<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: marksomnian</title><link>https://news.ycombinator.com/user?id=marksomnian</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 05 Oct 2026 10:11:09 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=marksomnian" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by marksomnian in "Is your Postgres migration safe or not safe?"]]></title><description><![CDATA[
<p>I like the concept and I'm trying to work out if it'll be useful for me, but I just cannot get past the cookie-cutter LLM style of the landing page. A Go library doesn't need a marketing page with a seemingly unrelated artwork and call-outs like "Climb from easy to nightmare →". Put a runnable example front and centre.</p>
]]></description><pubDate>Sat, 26 Sep 2026 10:24:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=49855113</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=49855113</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49855113</guid></item><item><title><![CDATA[New comment by marksomnian in "In-toto: A framework to secure the integrity of software supply chains"]]></title><description><![CDATA[
<p>To answer your question:<p>> Does Debian already provide signature on .deb files (that is, provide a manifest of their hashes and and sign each)?<p>Yes it does. If you look at <a href="https://ftp.debian.org/debian/dists/trixie/InRelease" rel="nofollow">https://ftp.debian.org/debian/dists/trixie/InRelease</a> it's a PGP-signed file containing a list of files and their hashes. Each of those files (eg <a href="https://ftp.debian.org/debian/dists/trixie/main/binary-amd64/Packages.gz" rel="nofollow">https://ftp.debian.org/debian/dists/trixie/main/binary-amd64...</a>) then contains a list of .deb files along with their shasums. In other words, a Debian repo is a set of deb files, metadata files with their hashes, index files with hashes of the metadata files, and PGP signatures for the indexes, so the whole chain can be verified.<p>This means that anyone can set up a deb mirror by (essentially, there's some extra steps) copying that entire structure and the integrity is guaranteed because only the upstream admins can sign the metadata.</p>
]]></description><pubDate>Sat, 18 Jul 2026 11:55:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48957231</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=48957231</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48957231</guid></item><item><title><![CDATA[New comment by marksomnian in "In-toto: A framework to secure the integrity of software supply chains"]]></title><description><![CDATA[
<p>That's exactly where I keep getting caught. I've looked at in-toto a number of times, and each time I've been left wondering "how is this better than a signed list of hashes?".<p>Which I suppose is what in-toto is at its core, but it's taken me a long time and lots of reading to get to that point, and I'm not seeing the advantages of it (except it being a standard, OK, fair enough).<p>I must be missing something.</p>
]]></description><pubDate>Sat, 18 Jul 2026 11:50:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=48957202</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=48957202</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48957202</guid></item><item><title><![CDATA[New comment by marksomnian in "We scaled PgBouncer to 4x throughput"]]></title><description><![CDATA[
<p>nginx (2004, ok, 22 years), ClickHouse (2016)</p>
]]></description><pubDate>Sun, 12 Jul 2026 09:57:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=48879830</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=48879830</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48879830</guid></item><item><title><![CDATA[New comment by marksomnian in "Real-time map of Great Britain's rail network"]]></title><description><![CDATA[
<p>That data is in fact made publicly available by Network Rail: <a href="https://wiki.openraildata.com/index.php/TD" rel="nofollow">https://wiki.openraildata.com/index.php/TD</a><p>though interpreting it isn't the easiest thing in the world...</p>
]]></description><pubDate>Mon, 06 Jul 2026 20:39:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48810214</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=48810214</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48810214</guid></item><item><title><![CDATA[Finding a needle in a 4 GB haystack: from 0.75 GB/s to 49 GB/s in Go]]></title><description><![CDATA[
<p>Article URL: <a href="https://segflow.github.io/post/fast-file-search-go/">https://segflow.github.io/post/fast-file-search-go/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48334876">https://news.ycombinator.com/item?id=48334876</a></p>
<p>Points: 7</p>
<p># Comments: 1</p>
]]></description><pubDate>Sat, 30 May 2026 10:56:01 +0000</pubDate><link>https://segflow.github.io/post/fast-file-search-go/</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=48334876</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48334876</guid></item><item><title><![CDATA[New comment by marksomnian in "Bluesky CEO Jay Graber is stepping down"]]></title><description><![CDATA[
<p>It's not that unusual to have an interim CEO hold the reins (read: sign anything that needs the CEO's signature) while a permanent one is found.</p>
]]></description><pubDate>Mon, 09 Mar 2026 19:43:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=47314374</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=47314374</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47314374</guid></item><item><title><![CDATA[ClickHouse Release 26.1]]></title><description><![CDATA[
<p>Article URL: <a href="https://presentations.clickhouse.com/2026-release-26.1/">https://presentations.clickhouse.com/2026-release-26.1/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46875610">https://news.ycombinator.com/item?id=46875610</a></p>
<p>Points: 8</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 03 Feb 2026 19:03:38 +0000</pubDate><link>https://presentations.clickhouse.com/2026-release-26.1/</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=46875610</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46875610</guid></item><item><title><![CDATA[New comment by marksomnian in "I hate GitHub Actions with passion"]]></title><description><![CDATA[
<p>In fact, uv's docs half-suggest this:<p>> With uv, it turns out that it's often faster to omit pre-built wheels from the cache (and instead re-download them from the registry on each run). On the other hand, caching wheels that are built from source tends to be worthwhile, since the wheel building process can be expensive, especially for extension modules.<p><a href="https://docs.astral.sh/uv/concepts/cache/#caching-in-continuous-integration" rel="nofollow">https://docs.astral.sh/uv/concepts/cache/#caching-in-continu...</a></p>
]]></description><pubDate>Wed, 14 Jan 2026 22:12:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=46624453</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=46624453</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46624453</guid></item><item><title><![CDATA[New comment by marksomnian in "Why users cannot create Issues directly"]]></title><description><![CDATA[
<p>In my experience, the remote shell weirdness is usually because the remote shell doesn’t recognise ghostty’s TERM=xterm-ghostty value. Fixed by either copying over a terminfo with it in, or setting TERM=xterm-256color before ssh’ing: <a href="https://ghostty.org/docs/help/terminfo" rel="nofollow">https://ghostty.org/docs/help/terminfo</a></p>
]]></description><pubDate>Fri, 02 Jan 2026 09:43:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=46463147</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=46463147</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46463147</guid></item><item><title><![CDATA[PEP 761 – Deprecating PGP signatures for CPython artifacts (2024)]]></title><description><![CDATA[
<p>Article URL: <a href="https://peps.python.org/pep-0761/">https://peps.python.org/pep-0761/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46412813">https://news.ycombinator.com/item?id=46412813</a></p>
<p>Points: 2</p>
<p># Comments: 2</p>
]]></description><pubDate>Sun, 28 Dec 2025 17:41:41 +0000</pubDate><link>https://peps.python.org/pep-0761/</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=46412813</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46412813</guid></item><item><title><![CDATA[New comment by marksomnian in "Building a macOS app to know when my Mac is thermal throttling"]]></title><description><![CDATA[
<p>Site appears to be hugged to death, repo is: <a href="https://github.com/angristan/MacThrottle" rel="nofollow">https://github.com/angristan/MacThrottle</a></p>
]]></description><pubDate>Sun, 28 Dec 2025 17:09:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=46412523</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=46412523</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46412523</guid></item><item><title><![CDATA[New comment by marksomnian in "Denial of service and source code exposure in React Server Components"]]></title><description><![CDATA[
<p>Meta don’t use RSC: <a href="https://bsky.app/profile/en-js.bsky.social/post/3lmvwmr5rfs23" rel="nofollow">https://bsky.app/profile/en-js.bsky.social/post/3lmvwmr5rfs2...</a><p>> We are not using RSC at Meta yet, bc of limits of our packaging infra (it’s great at different things) and because Relay+GraphQL gives us many of the same benefits as RSCs. But we are fans and users of server driven UI and incrementally working toward RSC.<p>(as of April 2025)</p>
]]></description><pubDate>Fri, 12 Dec 2025 00:25:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=46239360</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=46239360</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46239360</guid></item><item><title><![CDATA[New comment by marksomnian in "Doing Rails Wrong"]]></title><description><![CDATA[
<p>And `rails new` required me to install Ruby and Rails. I'm not sure what the point you're making is.</p>
]]></description><pubDate>Tue, 07 Oct 2025 18:08:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=45506599</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=45506599</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45506599</guid></item><item><title><![CDATA[New comment by marksomnian in "Shopify, pulling strings at Ruby Central, forces Bundler and RubyGems takeover"]]></title><description><![CDATA[
<p>GitLab too: <a href="https://gitlab.com/gitlab-org/gitlab" rel="nofollow">https://gitlab.com/gitlab-org/gitlab</a></p>
]]></description><pubDate>Tue, 23 Sep 2025 21:33:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=45353031</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=45353031</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45353031</guid></item><item><title><![CDATA[New comment by marksomnian in "Can You Develop Film in a Jägerbomb?"]]></title><description><![CDATA[
<p>Looks like the source the article is based around is <a href="https://www.diyphotography.net/develop-film-at-home-with-a-jager-bomb/" rel="nofollow">https://www.diyphotography.net/develop-film-at-home-with-a-j...</a>, which itself is a write-up of <a href="https://www.youtube.com/watch?v=5_Oja2mpYqg" rel="nofollow">https://www.youtube.com/watch?v=5_Oja2mpYqg</a>.</p>
]]></description><pubDate>Mon, 01 Sep 2025 19:03:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=45095594</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=45095594</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45095594</guid></item><item><title><![CDATA[New comment by marksomnian in "How we exploited CodeRabbit: From simple PR to RCE and write access on 1M repos"]]></title><description><![CDATA[
<p>If I were a CodeRabbit customer, I'd still be pretty concerned after reading that.<p>How can CodeRabbit be certain that the GitHub App key was not exfiltrated and used to sign malicious tokens for customer repos (or even used for that in-situ)? I'm not sure if GitHub supports restricting the source IPs of API requests, but if it does, it'd be a trivial mitigation - and one that is absent from the blog post.<p>The claim that "no malicious activity occurred" implies that they audited the activities of every repo that used Rubocop (or any other potential unsandboxed tool) from the point that support was added for it until the point that the vulnerability was fixed. That's a big claim.<p>And why only publish this now, when the Kudelski article makes it to the top of HN, over six months after it was disclosed to them?</p>
]]></description><pubDate>Tue, 19 Aug 2025 21:06:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=44956266</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=44956266</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44956266</guid></item><item><title><![CDATA[Reflections on the React Community]]></title><description><![CDATA[
<p>Article URL: <a href="https://leerob.com/reflections">https://leerob.com/reflections</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44881779">https://news.ycombinator.com/item?id=44881779</a></p>
<p>Points: 6</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 12 Aug 2025 21:01:50 +0000</pubDate><link>https://leerob.com/reflections</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=44881779</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44881779</guid></item><item><title><![CDATA[New comment by marksomnian in "Performance and telemetry analysis of Trae IDE, ByteDance's VSCode fork"]]></title><description><![CDATA[
<p>> might be good to mention that for transparency, because people can tell anyway and it might feel slightly otherwise<p>Devil's advocate: why does it matter (apart from "it feels wrong")? As long as the conclusions are sound, why is it relevant whether AI helped with the writing of the report?</p>
]]></description><pubDate>Sun, 27 Jul 2025 18:39:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=44703464</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=44703464</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44703464</guid></item><item><title><![CDATA[New comment by marksomnian in "TODOs aren't for doing"]]></title><description><![CDATA[
<p>I like this style. In a project I worked on we had CI reject any FIXMEs outright and any TODOs that weren't accompanied by an issue ticket[^1], so the hierarchy would be<p>FIXME: I am leaving a note to myself to not get distracted, but this code is not considered finished/mergeable until it's resolved<p>XXX: this needs fixing soon, but the code will still be functional without it<p>TODO: this needs revisiting but the code is perfectly useable without it - a lower priority XXX<p>NOTE: this does something unusual and you need to bear in mind while working on this code<p>[^1]: the value of doing (or not doing) this is a subject that has already been extensively rehashed in sibling comments</p>
]]></description><pubDate>Tue, 22 Jul 2025 21:34:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=44653267</link><dc:creator>marksomnian</dc:creator><comments>https://news.ycombinator.com/item?id=44653267</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44653267</guid></item></channel></rss>