<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: carols10cents</title><link>https://news.ycombinator.com/user?id=carols10cents</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 12 Apr 2026 09:05:01 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=carols10cents" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by carols10cents in "Decisions that eroded trust in Azure – by a former Azure Core engineer"]]></title><description><![CDATA[
<p>If you're writing the tests after writing the code, you're not doing TDD though.</p>
]]></description><pubDate>Fri, 03 Apr 2026 21:17:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=47632402</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=47632402</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47632402</guid></item><item><title><![CDATA[New comment by carols10cents in "Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised"]]></title><description><![CDATA[
<p>Since Shai-Hulud scanned maintainers' computers, if the signing key was stored there too (without a password), couldn't the attackers have published signed packages?<p>That is, how does signing prevent publishing of malware, exactly?</p>
]]></description><pubDate>Wed, 17 Sep 2025 17:54:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=45279111</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=45279111</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45279111</guid></item><item><title><![CDATA[New comment by carols10cents in "Crates.io phishing attempt"]]></title><description><![CDATA[
<p>Yeah, npm has orders of magnitude more users than crates.io. This attack's success, or lack thereof, has no bearing on the savviness of JavaScript or Rust developers.</p>
]]></description><pubDate>Fri, 12 Sep 2025 16:28:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=45223855</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=45223855</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45223855</guid></item><item><title><![CDATA[New comment by carols10cents in "Malicious versions of Nx and some supporting plugins were published"]]></title><description><![CDATA[
<p>So why are you upgrading?</p>
]]></description><pubDate>Thu, 28 Aug 2025 03:00:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=45047871</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=45047871</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45047871</guid></item><item><title><![CDATA[New comment by carols10cents in "Malicious versions of Nx and some supporting plugins were published"]]></title><description><![CDATA[
<p>Who is requiring you to use large numbers of transitive dependencies? You can always write all the code yourself instead.</p>
]]></description><pubDate>Thu, 28 Aug 2025 02:59:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=45047855</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=45047855</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45047855</guid></item><item><title><![CDATA[New comment by carols10cents in "Why is everybody knitting chickens?"]]></title><description><![CDATA[
<p>Why <i>wouldn't</i> you knit a chicken???</p>
]]></description><pubDate>Thu, 29 May 2025 20:59:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=44130340</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=44130340</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44130340</guid></item><item><title><![CDATA[New comment by carols10cents in "When Compiler Engineers Act as Judges, What Can Possibly Go Wrong?"]]></title><description><![CDATA[
<p>And the architect is a volunteer for Habitat for Humanity.</p>
]]></description><pubDate>Mon, 12 May 2025 14:26:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=43963347</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=43963347</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43963347</guid></item><item><title><![CDATA[New comment by carols10cents in "Tj-actions/changed-files GitHub Action Compromised – used by over 23K repos"]]></title><description><![CDATA[
<p>who is going to pay for the review of packages and updates? how do we know we can trust the reviewers?<p>github actions are name-spaced and that didn't help anything here...</p>
]]></description><pubDate>Sat, 15 Mar 2025 14:23:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=43372725</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=43372725</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43372725</guid></item><item><title><![CDATA[New comment by carols10cents in "Rust Just Failed an Important Test"]]></title><description><![CDATA[
<p>Do not try to equalize a maintainer guarding their time and energy from having to deal with an issue that has already been fixed and users that refuse to search or read with trying to cover up for gross negligence and bugs.</p>
]]></description><pubDate>Thu, 01 Aug 2024 20:11:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=41133078</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=41133078</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41133078</guid></item><item><title><![CDATA[New comment by carols10cents in "Rust Just Failed an Important Test"]]></title><description><![CDATA[
<p>No maintainer is obligated to maintain access to a discussion space for their users.<p>> One now doesn't even know and cannot even estimate the number of other issues that must have gone unreported. It's not safe or wise to use a package that is so shrouded in mystery. It is in fact foolhardy.<p>Issues don't get reported for any number of reasons. All open source is use at your own risk.</p>
]]></description><pubDate>Thu, 01 Aug 2024 17:07:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=41131250</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=41131250</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41131250</guid></item><item><title><![CDATA[New comment by carols10cents in "Fern Hollow Bridge should have been closed years before it collapsed"]]></title><description><![CDATA[
<p>It's the Charles Anderson Bridge. <a href="https://engage.pittsburghpa.gov/charles-anderson-bridge" rel="nofollow">https://engage.pittsburghpa.gov/charles-anderson-bridge</a></p>
]]></description><pubDate>Wed, 19 Jun 2024 11:10:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=40727100</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=40727100</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40727100</guid></item><item><title><![CDATA[New comment by carols10cents in "Timeline of the xz open source attack"]]></title><description><![CDATA[
<p>What would prevent the sock puppet accounts from signing each others' keys?</p>
]]></description><pubDate>Tue, 02 Apr 2024 16:52:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=39907960</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=39907960</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39907960</guid></item><item><title><![CDATA[New comment by carols10cents in "C++ creator rebuts White House warning"]]></title><description><![CDATA[
<p>How are these two problems unique to Rust though?</p>
]]></description><pubDate>Wed, 20 Mar 2024 16:34:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=39768917</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=39768917</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39768917</guid></item><item><title><![CDATA[New comment by carols10cents in "Show HN: Little Fixes – a spatial forum to improve your city"]]></title><description><![CDATA[
<p>It looks like accounts can be entirely anonymous. How are you planning on handling moderation of comments? What happens if I post on a neighbor's house "jagoff who lets their dogs poop everywhere lives here, please evict"?</p>
]]></description><pubDate>Fri, 23 Feb 2024 22:06:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=39486736</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=39486736</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39486736</guid></item><item><title><![CDATA[New comment by carols10cents in "When every ketchup but one went extinct (2022)"]]></title><description><![CDATA[
<p>Tell me you don't know anyone from Pittsburgh without telling me you don't know anyone from Pittsburgh.</p>
]]></description><pubDate>Thu, 15 Feb 2024 21:52:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=39389536</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=39389536</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39389536</guid></item><item><title><![CDATA[New comment by carols10cents in "Standards for Software Liability: Jim Dempsey, Lawfare, UC Berkeley Law"]]></title><description><![CDATA[
<p>> these are the folks who do the Lawfare podcast, right?<p>Yep, and they had a podcast episode with the author of this paper: <a href="https://www.lawfaremedia.org/article/the-lawfare-podcast-jim-dempsey-on-standards-for-software-liability" rel="nofollow">https://www.lawfaremedia.org/article/the-lawfare-podcast-jim...</a></p>
]]></description><pubDate>Fri, 26 Jan 2024 14:40:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=39143104</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=39143104</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39143104</guid></item><item><title><![CDATA[New comment by carols10cents in "How Australia’s ‘Bluey’ conquered children’s entertainment"]]></title><description><![CDATA[
<p>I wish Bluey hadn't introduced the concept of a "bush wee" to my kid, I've had to explain that no, we can't pee in someone's yard in the middle of our busy neighborhood...</p>
]]></description><pubDate>Fri, 05 Jan 2024 15:48:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=38880283</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=38880283</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38880283</guid></item><item><title><![CDATA[New comment by carols10cents in "Was Rust Worth It?"]]></title><description><![CDATA[
<p>Namespaces can't be typosquatted?</p>
]]></description><pubDate>Thu, 26 Oct 2023 17:13:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=38028646</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=38028646</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38028646</guid></item><item><title><![CDATA[New comment by carols10cents in "Was Rust Worth It?"]]></title><description><![CDATA[
<p>Crates.io has publisher information-- namespacing is not required for that. For example, here are all the crates owned by the `azure` GitHub organization and published by the `azure-sdk-publish-rust` team: <a href="https://crates.io/teams/github:azure:azure-sdk-publish-rust" rel="nofollow noreferrer">https://crates.io/teams/github:azure:azure-sdk-publish-rust</a></p>
]]></description><pubDate>Thu, 26 Oct 2023 13:34:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=38025290</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=38025290</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38025290</guid></item><item><title><![CDATA[New comment by carols10cents in "Was Rust Worth It?"]]></title><description><![CDATA[
<p>How do namespaces measurably increase security?</p>
]]></description><pubDate>Thu, 26 Oct 2023 13:30:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=38025253</link><dc:creator>carols10cents</dc:creator><comments>https://news.ycombinator.com/item?id=38025253</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38025253</guid></item></channel></rss>