snabelen.no is one of the many independent Mastodon servers you can use to participate in the fediverse.
Ein norsk heimstad for den desentraliserte mikroblogge-plattformen.

Administrert av:

Serverstatistikk:

449
aktive brukere

#dependencies

0 innlegg0 deltakere0 innlegg i dag
Karl Voit :emacs: :orgmode:<p><a href="https://graz.social/tags/Python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python</span></a>: Malicious <a href="https://graz.social/tags/PyPI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PyPI</span></a> Packages Stole <a href="https://graz.social/tags/Cloud" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cloud</span></a> <a href="https://graz.social/tags/Tokens" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tokens</span></a>—Over 14,100 Downloads Before Removal<br><a href="https://thehackernews.com/2025/03/malicious-pypi-packages-stole-cloud.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">thehackernews.com/2025/03/mali</span><span class="invisible">cious-pypi-packages-stole-cloud.html</span></a></p><p><a href="https://graz.social/tags/complexity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>complexity</span></a> <a href="https://graz.social/tags/dependencies" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependencies</span></a> <a href="https://graz.social/tags/programming" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>programming</span></a> <a href="https://graz.social/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a> <a href="https://graz.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a></p>
Peter N. M. Hansteen<p>No Project Is an Island: Why You Need SBOMs and Dependency Management <a href="https://nxdomain.no/~peter/no_project_is_an_island.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">nxdomain.no/~peter/no_project_</span><span class="invisible">is_an_island.html</span></a> <a href="https://mastodon.social/tags/sbom" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sbom</span></a> <a href="https://mastodon.social/tags/development" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>development</span></a> <a href="https://mastodon.social/tags/dependencies" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependencies</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/cves" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cves</span></a> The system you develop and maintain does not exist in isolation. Providing SBOMs for our work is our way to show we care.</p>
alexanderadam<p>Very cool:</p><p>if you're using <a href="https://ruby.social/tags/vscode" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vscode</span></a> and you program in :ruby: <span class="h-card" translate="no"><a href="https://ruby.social/@ruby" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ruby</span></a></span>, 💎 <span class="h-card" translate="no"><a href="https://fosstodon.org/@CrystalLanguage" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>CrystalLanguage</span></a></span> or 🐍 <span class="h-card" translate="no"><a href="https://techhub.social/@Python" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Python</span></a></span>, then you might want to use <span class="h-card" translate="no"><a href="https://ruby.social/@ninoseki" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ninoseki</span></a></span>'s <a href="https://ruby.social/tags/vscode_extension" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vscode_extension</span></a> Mogami, which shows the latest dependencies in <a href="https://ruby.social/tags/Gemfile" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Gemfile</span></a>, <a href="https://ruby.social/tags/shards" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>shards</span></a> and <a href="https://ruby.social/tags/requirements_txt" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>requirements_txt</span></a>.</p><p>Keep in mind that <a href="https://ruby.social/tags/crystalshard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>crystalshard</span></a> checks are only working on <a href="https://ruby.social/tags/github" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>github</span></a> repos for now though!</p><p><a href="https://github.com/ninoseki/vscode-mogami?tab=readme-ov-file#vscode-mogami" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/ninoseki/vscode-mog</span><span class="invisible">ami?tab=readme-ov-file#vscode-mogami</span></a></p><p><a href="https://ruby.social/tags/ruby" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ruby</span></a> <a href="https://ruby.social/tags/rubylang" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>rubylang</span></a> <a href="https://ruby.social/tags/CrystalLang" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CrystalLang</span></a> <a href="https://ruby.social/tags/crystal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>crystal</span></a> <a href="https://ruby.social/tags/CrystalLanguage" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CrystalLanguage</span></a> <a href="https://ruby.social/tags/python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>python</span></a> <a href="https://ruby.social/tags/code" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>code</span></a> <a href="https://ruby.social/tags/dependencies" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependencies</span></a> <a href="https://ruby.social/tags/rubyprogramming" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>rubyprogramming</span></a></p>
Daniel<p><a href="https://social.hnnng.space/tags/software" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>software</span></a> <a href="https://social.hnnng.space/tags/development" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>development</span></a> <a href="https://social.hnnng.space/tags/build" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>build</span></a> <a href="https://social.hnnng.space/tags/tooling" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tooling</span></a> <a href="https://social.hnnng.space/tags/dependencies" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dependencies</span></a><br><a href="https://simonwillison.net/2025/Feb/8/salvatore-sanfilippo/#atom-everything" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">simonwillison.net/2025/Feb/8/s</span><span class="invisible">alvatore-sanfilippo/#atom-everything</span></a></p>
SpaceLifeForm<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@kevinrothrock" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>kevinrothrock</span></a></span> </p><p>He should have stayed at home with a water hose that had no water pressure. </p><p>He could have moved the cars out and kept them cool for a few minutes.</p><p><a href="https://infosec.exchange/tags/ClimateChange" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ClimateChange</span></a> <a href="https://infosec.exchange/tags/Dependencies" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Dependencies</span></a> <a href="https://infosec.exchange/tags/SupplyChains" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SupplyChains</span></a></p>
Toasty<p>Hmm, two Python package dependencies which each export the same top-level module. The result: one just overwrites the other's files on installation! 🙃 </p><p>Does anybody know a secret sauce solution to this that doesn't involve splitting up apps or forking a package repository? Preferably compatible with uv.</p><p><a href="https://dosgame.club/tags/Software" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Software</span></a> <a href="https://dosgame.club/tags/Python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python</span></a> <a href="https://dosgame.club/tags/Packaging" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Packaging</span></a> <a href="https://dosgame.club/tags/Dependencies" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Dependencies</span></a></p>