Readit News logoReadit News
cayleyh commented on A critique of package managers   gingerbill.org/article/20... · Posted by u/gingerBill
SideburnsOfDoom · 12 hours ago
> He's arguing for developers to be more conscious of the dependencies they use

"be careful all the time" doesn't scale. Half of all developers have below-average diligence, and that's a low bar. No-one is always vigilant, don't think that you're immune to human error.

No, you need tooling, automation to assist. It needs to be supported at the package manager side. Managing a site where many files are uploaded, and then downloaded many times is not a trivial undertaking. It comes with oversight responsibilities. If it's video you have to check for CSAM. If it's executable code, then you have to check for malware.

Package managers are not evil, but they are a tempting target and need to be secured. This can't just be an individual consumer responsibility.

I can't speak for other ecosystems, but some NuGet measures are here:

https://devblogs.microsoft.com/dotnet/building-a-safer-futur...

https://learn.microsoft.com/en-us/nuget/concepts/security-be...

I believe that there have been (a few) successful compromises of packages in NuGet, and that these have been mitigated. I don't know how intense the arms race is now.

cayleyh · 10 hours ago
"Half of all developers have below-average diligence" - a lot of this is also not developer choice, but environmental. So much software is developed and maintained in very constrained economic environments, often by solo devs who also have other responsibilities. The choice here often is trading some "diligence" for "meeting business requirements in the time / budget constraints" imposed by your employer.
cayleyh commented on API Blueprint   apiblueprint.org... · Posted by u/maxwell
didgeoridoo · 3 days ago
GitHub repo is marked as archived by the owner. Is this project still alive?
cayleyh · 3 days ago
The company behind it got bought by Oracle, so all the public stuff was archived. Not sure if there is still any community around it after that.
cayleyh commented on Let's get real about the one-person billion dollar company   marcrand.com/p/lets-get-r... · Posted by u/bizgrayson
rideontime · a month ago
The dream of AI: eliminating all human relationships not mediated by a B2B SaaS contract.
cayleyh · a month ago
I structure all my personal relationships around B2B SaaS contracts. Mom isn't happy when I make changes to the ToS but I've got pretty hard vendor lock-in and a defensible moat there, so I mostly don't worry about the reputational damage.
cayleyh commented on Iron Law of Oligarchy   en.wikipedia.org/wiki/Iro... · Posted by u/rzk
mbones · a month ago
The author was part of an institution in Facist Italy that espoused the superhumanism of these “elites” over the little people as one of their core tenants: “The psychological difference that sets elites apart is that they have personal resources, for instance intelligence and skills, and a vested interest in the government; whilst the rest are incompetent and do not have the capabilities to govern themselves, the elite are resourceful and strive to make the government work.”
cayleyh · a month ago
Wild life path really. Started as a socialist and syndicalist, and then stuff happened (waving hands) and he joined the Mussolini fascists and died before he could see what fascism would do to Europe. Looks like he got more involved with eugenics and elite theory and blue pilled himself to accept fascism as the solution to the problems with democracy and socialism he focused on earlier in his life.
cayleyh commented on Apple announces Foundation Models and Containerization frameworks, etc   apple.com/newsroom/2025/0... · Posted by u/thm
tough · 3 months ago
they mention kata, so is this using kata underneath instead of their Hypervisor.framework?

im confused

https://katacontainers.io/

https://developer.apple.com/documentation/hypervisor

cayleyh · 3 months ago
Repo says it uses Hypervisor.framework on Apple Silicon devices.
cayleyh commented on Sign in with Apple" broke after update–losing data for a third of users   aso.dev/blog/apple-sign-i... · Posted by u/gorniv
j45 · 4 months ago
Is it still the case that offering Apple ID is mandatory on the iOS store?

Forcing users to use certain identity providers while uninformed as a sole point of failure is a challenge.

Apple (or other providers) already have the user with an ID, having the app do the bidding of propagating it's use further is a different issue.

If it was optional, and a convenience/preference that could be added, that would be a different thing.

cayleyh · 4 months ago
It's mandatory if you allow or use other 3rd party auth (ie. Facebook or Google).
cayleyh commented on Young people aren't as happy as they used to be [Global Flourishing Study]   nytimes.com/2025/04/30/we... · Posted by u/marojejian
sQL_inject · 4 months ago
Save this comment for the future: comparison is the thief of joy, and in our connected world, comparison is inescapable.

Young people are berated with constant comparison, whether it be beauty standards, financial success (across generations), or romance.

One day we'll study this period and affirm that globalization, hyper addictive media and pornography come with dark sides.

cayleyh · 4 months ago
This is related to the evaporation of "free time", socializing irl, and hobbies that I've observed vs. my pre-cellphone/pre-internet youth & young adulthood. Not having social media, work emails & slack, and all the group chats enforced periods of quietness, boredom, and being alone. You went out and socialized and did things in public more often just because you were bored and you couldn't just doomscroll and share memes with the group chat. The overall increase in baseline cognitive social load that is entirely digital and interruptive (notifications!!!) instead of planned irl activities just seems to add to general stress levels and decrease baseline mental wellness.
cayleyh commented on Apple M3 Ultra   apple.com/newsroom/2025/0... · Posted by u/ksec
jjtheblunt · 6 months ago
Is there a teardown link available for what you wrote? If so, that’s interesting.
cayleyh · 6 months ago
This has been pretty clear about all Apple chip designs, going back to some of the first A series afaik. They are "unified memory" but not "memory on die", they've always been "memory on package"-- ie. the ram is packaged together with the CPU, often under a single heat spreader, but they are separate components.

Apple's own product shots have shown this. Here's a bunch of links that clearly show the memory as separate. Lots of these modules you can make out the serial or model numbers and look up the manufacturer of them from directly :)

- Side-by-side teardown of M1 Pro vs M2 Pro laptop motherboards showing separate ram chips with discussion on how apple is moving to different type of ram configurations: https://www.ifixit.com/News/71442/tearing-down-the-14-macboo...

- M2 teardown with the chip + ram highlighted: https://www.macrumors.com/2022/07/18/macbook-air-m2-chip-tea...

- Photo of the A12 with separate ram chips on a single "package": https://en.wikipedia.org/wiki/Apple_A12X

- M1 Ultra with heat spreader removed, clearly showing 3rd party ram chips onpackage: https://iphone-mania.jp/news-487859/

u/cayleyh

KarmaCake day55August 1, 2014View Original