Migrating Renovate bots, while keeping existing PRs updated (2 mins read).

How to migrate between two Renovate bot accounts, in the case you want to do a 'big bang rollout'.
Migrating Renovate bots, while keeping existing PRs updated (2 mins read).
How to migrate between two Renovate bot accounts, in the case you want to do a 'big bang rollout'.
Back in May 2014 Joyent accidentally rebooted an entire datacenter (not just the handful of node as intended!). That incident--traumatic was it was--informed many aspects of the Oxide product. Bryan and Adam were joined by members of that former Joyent team to discuss, commiserate,...
Tracy & Ashley discuss open source funding issues, misaligned incentives, regulatory awareness, and advocacy for contributors.
<p>Actor, writer, and director Rashida Jones feels blank about being Conan O’Brien’s friend.</p><p>Rashida sits down with Conan to talk about tracing her family genealogy, the unanticipated success of Parks and Recreation, and confronting grief in her new Apple TV+ series Sunny. Plus, Conan considers taking his act to Vegas.</p><p>For Conan videos, tour dates and more visit <a href="http://TeamCoco.com">TeamCoco.com</a>.</p><p>Got a question for Conan? Call our voicemail: (669) 587-2847.</p>
Brian Fox is Co-founder and Chief Technology Officer at Sonatype, bringing over 28 years of hands-on experience driving software development for organizations of all sizes, from startups to large enterprises. A recognized figure in the Apache...
Manually triggering a Buildkite pipeline for a fork (1 mins read).
How to trigger a Buildkite pipeline to run on a fork, if you have access to trigger a build.
and talk about a pretty big bug found in CocoPods ownership. We also touch on a paper that discusses the technical debt that open source should have. We discuss what the long term sustainability of open source. There aren't any good solutions for open source today, but talking about these problems is important, we have to start to understand what's going on before we can plausibly discuss solutions. If you're an open source project that needs to put things on pause, or even walk way, that's OK. Show Notes
Shawn “swyx” Wang is back to talk with us about the state of DevRel according to ZIRP (the Zero Interest Rate Phenomenon), the data that backs up the rise and fall of job openings, whether or not DevRel is dead or dying, speculation of the near-term arrival of AGI, AI Engineering as the last job standing, the innovatio...
Good luck to the Lionesses men's team this evening #EURO2024
It's interesting that people keep talking about the Trump incident as a "shocking act" when it really wasn't shocking at all if you've been paying attention to American gun violence and the Republicans' constant calls for political violence and death threats against Democratic politicians and journalists (though these are mainly targeting female, Black and queer journalists and a lot of the targets are women in politics, so maybe straight White male journalists aren't being subjected to nearly as much of this and just don't believe their colleagues). I wish one journalist would just honestly say 'in a not unexpected act of political violence in our landscape of constant gun violence" or something that acknowledged reality. This kind of gun violence is now terribly mundane in the US and Trump and the GOP helped make it mundane.
Week Notes 24#28 (6 mins read).
What happened in the week of 2024-07-08?
Dependency Management Data vv0.101.0 is out 🚀 Check out the release notes at https://gitlab.com/tanna.dev/dependency-management-data/-/releases/v0.101.0
Dependency Management Data's now on Mastodon! (1 mins read).
Announcing the dependency-management-data Mastodon account for automated release announcements (and more?).
Dynamically querying EndOfLife.date data for internal packages with Open Policy Agent and Dependency Management Data (3 mins read).
How you can retrieve End-of-Life data via EndOfLife.date using Dependency Management Data's Policies functionality.
Attached: 1 image #AaronSwartz killed himself because he scraped research data and they aggressively prosecuted him. Now #AI companies say they should scrape our data for free.
Attached: 1 image
If you have a personal website, which I assume you do if you're following me here, you should add yourself to the Internet Phonebook while the call for websites is still open! They even have an "indie …
Attached: 1 image Wake up everyone, a new response header just dropped
Literally last night I was reading [this post on r/Rick and Morty] (https://www.reddit.com/r/rickandmorty/comments/1dvcja9/comment/lbmkw2k/) (some spoilers) and:
Political candidates that survive assassination almost always win
Is 😬😬 re US Politics
Git was designed to be distributed but there is a lot of gravity around GitHub. What does the model look like for a business that encourages you to run your own git server and what does the backend for gitea.com look like?
Conferences & CFPs🇮🇱 GopherCon Israel, Sept 9 @ Tel AvivCFP open until Jul 15🇦🇺 GopherCon AU, NoCFP open until Sept 15🇮🇳 GopherCon India, Dec 1 @ Jaipur🇩🇪 Fyne Conf, Sept 20 @ BerlinCFP open until Aug 16🇸🇬 GopherCon Singapore, October TBDCFP open until Aug 19Go 1.23 draft release notes⏲️ Blog:...
Welcome to Kaizen 15! We go deep on the big Changelog News redesign, give shout outs to folks who’ve helped us along the way &amp; Gerhard takes us on his journey to turn Jerod’s pipe dream into a reality!
Content warning: transphobia, cis people who vote Labour read this, ukpol
89 things I know about Git commits (7 mins read).
Some of the things I've learned over a decade of Git usage, and working on writing good commit messages.
Paul Copplestone, CEO of Supabase (the meme-lord himself), joins the show to take us on the journey of Supabase leading Postgres for life, and how it all starts with Postgres as the base-layer substrate for the entire Supabase platform. They’re laser focused on the drive ahead, not the rear-view mirror. Disclosure: Ada...
This week on The Business of Open Source, I spoke with Joe Duffy, co-founder and CEO of Pulumi.We kicked off the conversation by talking about why Pulumi is open source in the first place — a mix of Joe’s long-standing interest in open source and a feeling like a developer tool like Pulumi just...
Join us for an insightful discussion on the intricacies of Developer Relations in the open source world. Our panel of experts will delve into key differences between open and closed source platforms, the unique challenges and opportunities in open source DevRel, and the impact of AI tools on the community. Gain practical insights and hear success stories from industry leaders.
Anyone know if there's a way of tweaking the new #FirefoxNightly Android layout?
Not a fan of the two row format they've now got
Really hate that the address bar only shows the domain, not the full URL, until you tap into it 😕
This week on The Business of Open Source, I spoke with Tyler Jewell — for the second time, now. Last time I spoke with Tyler, he was an investor at Dell Technologies Capital, he’s since taken over as CEO of Lightbend. We talked about a lot, but there was a definite theme to our conversation:...
Carol Lee (Clinical Scientist) shares her research on code review anxiety. We dive deep into her recent research paper “Understanding and Effectively Mitigating Code Review Anxiety”. We get into all the nooks and crannies of this topic — common code review myths, strategies for coping, the need for awareness and self-r...
Gareth Greenaway from the Salt project joins us for a trip down memory lane with configuration management and why open source projects have changed over the past decade.
Dependency Management Data is now a lot easier to work with when using Software Bill of Materials (3 mins read).
Announcing an improved model for interacting with SBOMs, removing the need to understand the Repo Key up-front.
Visit our homepage - cupogo.dev - for links to our Patreon, Store, past episodes, and more.🚢 Releases1.23 RC1 released1.22.5 & 1.21.12 pre-release announcementProposals1️⃣ Accepted: cmd/gofmt: change -d to exit 1 if diffs exist🆕 Accepted: list deprecations and newer available dep versions 🪢...
Attached: 1 image 10 July - Second OpenUK Digital Meet-up! Join Dr Dawn Foster, James Humphries and host Jamie Tanna, in their talks on high-profile forks, their impacts and the challenges of launching a fork. Register https://www.meetup.com/openuk/events/301139203/?utm_medium=referral&utm_campaign=share-btn_savedevents_share_modal&utm_source=link #openuk #digitalmeetup #opensourcelondon
and talk about the latest polyfill.io mess. Apparently someone took over a very popular project and started to serve malware. First XZ, now this. What does it mean for open source? We don't have any answers, and it's hard to even talk about this problem because it's so big. The thing is though, even if we can't fix open source, it's here to stay. Show Notes
Week Notes 24#27 (5 mins read).
What happened in the week of 2024-07-01?
Adam &amp; Jerod discuss the news! But first, we discuss how you can keep up with the software world (good question, Tyler Boyd!) On the docket: Developer job postings trend, the Ladybird Browser Initiative, the Polyfill.js supply chain attack &amp; is the future self-hosted?
Go 1.22.5 & 1.21.12 releasedConferences🇮🇱 GopherCon Israel, Sept 9 @ Tel AvivCFP open until Jul 15🇦🇺 GopherCon AU, NoCFP open until Sept 15🇮🇳 GopherCon India, Dec 1 @ JaipurNew proposal: include abandoned packages in list of deprecationsBlog post: gRPC: The Good Parts by Kevin McDonald🍪 New...
Dependencies! We need them, but how do we use them effectively and safely? In this week’s episode Kris is joined by Ian and Johnny to discuss the polyfill.io supply chain attack, the history of dependency management and usage in Go, and the Go Proverb that “a little copying is better than a little dependency”. Of cours...
Attached: 1 image Can not stop laughing at this
If there's one thing I've learned as a browser-engine dev: Everything is political! The most mundane things (e.g. how we answer "what time is it?") has the weight of historical politics behind it. Software freedom is a political project, you can't "leave politics out of it"! It makes a lot more sense to ask "how is this political?" than "is this political?". Because it is!
Technology is political. If your project or organisation has a “no politics” clause, you’re saying you’re happy to exclude people whose very existence is political in our societies. It’s only defensible if you’re coming from a place of privilege where the dominant politics are to your advantage so you can take them as given. There is no such thing as “no politics”; there is only “no politics other than the politics of the status quo that I benefit from, which I’ve internalised as normal.”
The “innovation token” model for selecting technologies is bad, and here’s why.
🗳️✅ Get the fuckers out of power
If you view changing documentation to use generic “they” instead of “he” text as too political to be acceptable, then I’m sorry but your project is deeply unserious. “The generic user is a man” is a deeply political statement, and hiding behind “we’re apolitical” is bullshit. https://hachyderm.io/@Mara/112718515777208791