Reposted cathos (@cathos@merveilles.town) Post details Maintenance is more important than innovation. This xz debacle is a symptom of a system that prioritizes lots of things above maintenance. Take this as a reminder to rest, to mend things & pay attention to what needs mendin … | Continue reading


@jvt.me | 1 month ago

Week Notes 24#13

A four-day week ahead of the Easter weekend. Enjoyed attending the GitHub OSPO Advisory Board, learning about cool stuff being done at GitHub and OSPOs around the world On Thursday, went to see James Acaster in Nottingham for his Heckler's Welcome tour, which was very good! We'd … | Continue reading


@jvt.me | 1 month ago

Listened to Cup o' Go | Bikeshedding about bikeshedding, and Go Community Roundup Post details Proposals(re)accepted: add slices.Repeat functionaccepted: report use of too-new standard library symbols with go vetFrom around the communityBlog: Context-induced performance bo … | Continue reading


@jvt.me | 1 month ago

Listened to Jacob Kaplan-Moss on Compensating Open Source Maintainers (but not that way) by SustainOSS  Post details Jacob talks about the backlash against open source maintainers seeking compensation, ethical use of software, financial support for maintainers, and complexities … | Continue reading


@jvt.me | 1 month ago

Reposted Aral Balkan (@aral@mastodon.ar.al) Post details Personally, I’d rather celebrate a day about real living people than a fictitious magic zombie. | Continue reading


@jvt.me | 1 month ago

Bookmarked Optimizing SQLite for servers Post details SQLite is often misconceived as a "toy database", only good for mobile applications and embedded systems because it's default configuration is optimized for embedded use cases, so most people trying i … | Continue reading


@jvt.me | 1 month ago

Reposted Luis Villa (@luis_in_brief@social.coop) Post details Attached: 1 image This text is not something we wrote in a rush this morning to meet the moment. We've had variations on this on our site from day 1. I believed it then and I believe it now. | Continue reading


@jvt.me | 1 month ago

Reposted Mike Sheward (@SecureOwl@infosec.exchange) Post details people are saying the xz backdoor is likely the work of a nation state actor, and given that it appears to been slow rolled for a couple of years and immediately became obsolete before it was fully launched - you … | Continue reading


@jvt.me | 1 month ago

Reposted Neil Brown (@neil@mastodon.neilzone.co.uk) Post details New blogpost: _**[It is about trust, not software](https://neilzone.co.uk/2024-03-30-it-is-about-trust-not-software.html)**_ My reflections on the `xz` situation. > This isn't about software, it's about tr … | Continue reading


@jvt.me | 1 month ago

Reposted Aaron Patterson ✅ (@tenderlove@mastodon.social) Post details "open source needs more funding!" *nation state pays for backdoor* "not like that!" | Continue reading


@jvt.me | 1 month ago

Listened to SoCal Linux Expo with SCaLE attendees (Ship It! #97) Post details Justin & Autumn take you with them to the 2024 SoCal Linux Expo where they asked six fellow attendees about their favorite open source projects and their least favorite commands. | Continue reading


@jvt.me | 1 month ago

What can we learn about the backdooring of `xz`/`liblzma`, using OpenSSF Security Scorecards and dependency-management-data?

CVE-2024-3094 This evening, it was announced by Andres Freund that there is backdoored code in xz and liblzma: I accidentally found a security issue while benchmarking postgres changes. If you run debian testing, unstable or some other more "bleeding edge" distribution, I strongl … | Continue reading


@jvt.me | 1 month ago

Reposted The Seven Voyages Of Steve (@sinbad@mastodon.gamedev.place) Post details I feel like subscriptions have generally made software quality worse. There was an argument that having to make paid upgrades to generate revenue to pay salaries put pressure on companies to change … | Continue reading


@jvt.me | 1 month ago

Reposted Eloy (@eloy@hsnl.social) Post details @noracodes@tenforward.social IMHO you should pay for open source if you are making a profit on it. Lots of companies are reselling proprietary software and are paying for licenses without having specific feature wishes for the softwa … | Continue reading


@jvt.me | 1 month ago

Reposted https://hsnl.social/@eloy/112162763329458659# . | Continue reading


@jvt.me | 1 month ago

Reposted Forrest Brazeal (@forrestbrazeal@hachyderm.io) Post details "Vendor lock-in"? They wish. All these vendors are locked in here with ME. | Continue reading


@jvt.me | 1 month ago

Listened to Questions from a new Go developer (Go Time #308) Post details In this episode we answer any/all questions from a new Go developer. Features, best practices, quirks of the language… it’s all on the table for discussion. | Continue reading


@jvt.me | 1 month ago

Listened to Cup o' Go | 🚫 Computer says "No" 🧝 Plus one shell to rule them all with xiaq Post details 🇮🇹 GoLab 2024 coming up Nov 11-13 in Florence ItallyCFP open through May 1Proposals🚫 Declined: time.Parse: letter-based formats🚫 D … | Continue reading


@jvt.me | 1 month ago

Week Notes 24#12

A last day in Rome, travel home, and then back to work. On Monday, Anna had booked a pasta + tiramisu making course with my parents, which was a lot of fun, and a lot of work 😅 Was interesting to see just how much work a single portion of fresh pasta (ravioli and fettucci … | Continue reading


@jvt.me | 1 month ago

Week Notes 24#11

A lovely first week in Florence and Rome - ahead of my 30th birthday on Sunday: A very early flight (waking up at 0400 😵 - and glad we had a good buffer as the roads + satnav were a little confusing - but glad to have arrived in Rome in good time, and able to take the tra … | Continue reading


@jvt.me | 1 month ago

Listened to Productivity engineering at Netflix with Andy Glover, CTO at ReadySet (Ship It! #96) Post details What’s the difference between productivity engineering and platform engineering? How can you continue to re-platform with a moving target? On this episode, we’re joined b … | Continue reading


@jvt.me | 1 month ago

Listened to Navigating Node.js Security: A Conversation with Matteo Collina by Schalk Neethling Post details In a riveting episode of the Mechanical Ink podcast, host Schalk Neethling welcomed Matteo Collina, a luminary in the Node.js community whose work has amassed over 22 bill … | Continue reading


@jvt.me | 1 month ago

Reposted Souvlaki Space Station 🛸 (@anarchiv@todon.nl) Post details Can web designers PLEASE STOP with the thing where the bulk of the website loads first and then things on the top load last so you invariable end up clicking on something you didn't mean to | Continue reading


@jvt.me | 1 month ago

Listened to The Oban Pros with Shannon & Parker Selbert (Changelog & Friends #35) Post details Today you get Sorentwo for the price of one! We are joined by Shannon & Parker Selbert, both halves of the mom-and-pop software shop behind Oban, the robust job processi … | Continue reading


@jvt.me | 1 month ago

Reposted JimmyB (he/him) (@JimmyB@mas.to) Post details @aral@mastodon.ar.al My little lad had a bad leukaemia when he was 20 months - in 2002. He had care at Great Ormond St - I calculated at the time (I’m an accountant) at somewhere between £250k and £500k, entirely free to us. … | Continue reading


@jvt.me | 1 month ago

Reposted Scott Williams 🐧 (@vwbusguy@mastodon.online) Post details Source Available != Open Source That's not an opinion. If it's SSPL, BUSL, etc., it's categorically not "open source" according to the Open Source Definition. | Continue reading


@jvt.me | 1 month ago

Reposted Baldur Bjarnason (@baldur@toot.cafe) Post details I’ll let you in on a secret: I love sporadically updated weblogs. I subscribe to over 1200 feeds and most of them are sporadic or even technically “inactive”. Months often pass between updates It means that every post pub … | Continue reading


@jvt.me | 1 month ago

Reposted Waldo Jaquith (@waldoj@mastodon.social) Post details $1 million budget: 90% test coverage, comprehensive DevOps pipeline, all work rooted in user research, delivery every two weeks, all code in an open repo. $300 million budget: No tests, no CI/CD, no user research, deli … | Continue reading


@jvt.me | 1 month ago

Reposted TC 💖 (@talia_christine@beige.party) Post details Attached: 1 image | Continue reading


@jvt.me | 1 month ago

Listened to Cup o' Go | What makes a first-class Go port? Plus 👸 OpenAPI tools fit for a princess, with quobix Post details 🇬🇧 Manchester Go Meetup, April 3Proposals🕛 Declined: time: add "1136214245" as layout string for unix timestamp💪 Act … | Continue reading


@jvt.me | 1 month ago

Listened to Containers on a diet with Kyle Quest (Ship It! #95) Post details Kyle Quest joins the show to tell Autumn & Justin all about the evolution of DockerSlim & minimal container images. Why are small container images important? What are different strategies … | Continue reading


@jvt.me | 1 month ago

Reposted Miah Johnson (@miah@hachyderm.io) Post details Remember folks. When VC is funding Corporation that releases a Open Source project its only a matter of time until they take it back. Their goal is to get their product embedded into your organization and abuse you for free … | Continue reading


@jvt.me | 1 month ago

Reposted Simon Willison (@simon@simonwillison.net) Post details Attached: 1 image @msw@mstdn.social Urgh what a miserable diff | Continue reading


@jvt.me | 1 month ago

Reposted Dan Gillmor (@dangillmor@mastodon.social) Post details If you're using Glassdoor, stop right now and delete your account. This company just made it completely clear it can't be trusted. Read this from @arstechnica https://arstechnica.com/tech-policy/2024/03/glassdoor-add … | Continue reading


@jvt.me | 1 month ago

Reposted a post on gregorlove.com by gRegor Morrill Post details It’s Long COVID Awareness Day. An estimated 65 million people suffer from it globally. Remember that the risk of long-term health issues in multiple organs increases after each infection, even if your … | Continue reading


@jvt.me | 1 month ago

Listened to The Business of Open Source | From Project to Profit with Heather Meeker Post details This week on The Business of Open Source I talked to Heather Meeker, General Partner of OSS Capital and author of From Project to Profit, How to Build a Business around your Open Sou … | Continue reading


@jvt.me | 1 month ago

Very excited to be speaking at the @TheLeadDev webinar Does your org need platform engineering? in a few weeks! Hope to share some of my experiences with #PlatformEngineering and #DeveloperExperience | Continue reading


@jvt.me | 1 month ago

I will be attending Does your org need platform engineering? Post details | Continue reading


@jvt.me | 1 month ago

I will be attending SustainOSS: Foundations and Fiscal Hosting for Open Source Communities Post details Join Shane Curcuru (fossfoundation.info) and Lauren Gardner (Open Source Collective) to talk about the state of fiscal hosting for FOSS! | Continue reading


@jvt.me | 1 month ago

Reposted Sara Safavi (@sara@hachyderm.io) Post details Attached: 1 image Ok I’m doin the thread I said I wanted to do last week. (feel free to mute unless you enjoy a little second-hand drama as a Monday morning treat) Attn #devrel people! Are you job hunting? Does this pic of se … | Continue reading


@jvt.me | 1 month ago

Reposted aburka 🫣 (@aburka@hachyderm.io) Post details Hot take: if I can say "they just tested positive" and you don't have to ask "for what?" then the pandemic isn't over. | Continue reading


@jvt.me | 1 month ago

Reposted Dgar (@dgar@aus.social) Post details Attached: 1 image | Continue reading


@jvt.me | 1 month ago

Reposted fabriek (@fabriek@octodon.social) Post details Attached: 1 image Putting framed quotes meant for the kitchen in the bathroom. | Continue reading


@jvt.me | 1 month ago

I may be attending Cultivating Collaboration: Unveiling Cultural Dynamics in Remote DevOps Teams, Tue, Mar 26, 2024, 6:30 PM | Meetup Post details **The Talk;** In an era where technology connects global teams seamlessly, the cultural aspects of DevOps play a pivotal role in dete … | Continue reading


@jvt.me | 1 month ago

Bookmarked So you've been reorg'd... - Jacob Kaplan-Moss Post details I’ve been through close to a dozen reorgs. This article contains the advice I wish I’d been given earlier in my career when I didn’t yet have that experience. Reorgs are disruptive, and nobody really tells you … | Continue reading


@jvt.me | 1 month ago

No #WeekNotes tonight as I'm celebrating my 30th birthday in Rome 🎂🥂🍝🍷 If you wanted to do something nice to honour it, you could support my work on the Open Source projects I maintain as well as the content on my blog. But I'd also love to see y'a … | Continue reading


@jvt.me | 1 month ago

Reposted Schalk Neethling (@schalkneethling@hachyderm.io) Post details Radical salary transparency FTW? https://youtu.be/Bzmu5bcR3HQ?si=xcfkyVopAxahSMdh via @changelog@changelog.social @www.jvt.me@www.jvt.me | Continue reading


@jvt.me | 1 month ago

Reposted https://www.youtube.com/watch?v=Bzmu5bcR3HQ . | Continue reading


@jvt.me | 1 month ago