A sync process syncs the open disk files once every config.syncInterval. Sync also can be done on every request if config.alwaysFsync is True.
107 karma · joined May 19, 2021
A sync process syncs the open disk files once every config.syncInterval. Sync also can be done on every request if config.alwaysFsync is True.
I was so excited because this was exactly what I coded up today, I jumped straight to the comments.
I used ollama to build this and ollama supports tool calling natively, by passing a `tools=[...]` in the Python SDK. The tools can be regular Python functions with docstrings that describe the tool use. The SDK handles converting the docstrings into a format the LLM can recognize, so my tool's code documentation becomes the model's source of truth. I can also include usage examples right in the docstring to guide the LLM to work closely with all my available tools. No system prompt needed!
Moreover, I wrote all my tools in a separate module, and just use `inspect.getmembers` to construct the `tools` list that i pass to Ollama. So when I need to write a new tool, I just write another function in the tools module and it Just Works™
Paired with qwen 32b running locally, i was fairly satisfied with the output.
I might be wrong, so do correct me if so.
This is how all major players in the market recommend you set up your CI pipeline. The problem here lies in implicit trust of the pipeline configuration which is stored along with the code.
Other exploits might need more targeted steps to achieve. For example, embedding a malware into the source code might require language / framework fingerprinting.
This seems to be automatically mitigated in systems which might have a "build" / "compilation" phase, because for the application to work in the first place, you only need the compiled output to be deployed. For instance, Apache Tomcat.
God knows what other bugs their software has.
Anyways, you could also block all traffic to ngrok servers just to ensure your Dev teams aren't skirting around your firewall.
Fair use is only allowed if the work you're doing is purely for the greater good. I might be wrong though, IANAL.
The same could be said for all the other Secret Scanning partners GitHub has, like AWS and so on.
That being said, it's impossible that a "bad regexp" is gonna make its way to the GitHub codebase.
Now you're talking about phishing sites.
Can you clarify which kind of websites you're referring to?
I managed to fix three thousand code smells on a very badly written codebase in a span on two days. Thanks IntelliJ IDEA!
There's also hub, from GitHub. I find myself using "hub sync" to update all my local branches at once.
How would NeuralHash pick a "hidden image"? It only uses the pixels of the image to get the hash. Any hidden image in the metadata would not even be picked up and no amount of steganography can fool NeuralHash.
> There is many vectors. For example you can leave phone unattended and someone can snap a picture of an image or since a collision may look innocent to you, you would overlook it in an email etc...
As iterated elsewhere in this thread, random gibberish pixels colliding with CSAM would definitely not be useful in incriminating anyone. The manual process would catch that. Also, if the manual process is overloaded, I'm pretty sure basic object recognition can filter out most of the colliding gibberish .