<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: broxit</title><link>https://news.ycombinator.com/user?id=broxit</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 15 Jun 2026 04:59:19 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=broxit" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by broxit in "Show HN: Homebrew 6.0.0"]]></title><description><![CDATA[
<p>> Even in that case, my suggestion would be that we just run it in our own CI and block package release.<p>I agree.<p>> open source security scanner that runs on all Homebrew packages and requires a cooldown.<p>I think that is where all this is going in the longterm.<p>Until then, any upstream shenanigans are more likely to surface in hours 0-48 after a new release than hours 0-4.</p>
]]></description><pubDate>Thu, 11 Jun 2026 18:26:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=48494446</link><dc:creator>broxit</dc:creator><comments>https://news.ycombinator.com/item?id=48494446</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48494446</guid></item><item><title><![CDATA[New comment by broxit in "Show HN: Homebrew 6.0.0"]]></title><description><![CDATA[
<p>Glad to see that Homebrew is taking security seriously. Still, I want to minimize the number of parties who can quickly get new code onto my machine.<p>Your doc says "Human review of each release." What does that actually entail?<p>uv had a release at 10:21am yesterday with 7,060 additions and 2,409 deletions. The new release was available in homebrew at 11:46am. What human review happened there?<p>I don't know of any other OS package manager that ships code this quickly to users. Arch Linux has not pushed the new release of uv yet, for example.</p>
]]></description><pubDate>Thu, 11 Jun 2026 18:04:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=48494120</link><dc:creator>broxit</dc:creator><comments>https://news.ycombinator.com/item?id=48494120</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48494120</guid></item><item><title><![CDATA[New comment by broxit in "Show HN: Homebrew 6.0.0"]]></title><description><![CDATA[
<p>Thanks for the update. Is there any chance we can get some kind of cooldown mechanism in Homebrew?<p>The only people I want to trust to quickly ship new code to my machine are Apple and my browser (which handles more untrusted input than anything else).<p>For everything else (vscode and its extensions, npm, homebrew, and all the apps that self-update), I prefer to err on the side of waiting a few days.<p>Some exceptional 0days might warrant a cooldown bypass, but even in its current form users are vulnerable to 0days until they run brew upgrade.</p>
]]></description><pubDate>Thu, 11 Jun 2026 17:30:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48493473</link><dc:creator>broxit</dc:creator><comments>https://news.ycombinator.com/item?id=48493473</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48493473</guid></item></channel></rss>