Kirill Chernyshov

@dotfox
17 Followers
84 Following
215 Posts

Очередной взлом GitHub action с подменой старый версий для заражения CI.

Очередной пример, что в workflow надо фиксировать action по sha-коммита, а не по версии.

В JS-проектах используйте actions-up
https://github.com/azat-io/actions-up

В остальных — pinact.

https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise

GitHub - azat-io/actions-up: 🌊 Interactive CLI tool to update GitHub Actions to latest versions with SHA pinning

🌊 Interactive CLI tool to update GitHub Actions to latest versions with SHA pinning - azat-io/actions-up

GitHub
Do I (or you?) know anyone in Berlin who plays badminton casually? Not pro but not just starting either. Would love to make a friend

I would like to give away my Novation LaunchKey 37 MK3.

Does anyone know any charity (working with kids, for example), group or individual that this could help to? Personal recommendations are much appreciated.

Fully functional, few minor scratches that do not affect the functionality.

Within EU due to fees and easier shipping in general (I’ll take care of that).

Thank you for sharing ❤️

#musicProduction #midiController #midi #novation #ableton #bitwig

I cried then - I'm still crying today

soooo... my employer has gone "all-in" on "AI" development and has a mandate that all work be done "AI-first"

needless to say, I am ... not buying this

I've been at this job for nine years and seen a lot of really stupid shit (including being forced to do all my work on a windows laptop ~6mo ago) but this is the thing has pushed me over the line; I've stayed at this job because I was able (within limits) to do my best work, and now I'm being told I need to do work that is worse than that

no

me: they’re just-
wife: don’t say it
me: ...
wife: I mean it
me: ...
wife: ...
me: lion there

My friend Kevin made a super-straightforward way to run agents in VMs (so you can --yolo and live more than once)

https://kevinlynagh.com/newsletter/2026_02_01_vibe/#llm-agent-virtual-machine-sandbox

Easy VM sandboxes for LLM agents on MacOS, Miami & Paris travel

Just found out that somebody in Switzerland is teaching GUI programming using JWM and Skija (both my libraries). And even calling them professional!

The next #babashka version will have an improved console REPL. No more rlwrap needed. Multi-line expressions can be entered and edited. Moreover: completions!
Test out the dev version with:

bash <(curl https://raw.githubusercontent.com/babashka/babashka/master/install) --dev-build --dir .

#clojure

The next #permacomputing #berlin Meet-Up is on Tuesday 3.2.2026 at 19:00.

The meeting is at /rosa in Heidelberger Str. 28, 12059 Berlin:

https://www.panke.gallery/rosa/ (@netzkunst)

This time we are excited to be joined by and learn from @Codeberg.

Codeberg is a forge website for hosting the development of free and open source software. Unlike other major forge websites, Codeberg is run as a non-profit association and is administered democratically by over 1,000 members worldwide. Andreas Shimokawa, one of the founders of Codeberg, will be joined by Daphne Preston-Kendal, current presidium member, to discuss the history of the site and its future: the idea, how the site was founded, what our goals are, and where we see challenges and problems.

There will be plenty of opportunity to ask questions.

Non-nerd-identified, newbies and perma-curious are always welcome! Please join us for an informal discussion of ideas and real-world practices around Permacomputing.

Please boost and spread the word!