Posts by zimoun@sciences.re
 (DIR) Post #B4MYXnYpO0Nmn1cPM8 by zimoun@sciences.re
       0 likes, 0 repeats
       
       @civodul My favorite quote:« […] reviewing the uutils coreutils package (a Rust rewrite of standard GNU utilities).A race condition in the rm utility allowed an unprivileged local attacker to […]The default rm command in Ubuntu 25.10 was reverted to GNU coreutils to mitigate this risk immediately. »
       
 (DIR) Post #B4f8DsHRDutYpYYulE by zimoun@sciences.re
       0 likes, 1 repeats
       
       « Don’t trust, verify » by #curl author – must-read!« Software and digital security should rely on verification, rather than trust. I want to strongly encourage more users and consumers of software to verify curl. And ideally require that you could do at least this level of verification of other software components in your dependency chains. »🤔 It reminds me « Identifying software » #Guix blog post. 🤩Check them out!https://guix.gnu.org/en/blog/2024/identifying-software/https://daniel.haxx.se/blog/2026/03/26/dont-trust-verify/
       
 (DIR) Post #B5Uo3j48jVlyUd8q12 by zimoun@sciences.re
       0 likes, 0 repeats
       
       « The politics of language design » by Pierre-Étienne Meunier🤔 and again 🤔Although, I’m not sure to follow the “stir up a hornet's nest”, the talk raises some core questions about governance or the social impact of technical choices.Damned, I’m sad that although living in Paris my schedule hasn’t let me the opportunity for attending to #LixCon2026 in Paris. Next time, maybe…1/6
       
 (DIR) Post #B5Uo3jLrfbx1NbQzdw by zimoun@sciences.re
       0 likes, 0 repeats
       
       The politics of language design by Pierre-Étienne Meunier in #LixCon2026« Fake supply chain security, even worse than no supply chain security at all? »Indeed, it’s a question for #Nix and #Guix. Yeah 1. … and then 2. …2/6
       
 (DIR) Post #B5Uo3jYGvTsM05Etyy by zimoun@sciences.re
       0 likes, 0 repeats
       
       The politics of language design by Pierre-Étienne Meunier in #LixCon2026« Fake supply chain security, even worse than no supply chain security at all? »…Yeah:1. The builds aren’t guaranteed reproducible by design, I mean, it’s the exactly same as Debian, etc. About Nix I don’t know the details, please read Nix’s expert @luj blog post: https://luj.fr/blog/is-nixos-truly-reproducible.htmlAbout Guix, it’s currently poorly monitored, to my knowledge.3/6
       
 (DIR) Post #B5Uo3jttd5An59MAgi by zimoun@sciences.re
       0 likes, 0 repeats
       
       The politics of language design by Pierre-Étienne Meunier in #LixCon2026« Fake supply chain security, even worse than no supply chain security at all? »…Yeah:2. Guix/Nix packages stuff: it means it provides tooling for auditing and verifying if the binary matches the identified source; and for the whole chain of dependencies. But there is no guarantee it’s fully error-free – we’re able to point where the error if any comes from. It’s already a lot!Guix is like the indian Dabbawala service using “barecodes” everywhere. It doesn’t prevent stories as The Lunchbox. 😉https://en.wikipedia.org/wiki/Dabbawalahttps://en.wikipedia.org/wiki/The_Lunchbox4/6
       
 (DIR) Post #B5Uo3kDkRH3K4ie1dA by zimoun@sciences.re
       0 likes, 0 repeats
       
       The politics of language design by Pierre-Étienne Meunier in #LixCon2026« Create your own language only if you need something new in language design »« OCaml already exists and is the best language for that particular job »Yeah, I would have loved instead of Nix language 😱 and Guix Scheme DSL 🤨 to have OCaml. 🤩5/6
       
 (DIR) Post #B5Uo3kXbFSvr4HvsZc by zimoun@sciences.re
       0 likes, 0 repeats
       
       🤔 To some extent, ideas behind Elpe reminds me propellor (Haskell)Joey Hess’s talk in linux conf au 2017: https://youtu.be/kzXXcr8TyJYhttps://nest.pijul.com/pmeunier/elpe6/6
       
 (DIR) Post #B6E3ZjI9fb7bt1c1Pk by zimoun@sciences.re
       0 likes, 0 repeats
       
       @khinsen About loading manifest.scm inside isolated Guile environment, it might be more annoying than expected.  For instance, channels.scm files are usually very boilerplate and already two reports:https://codeberg.org/guix/guix/issues/8519https://codeberg.org/guix/guix/issues/8573Well, an option for being able to isolate might be helpful but it should not be the default for manifest.scm file, IMHO.@civodul
       
 (DIR) Post #B6EV6tSnZQHvkgd3po by zimoun@sciences.re
       0 likes, 1 repeats
       
       @civodul My favorite quote from the post resuming the today’s computing world:« […] and many more are all about deploying software of unknown origin like there’s no tomorrow. »