Post details
@www.jvt.me@www.jvt.me someone said there was an unattended bag, so probably just precautions to search it by pyrotechnics.
Post details
Attached: 1 image On my way home from Open Source Summit EU in Prague. So much global cyber policy! If the attendance at sessions and workshops is any measure, CRA and how it impacts the open source ecosystem has become a very hot topic. Guides available at https://policy.openssf.org and free training available here https://openssf.org/tag/cra-training-course/ by the way.

Post details
The many police cars and red tapes both inside and outside, and the alternative exit path was a nice touch to end the conference though.
We don't have any details as to what happened, do we? (their email understandably doesn't share much)
Post details
See how Chainguard built forkstore to securely manage public CVE fixes and embargoed Athena patches on the same open source packages.

Post details
Secure GitHub Actions beyond SHA pinning. Chainguard Actions is now GA with 1,000+ hardened, continuously verified drop-in replacements.

Post details
Finding a zero-day is only the start. Learn how Athena determines which software versions are affected and what fixes customers should deploy.

Logs as UX (12 mins read).
Looking at how logs being the main interface for understanding how tools work can be a blessing and a curse.
Between and I took 12963 steps.
Post details
I'm about to get on a plane and will be gone for a couple weeks, but didn't want to leave you Breaking Changeless so I did the thing where I stand up in front…

Bah that's even easier thanks! Will update + give you a credit 💜
Minifying JSON with jq (1 mins read).
How to take a pretty-printed JSON string and replace it with a minifed JSON string using jq.
Between and I took 7603 steps.
Gotcha: GitHub Custom Properties are public (2 mins read).

A known documented, but maybe lesser known, fact about GitHub Custom Properties' values and descriptions being available to anyone with read access.
Post details
Zach Holman, founder of Signed, joins me for another 🔥Hotfix🔥. Zach wants more of everything. Let's see what we can do about that. Write into the show at…

Between and I took 7239 steps.
Between and I took 9436 steps.
Post details
Episode 10 of Infrastructure Frontiers with Seth Falcon. Industry Experts run down all the AI news. Adam Jacob, Paul Stack, and Nick Stinemates are joined…

Post details
Had a physical today and took a depression test, and two of the questions were, over the last two weeks how many days have you: - felt tired - had trouble concentrating WHO IS PASSING THESE?? Who is not feeling like this all the time?
Post details
these are words trans women would use to insult each other
Post details
How Did This Get Made? · Episode
Post details
How Did This Get Made? · Episode
Post details
How Did This Get Made? · Episode
Post details
How Did This Get Made? · Episode
Post details
The HDTGM crew are LIVE from the Beacon Theatre in New York to break down the 1973 tale of a rebellious young seagull who just wants to fly fast and ends up... in outer space?!

Post details
Josh chats with Jeff Matchett from Cloudsmith about a new report they put out. It has some scary looking statistics in it about how organizations are using dependencies. There are some surprising numbers in there, but the story is really one of defense in depth. There's no single thing we can do here, it's all about knowing what you have every step of the way. It's easy to say, but certainly a challenge to do right. James is a ton of fun to chat with and filled with energy and knowledge. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-10-james-cloudsmith
Post details
Nick Kroll (Oh, Hello on Broadway, The House) returns to join Paul, June, and Jason to discuss the 1994 Jean-Claude Van Damme movie Timecop.

Between and I took 7946 steps.
Post details
How Did This Get Made? · Episode
Post details
Short version: Adding the rel=canonical URL in your web pages is important for more than just search results. It can also impact link previews in other Google products like Docs. I recently ran into a …(https://gregorlove.com/2026/10/canonical-links-in-google-products/)
Post details
HDTGM All-star Nick Kroll (Big Mouth) joins Paul, June, and Jason to discuss the 2019 neo-noir thriller Serenity. Recorded live from Austin City Limits at the Moody Theater, they talk about the big twist that comes way too early, McConaughey being so wet in the movie, the sex scene on the boat, and more. This episode is brought to you by Squarespace (www.squarespace.com/BONKERS), CNN original series: The Movies, Simplisafe (www.simplisafe.com/bonkers), and Allbirds (www.allbirds.com). Subscribe to Unspooled with Paul Scheer and Amy Nicholson here: http://www.earwolf.com/show/unspooled/ Check out our tour dates over at www.hdtgminfo.com! Check out new HDTGM merch over at https://www.teepubli…wdidthisgetmade Where to Find Jason, June & Paul: @PaulScheer on Instagram & Twitter @Junediane on IG and @MsJuneDiane on Twitter

Week Notes 26#40 (2 mins read).
What happened in the week of 2026-09-28?
Post details
Automatic dependency update PR-raising tooling! We actually introduced Renovate recently in our azure devops CICD pipeline setup and it works pretty well. For years we didn’t have a dependabot- like solution and I am glad that we now have Renovate to cover that gap! [contains quote post or other embedded content]
Post details
How Did This Get Made? · Episode
Post details
Between and I took 13435 steps.
Post details
Closed That Tab is back. Erika finally read Richard Cook's How Complex Systems Fail, an 18 point paper Cook wrote with patient safety and medical systems in mind, but one that is frequently discussed in web development and software engineering since the foundational principles apply universally. Erika and Bethany work through what holds up in practice.They cover the difference between normal failure and catastrophic failure, why knowing your system's baseline is its own skill, and why fixes are never free: every change adds complexity, knowledge gaps, and new risk. They get into safety as a set of defensive actions, including rate limiting, caching, rollback plans, feature flags, backups, playbooks, and watching for drift. Then they take on Cook's most contested claim, that root cause analysis is fundamentally wrong for complex systems, and where they agree and disagree. Bethany makes the case that incident reviews are still one of the best learning tools available, as long as psychological safety comes first.The conversation also digs into hindsight bias and self-blame, the difference between taking accountability and taking blame, practitioners as both the risk and the defense in a system, why training and safety work are chronically undervalued, where AI helps during an incident and where you still need a human expert, practicing failure through game days and shadowing, and keeping on-call sustainable so you do not burn out the people holding the pager.HostsOvercommitted: https://overcommitted.devBethany Janos: https://www.trustyduck.devErika Eggemeyer: https://github.com/eggyheadLinksHow Complex Systems Fail by Richard Cook: https://www.adaptivecapacitylabs.com/HowComplexSystemsFail.pdfThinking In Systems: https://www.chelseagreen.com/product/thinking-in-systems/

You're currently viewing page 1 of 908, of 45386 posts.