GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Jérôme Petazzoni (jpetazzo@hachyderm.io)

  1. Embed this notice
    Jérôme Petazzoni (jpetazzo@hachyderm.io)'s status on Friday, 24-May-2024 04:22:28 JST Jérôme Petazzoni Jérôme Petazzoni
    in reply to
    • Rich Felker

    @dalias not wanting to be pedantic, but if I build a package (in a sandboxed environment), then install that package, and the postinstall script of the package backdoors my system, how am I being more secure than curl|sh?

    (My stance is that curl|sh per se isn't bad; the key thing is to look at provenance: https on a well-known domain with legit-looking URL = good; anything else = beware. And same thing for any package or any artifact in any form. I'm happy to revise said stance tho!)

    In conversation about a year ago from hachyderm.io permalink
  2. Embed this notice
    Jérôme Petazzoni (jpetazzo@hachyderm.io)'s status on Friday, 24-May-2024 04:22:21 JST Jérôme Petazzoni Jérôme Petazzoni
    in reply to
    • Rich Felker
    • Amber

    @puppygirlhornypost @dalias I agree with you; I'm going to try to rephrase my initial question 😅

    Given that virtually all¹ package managers have some way to run arbitrary postinstall scripts (as root!); what makes a deb/rpm/AUR/... better than curl|sh?

    My stance is that if I install packages from "core" repos, I'm probably good, because these maintainers usually care *a lot* and to a fantastic job (at least compared to the average dev trying to package their stuff).

    But with 3rd party stuff…

    In conversation about a year ago from gnusocial.jp permalink
  3. Embed this notice
    Jérôme Petazzoni (jpetazzo@hachyderm.io)'s status on Thursday, 12-Oct-2023 18:03:00 JST Jérôme Petazzoni Jérôme Petazzoni

    Mes collègues préparent un live stream pour parler de kuik (kube-image-keeper), c'est mardi prochain (le 17!) à 17h, et ça promet d'envoyer du lourd :)

    https://www.eventbrite.fr/e/billets-enix-live-show-cauchemar-dans-k8s-quand-la-registry-fait-des-siennes-721265182577

    (English friends: this will be a French live stream about kube image keeper, by the very excellents Alex Buisine and Paul Laffitte!)

    In conversation Thursday, 12-Oct-2023 18:03:00 JST from hachyderm.io permalink

    Attachments


    1. https://media.hachyderm.io/media_attachments/files/111/221/213/731/375/937/original/e3acf2c5cab9af7c.png
    2. No result found on File_thumbnail lookup.
      Enix Live Show - Cauchemar dans k8s : quand la registry fait des siennes
      Des problèmes d’indisponibilité ou de quota sur vos registries ? Découvrez kuik, outil open source de caching d’images Docker dans K8s !
  4. Embed this notice
    Jérôme Petazzoni (jpetazzo@hachyderm.io)'s status on Sunday, 23-Apr-2023 04:18:22 JST Jérôme Petazzoni Jérôme Petazzoni
    • Thomas 🔭🕹️

    @thomasfuchs you're making some very good points, but I'm worried that some folks would latch to the car part of the story, which is kind of twisted. While it's true that personal cars amount to maybe 5% of GHG emissions worldwide, transport overall is like 15%, and in the US per capita transportation is one of the top emitters:

    In conversation Sunday, 23-Apr-2023 04:18:22 JST from hachyderm.io permalink

    Attachments


    1. https://media.hachyderm.io/media_attachments/files/110/244/071/164/135/049/original/fc24a5b5a4d5c62f.jpg

User actions

    Jérôme Petazzoni

    Jérôme Petazzoni

    Containers, DevOps, Kubernetes, Music.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          114081
          Member since
          22 Apr 2023
          Notices
          4
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.