[-] Kissaki@programming.dev 2 points 14 hours ago

Code and graphics prompting typically doesn't need to make web requests to serve a response.

[-] Kissaki@programming.dev 5 points 14 hours ago* (last edited 14 hours ago)

TL;DR: we spend more CPU cycles rendering commits for scrapers than we spend on all other kinds of legitimate access, including git clones.

I've read similar and even worse before. Probably from Codeberg, or maybe a smaller host of Forgejo or GitLab.

The blame html pages were repeatedly being requested. Which is even worse and even less plausibly useful than a commit html page.

[-] Kissaki@programming.dev 3 points 14 hours ago* (last edited 14 hours ago)

They're not scraping to cache or store, they're operating as an agent - scraping or single user requests.

Which is obviously bad and damaging, especially on their scale and on repeatedly fetched websites that they could be caching.

Google indexed the entire web. It's baffling that such indexing is not the norm on these huge providers.

Just my interpretation anyway.

[-] Kissaki@programming.dev 6 points 16 hours ago

used 20% of my CPU […], but didn’t report that usage

haha

[-] Kissaki@programming.dev 3 points 16 hours ago

The clarity of Activity Monitor.
The depth of Task Manager.
The speed of a cockpit.

What is "a cockpit"?

[-] Kissaki@programming.dev 32 points 16 hours ago

ha, nice pic

[-] Kissaki@programming.dev 5 points 1 day ago

; thank you OpenAI nee Microsoft.

What does this nee formulation mean, or is this a typo?

[-] Kissaki@programming.dev 5 points 1 day ago

Looking into the mentioned unforgivable vulnerabilities and stubborn weaknesses published by CISA:

Unforgivable Vulnerabilities (PDF)

Given the above criteria, following are some candidates for unforgivable vulnerabilities that satisfy all (or most) of the criteria for an unforgivable vulnerability. […]

  1. Buffer overflow using long strings of "A" characters in:
    • a. Username/password during authentication
    • b. File or directory name
    • c. Arguments to most common features of the product or product class
  2. XSS using well-formed <script> tags, especially in the:
    • a. Username/password of an authentication routine
    • b. Body, subject, title, or to/from of a message
  3. SQL injection using ' in the:
    • a. Username/password of an authentication routine
    • b. "id" or other identifier field
    • c. Numeric field
  4. Remote file inclusion from direct input such as:
    • a. include($_GET['dir'] . "/config.inc");
  5. Directory traversal using "../.." or "/a/b/c" in GET or SEND commands of frequently-used file sharing functionality (e.g., a GET in a web/FTP server, or a send-file command in a chat client)
  6. World-writable critical files:
    • a. Executables
    • b. Libraries
    • c. Configuration files
  7. Direct requests of administrator scripts
  8. Grow-your-own crypto
  9. Authentication bypass using "authenticated=1" cookie/form field
  10. TOCTOU race condition – symlink
  11. Privilege escalation launching "help" (Windows)
  12. Hard-coded or undocumented account/password
  13. Unchecked length/width/height/size values passed to malloc()/calloc()

Stubborn Weaknesses

| CWE-ID | Description | 2023 Rank | |


|


|


| | CWE-787 | Out-of-bounds Write | 1 | | CWE-79 | Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 2 | | CWE-89 | Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 3 | | CWE-416 | Use After Free | 4 | | CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | 5 | | CWE-20 | Improper Input Validation | 6 | | CWE-125 | Out-of-bounds Read | 7 | | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 8 | | CWE-352 | Cross-Site Request Forgery (CSRF) | 9 | | CWE-476 | NULL Pointer Dereference | 12 | | CWE-287 | Improper Authentication | 13 | | CWE-190 | Integer Overflow or Wraparound | 14 | | CWE-502 | Deserialization of Untrusted Data | 15 | | CWE-119 | Improper Restriction of Operations within Bounds of a Memory Buffer | 17 | | CWE-798 | Use of Hard-coded Credentials | 18 |

[-] Kissaki@programming.dev 1 points 1 day ago

It's not the exact thing; it just makes it worse. For many people, it's personality and psychology; they go the path of least resistance and don't care about much besides their main goals. Whether you embed it in capitalism or not, these fundamental causes remain.

Do you have an economic or social system in mind where it would be solved or better?

15

The htmx team is very happy to announce the release of htmx 4.0.0! This is the culmination of 8 months of work (plus a game) and we are very happy with the results.

Note that we are not marking 4.0 as latest in NPM because we do not want to force-upgrade users who are relying on non-versioned CDN URLs for htmx. Instead, 2.x will remain latest and the 4.0 line will remain next until some point in early 2027. The website, however, will reference 4.0.

We hope you enjoy htmx 4. htmx 2 will continue to be supported indefinitely so don’t feel any pressure to upgrade.

[-] Kissaki@programming.dev 8 points 3 days ago

"Click to Play" on the video - nah mate, you gotta auto-play those videos, and embed them in the article. Bonus points for the video being unrelated to the article.

I've seen it. I've experienced it. I hate it.

The bottom right videos were the previous iteration of that.

[-] Kissaki@programming.dev 10 points 3 days ago

“I think Nvidia is very much a community,

🤨

[-] Kissaki@programming.dev 1 points 3 days ago* (last edited 3 days ago)

to serve specific purposes

You're asking for specifics on their concerns while not providing the specifics that were already in place in your claim here.

They acknowledged and included reasons for the Cloudflare adoption in their original post.

2

For five days in March 2026, a single stolen token let one group poison five software ecosystems including a package downloaded 95 million times a month. The attack started with a misconfigured GitHub Actions workflow, and ended with backdoored code sitting inside CI/CD pipelines around the world.

Today, two people behind this attack were arrested. TeamPCP, allegedly operated by these threat actors, started attacks in late 2025 running opportunistic cloud exploits, then pivoted in early 2026 to targeting the software supply chain itself.

Flare’s Emerging Threats Team wanted to share examples of some of the techniques that can be used to unmask one operator behind TeamPCP, using the Flare platform to trace a single alias across the accounts, credentials, and infrastructure that connected back to a real identity. There were other independent investigations on this topic, including by Brian Krebs. Below, we walk through who TeamPCP is and share the process of deanonymizing threat actors.

2

Game trailers which take their time to show gameplay can perform way better than trailers which are cut fast and make a hard sell. See a before/after for the Sheepherds' Announce/Launch trailer to see what a difference the editing style made!

I explain how to make a game trailer which lets the viewer see what’s special about the game and how to apply it when you edit a gameplay trailer.

46

In Brief:

  • Two motions regarding "artificial intelligence" and Large Language Models (LLMs) were voted on among Codeberg e. V. members and passed.
  • We are promising to not use any of your data to train LLM and explain what the planned Terms of Use change mean for 'vibe-coded' projects.
  • We believe that LLMs endanger the free/libre software ecosystem as a whole.

The blog/news post then goes extensively into where Codeberg understands itself to be in the development landscape, and their voting results. They present their interpretation of the current software development and hardware landscape under the influence of LLMs, and the consequences they take. And how it changes not only development in general, but FOSS collaboration and projects specifically.

To us, it seems ridiculous to see projects with a single developer and virtually no users consuming as much or even more resources than some of the largest community projects on Codeberg, which operate frugal with CI/CD and storage resources. We do not believe it is reasonable for Codeberg to invest our precious donation money into hosting of large ghost projects.

-3
47

Andrew Kelley quit his job in 2018 to build a programming language. Eight years later, Zig powers Ghostty, TigerBeetle and Uber's cross-compilation. It's top 5 most admired on Stack Overflow. There's just one thing missing: 1.0. Andrew Kelley explains why.

Vitaly talked to Andrew about:

  • Why Zig has no 1.0 after a decade, and why that's deliberate
  • Why Zig left GitHub
  • Why Zig banned AI from Zig
  • What makes Zig better than C (and why every other C replacement failed)
  • Andrew’s take on Open Source

It's a long interview, but I found it very interesting and worth it.

5

When using Central Package Management (Directory.Packages.props holds package versions), package version declarations can remain after package references have been removed. The package versions are unused and misleading.

dotnet nuget why can be used to get a dependency tree across projects to answer how a package comes into the dependency tree. However, the extensive tree list result for a list of version declarations is not viable to simply determine what 'is in use' and what isn't.

I am sharing my Nushell snippet which answers the question of what is declared but not referenced:

# List Directory.Packages.props version declarations that are in no csproj
def "dotnet unused-dirpackprops" [] {
  let defs = open Directory.Packages.props | from xml | get content | where tag == ItemGroup | get content.attributes.Include | flatten | sort --ignore-case --natural
  let refs = ls **/*.csproj | get name | each { open | from xml | get content | select content | flatten | flatten | where tag == PackageReference | get attributes.Include } | flatten | uniq | sort --ignore-case --natural
  $defs | difference $refs
}
❯ dotnet unused-dirpackprops
╭───┬─────────────────────────────────────────╮
│ 0 │ coverlet.collector                      │
│ 1 │ System.Net.Http                         │
│ 2 │ System.ServiceProcess.ServiceController │
╰───┴─────────────────────────────────────────╯

Gaps: In this simple form, only covers the standard csproj package references. Package references included during build through other target or prop files are not covered (probably irrelevant for most users).

6
submitted 1 month ago* (last edited 1 month ago) by Kissaki@programming.dev to c/uiux@programming.dev

They go over how the web and frameworks decided against horizontal, apart from deliberate emphasis, they go over some desktop layout attempts, failures and successes (more of the same vs navigation), a chapter about (paper) documents as the source, and endless panes now using horizontal.

From the description:

Almost every screen we use is a landscape rectangle, wider than it is tall. And on almost all of them, the content moves vertically. Always down.

This video walks through a wrong question. If mobile scrolls down, why doesn't the desktop scroll sideways?

The question turns out to be wrong.

Chapters

  • [00:00] Introduction
  • [01:23] The Web Could, and Doesn't
  • [03:18] The Microsoft Bet - Windows 8 "Metro"/"Modern" failure
  • [06:18] What Makes a Difference - Layouts where horizontal works
  • [09:14] Horizontal Scrolling as Emphasis
  • [10:24] When Horizontal Axis Means Something
  • [12:13] The Document Model
  • [14:06] The Potential of a Glass Plane

References

56
11
8
6
view more: next ›

Kissaki

0 post score
0 comment score
joined 3 years ago
MODERATOR OF