────────────┼─────────┼─────────────────┼─────────────────────────────────────────────────────────┼─────────────────────────────────────────────────────────┼─────────────┤
  │ cli.color       │ click_extra.colorize.ColorOption        │ --color, --ansi / --no-color, --no-ansi │ bool │                 │        │ CLI_COLOR       │ True                                                    │ True                                                    │ DEFAULT     │
  │ cli.config      │ click_extra.config.ConfigOption         │ -C, --config CONFIG_PATH                │ str  │                 │        │ CLI_CONFIG      │ /home/runner/.config/cli/*.{toml,yaml,yml,json,ini,xml} │ /home/runner/.config/cli/*.{toml,yaml,yml,json,ini,xml} │ DEFAULT     │
  │ cli.help        │ click_extra.colorize.HelpOption         │ -h, --help                              │ bool │                 │        │ CLI_HELP        │ False                                                   │ False                                                   │ DEFAULT     │
  │ cli.int_param1  │ cloup._params.Option                    │ --int-param1 INTEGER                    │ int  │                 │        │ CLI_INT_PARAM1  │ 10                                                      │ 3                                                       │ COMMANDLINE │
  │ cli.int_param2  │ cloup._params.Option                    │ --int-param2 INTEGER                    │ int  │                 │        │ CLI_INT_PARAM2  │ 555                                                     │ 555                                                     │ DEFAULT     │
  │ cli.show_params │ click_extra.parameters.ShowParamsOption │ --show-params                           │ bool │                 │        │ CLI_SHOW_PARAMS │ False                                                   │ True                                                    │ COMMANDLINE │
  │ cli.time        │ click_extra.timer.TimerOption           │ --time / --no-time                      │ bool │                 │        │ CLI_TIME        │ False                                                   │ False                                                   │ DEFAULT     │
  │ cli.verbosity   │ click_extra.logging.VerbosityOption     │ -v, --verbosity LEVEL                   │ str  │                 │        │ CLI_VERBOSITY   │ WARNING                                                 │ Debug                                                   │ COMMANDLINE │
  │ cli.version     │ click_extra.version.VersionOption       │ --version                               │ bool │                 │        │ CLI_VERSION     │ False                                                   │ False                                                   │ DEFAULT     │
  ╰─────────────────┴─────────────────────────────────────────┴─────────────────────────────────────────┴──────┴──────────────────┴─────────┴─────────────────┴─────────────────────────────────────────────────────────┴─────────────────────────────────────────────────────────┴─────────────╯
[1]: https://github.com/kdeldycke/click-extra

[2]: https://kdeldycke.github.io/click-extra/config.html

[3]: https://kdeldycke.github.io/click-extra/parameters.html#show...

kdeldycke··on EU suggests breaking up Google's ad business in preliminary antitrust ruling
In a project I maintain on billing and payments[1], I had a link to Google Ads API. It was documenting how they had hard-limit budget, with notions like "capped actuals" and "monthly with rollover". The explanation was quite good so I keep it around to explain the concept, and why it was perfect for customers to avoid any surprises.

Then the URL[2] 404'd and the API disappeared. I couldn't find any references to a "BillingCap". I wondered why[3].

Now it makes sense: they got rid of budgets as you explained above. Everything's seems to be obfuscated behind a quite opaque Proposals/Deals[4] data structure now.

[1]: https://github.com/kdeldycke/awesome-billing

[2]: https://developers.google.com/ad-manager/api/reference/v2019...

[3]: https://twitter.com/kdeldycke/status/1625409998225285121

[4]: https://developers.google.com/authorized-buyers/apis/guides/...

kdeldycke··on Show HN: Trogon – An automatic TUI for command line apps
That's funny because like Trogon, I also implemented some kind of introspection for Python's Click arguments structure. But to automatically derives a configuration file instead of a TUI: https://kdeldycke.github.io/click-extra/config.html
kdeldycke··on Show HN: Skip the SSO Tax, access your user data with OSS
For those wondering what the "SSO Tax" is, it refers to the excessive pricing practiced by SaaS providers to access the SSO feature on their product.

A documented rant has made the rounds at https://sso.tax , which lists all vendors and their pricing of SSO.

kdeldycke··on Telemetry in Front-End Tools
Maybe it is time to revive https://consoledonottrack.com , an initiative to unify the convention of having one standard environment variable to opt-out of any tracking.
kdeldycke··on Launch HN: Neptyne (YC W23) – A programmable spreadsheet that runs Python
Resolve One was on my radar at the time because I was deep into building ERPs in Python.

All our clients had stacks of sedimented business rules and know-how, lying around in a mess of unreliable, unmaintained and un-versioned Excel files.

I was thinking of using Resolve One as a conduit that might be helpful to absorb all of that. A UI similar to a spreadsheet would be a clever trojan for adoption, as I could win the hearts and minds of the users that were not seeing themselves as developers. While bringing better software engineering and QA in the enterprisey world of organically grown, ad-hoc solutions.

Neptyne seems to revive that grand vision, so it would be interesting to study how and why Resolve One failed. Too soon perhaps, as the market wasn’t as big as it is today? Or maybe by the time you reach the critical point of the messy pile of Excel docs, you consent to invest into your core business and hire internal developers. I’d love to read a post-mortem of Resolve One.

kdeldycke··on TIL: You Can Stop Updating Copyright Attribution Years (2021)
Also, you can remove any "All rights reserved" notice, thanks to Nicaragua: https://en.wikipedia.org/wiki/All_rights_reserved#Obsolescen...

Just did that on my projects with a simple call to:

    find ./ -iname "*.py" -exec perl -p -i -e 's/# All Rights Reserved.*\n//sg' "{}" \;

The result: https://github.com/kdeldycke/meta-package-manager/commit/3ab...
kdeldycke··on In Praise of Alpine and APK
> I also tried having a meta-package, which has my “list of wanted packages” as dependencies, and then remove anything no required my it. Again, I needed extra scripts and complexity on top of the package manager itself.

I have something similar for my dotfiles, a list of packages, their manager and version in a TOML file: https://github.com/kdeldycke/dotfiles/blob/main/packages.tom...

I then feed this to meta-package-manager[1] to install:

    $ mpm restore ./packages.toml

[1] https://github.com/kdeldycke/meta-package-manager
kdeldycke··on Launch HN: Neptyne (YC W23) – A programmable spreadsheet that runs Python
The concept of Python-based spreadsheets was explored by Resolver One[1], a defunct proprietary desktop app that was discontinued ~10 years ago[2].

It seems a web version of the app has been published in open-source[3] but that too has been EOL.

[1] https://web.archive.org/web/20120211201410/http://www.resolv... [2] https://www.resolversystems.com [3] https://github.com/pythonanywhere/dirigible-spreadsheet

kdeldycke··on Launch HN: Lago (YC S21) – Open-source usage-based billing
> surprised if the interchange fees don't net out negative for the biller

That's worth investigating!

Now in a fictional, adversarial way, you can think of a bot exploiting this discrepancy to bankrupt a competitor: create dozens of fake accounts, consume just shy of $0.01 of resources, and have the platform pays 30x more in payment fees (public Stripe price is 30¢/transaction).

To incur a net loss of $1,000,000, you’ll have to find an antagonist ready to create 3,448,276 accounts (1_000_000 / (0.30 - 0.01)), each with their own identity and mean of payment, for a total of $34,482.76.

Fortunately this is highly impractical and will be caught real fast by your internal anti-abuse systems (you have those in place right?).

kdeldycke··on Ruff: A fast Python linter, written in Rust
If the main argument for Ruff is speed, its real advantage is the consolidation of the Python QA menagerie:

  - isort (import statement sorting)
  - pyupgrade (syntax upgrade for newer Python versions)
  - pylint (general linting)
  - pycln (remove unused imports)
  - pydocstyle (docstring syntax checks)
All of these can be replaced with a single ruff call. Ruff consolidates the rules from all these tools into a comprehensive and non-overlapping corpus. And removes the burden of having to find the right invokation order.

What's missing for ruff to be the gold standard, is to adopt features from:

  - autopep8 (wraps long comments)
  - docformatter (docstring auto-formatting)
  - black (determinism code formatting)
  - blacken-docs (applying black on Python code blocks in documentation)
kdeldycke··on Launch HN: Lago (YC S21) – Open-source usage-based billing
This book? https://www.amazon.com/Superdistribution-Objects-Property-El...

Strong vibes of the dot-com era reading the description but there's probably one or two insights there worth revisiting. Ordered! :)

kdeldycke··on Launch HN: Lago (YC S21) – Open-source usage-based billing
Small bills are cool, until it's too small.

I remember having to negotiate with Stripe the removal of their lowest limits. The quantum of unit I was billing on my cloud platform was such that you could consume just enough CPU and storage to end up with a $0.01 invoice at the end of the month.

It was impossible for Stripe to process this payment. IIRC their lowest limit was $0.50 or $0.10. I guess they had this limit in place to prevent abuse and limit fraud. As we had similar hard-coded heuristics for the same reasons.

Page 1 of 5Next →