Is this for me? | Git for All

1_r/devopsish
KubeCon: Five biggest trends from the Kubernetes love fest in Amsterdam
Fossil: OCI Containers
caarlos0/xdg-open-svc: xdg-open as a service
xdg-open as a service. Contribute to caarlos0/xdg-open-svc development by creating an account on GitHub.
Sacklers Gave Millions to Institution That Advises on Opioid Policy
Even as the nation’s drug crisis mounted, the National Academies of Sciences, Engineering and Medicine continued to accept funds from some members of the Sackler family, including those involved with Purdue Pharma.
Iranian Hackers Launch Sophisticated Attacks Targeting Israel with PowerLess Backdoor
Iranian nation-state threat actor linked to new phishing attacks targeting Israel with an updated version of a backdoor called PowerLess.
Git 2.40.1 & Other Updates Due To Three New Security Vulnerabilities
Git 2.40.1 is out today due to three new security vulnerabilities being disclosed
GPT4 should be part of your toolkit
On March 24 I wrote GPT is revolutionary. On March 27 I got access to GPT4.1 Now that I’ve used it for a month, I’m firmly in the “this is the greatest thing...
BlueSky Reply-Based Social Graph by Jaz (jaz.bsky.social)
Just laid off a ton of people but found billions to keep Wall Street happy, what are we doing as a society? | Alphabet authorizes $70 billion buyback
If Google ends up spending the entire amount on buybacks, it would represent a continuation of last year's pace.
Make It Safe for Employees to Speak Up — Especially in Risky Times
In turbulent times like these, it’s natural for people to hold back and avoid taking risks at work. This can mean a reluctance to report mistakes, ask questions, offer new ideas, or challenge a plan. People, whether they’re aware of it or not, try to protect their reputations and jobs. Unfortunately, the same behaviors that feel risky to individual employees are precisely what their companies need in order to thrive in this uncertain economic climate. To solve this dilemma, we encourage leaders to adopt a “winning formula” for achieving a more psychologically safe workplace and the benefits it provides.
Silence Isn’t Consent – Terence Eden’s Blog
Regular blogging by Terence Eden.
16 of the best AI and ChatGPT content detectors compared
We tested the top detection tools for AI-generated content. Here's what they are good and bad at, plus what to expect when using them.
Amazon CodeCatalyst
Mastodon Is Doomed - Justin Garrison
ETHOS | Emerging Threat Open Sharing
ETHOS is the OT-centric, open-source platform for sharing anonymous early warning threat information.
Industrial security vendors partner to share intelligence about critical infrastructure threats
The biggest companies working in industrial cybersecurity are building an early-warning platform called ETHOS to share threat intelligence.
iOS Lockdown Mode effective against NSO zero-click exploit
Apple's Lockdown Mode has shown that it can do what it was designed to do by notifying users about an NSO exploit.
Exploit released for 9.8-severity PaperCut flaw already under attack
Code-execution flaw was patched in March but doesn't seem to be widely installed.
These are some of the most useful cli commands of macOS | Using open, pbcopy and pbpaste over SSH
I think I talked about this a couple of times before, but I usually work by SSH-ing from my mac into a Linux machine (a rather chunky one, might I add).
While it allows me to work faster when I’m not home and with a poor internet connection, it has some drawbacks too. Two of them are the lack of clipboard integration and the fact that open (or xdg-open) won’t work.
Why I'm not worried about AI causing mass unemployment
Software didn't eat the world and AI won't either.
Could LLM's replace abstractions? - by Ant Stanley
rmcan/swiftsky: An unofficial Bluesky/ATProto client in SwiftUI
Blog: Updates to the Auto-refreshing Official CVE Feed
Authors : Cailyn Edwards (Shopify), Mahé Tardy (Isovalent), Pushkar Joglekar
Since launching the Auto-refreshing Official CVE feed as an alpha
feature in the 1.25 release, we have made significant improvements and updates. We are excited to announce the release of the
beta version of the feed. This blog post will outline the feedback received, the changes made, and talk about how you can help
as we prepare to make this a stable feature in a future Kubernetes Release.
Feedback from end-users
SIG Security received some feedback from end-users:
The JSON CVE Feed did not comply
with the JSON Feed specification as its name would suggest.
The feed could also support RSS
in addition to JSON Feed format.
Some metadata could be added to indicate the freshness of
the feed overall, or specific CVEs . Another suggestion was
to indicate which Prow job recently updated the feed. See
more ideas directly on the the umbrella issue .
The feed Markdown table on the website should be ordered
from the most recent to the least recently announced CVE.
Summary of changes
In response, the SIG did a rework of the script generating the JSON feed
to comply with the JSON Feed specification from generation and add a
last_updated root field to indicate overall freshness. This redesign needed a
corresponding fix on the Kubernetes website side
for the CVE feed page to continue to work with the new format.
After that, RSS feed support
could be added transparently so that end-users can consume the feed in their
preferred format.
Overall, the redesign based on the JSON Feed specification, which this time broke
backward compatibility, will allow updates in the future to address the rest of
the issue while being more transparent and less disruptive to end-users.
Updates
Title
Issue
Status
CVE Feed: JSON feed should pass jsonfeed spec validator
kubernetes/webite#36808
closed, addressed by kubernetes/sig-security#76
CVE Feed: Add lastUpdatedAt as a metadata field
kubernetes/sig-security#72
closed, addressed by kubernetes/sig-security#76
Support RSS feeds by generating data in Atom format
kubernetes/sig-security#77
closed, addressed by kubernetes/website#39513
CVE Feed: Sort Markdown Table from most recent to least recently announced CVE
kubernetes/sig-security#73
closed, addressed by kubernetes/sig-security#76
CVE Feed: Include a timestamp field for each CVE indicating when it was last updated
kubernetes/sig-security#63
closed, addressed by kubernetes/sig-security#76
CVE Feed: Add Prow job link as a metadata field
kubernetes/sig-security#71
closed, addressed by kubernetes/sig-security#83
What's next?
In preparation to graduate the feed
to stable i.e. General Availability stage, SIG Security is still gathering feedback from end users who are using the updated beta feed.
To help us continue to improve the feed in future Kubernetes Releases please share feedback by adding a comment to
this tracking issue or
let us know on #sig-security-tooling
Kubernetes Slack channel, join Kubernetes Slack here .
SpaceX Starship explosion spread particulate matter for miles
SpaceX Starship explosion leaves researchers looking for answers about health and environmental impacts from debris and particulate emissions.
The “Earn It” Act is Back, Seeking To Scan Us All
We all have the right to have private conversations. They’re vital for free and informed self-government. When we want to have private conversations online, encryption makes it possible. Yet Congress is debating, for a third time, the EARN IT Act (S. 1207)—a bill that would threaten encryption, and instead seek to impose universal scanning of our messages, photos, and files.
The EARN IT Act invites all 50 states to regulate internet services, hoping state legislatures will follow a set of “best practices” set by a federal commission stacked with law enforcement agencies. The bill’s supporters want to wipe true end-to-end encryption from the internet, and replace it with scanning software that puts us all in a permanent criminal lineup.
ianklatzco/twitter-to-bsky: import a twitter archive into bsky
import a twitter archive into bsky. Contribute to ianklatzco/twitter-to-bsky development by creating an account on GitHub.
deleting system32\curl.exe | daniel.haxx.se
Apple’s iOS “walled garden” doesn’t break antitrust laws, appeals court affirms [Updated]
But court leaves injunction against "anti-steering" payment language in place.
Fedora 39 Looks To Boost vm.max_map_count To Help Windows Games With Steam Play
Fedora 39 this autumn is looking at boosting its vm.max_map_count default to better match the behavior of SteamOS / Steam Deck and allowing more Windows games to run out-of-the-box with Steam Play.