Why is it that I keep seeing "everyone should pin their GitHub Actions versions to a SHA because that's the secure way to do it" and not "GitHub should build tooling that creates and manages Actions lockfiles by default"? Am I just missing that version and only seeing the former one boosted?
Today's @nprofile1q... call starts in five hours (at 9PM US Eastern time). Join us to talk about contribution sprints, conference websites, and all sorts of other community organizing topics. https://www.conferencechats.org
If you're eligible to vote in the DSF elections, please check your inbox, set aside some time to read each candidate statement, and vote before the due date of 23:59 on November 26, 2025 AoE. It's important, and it won't take you a ton of time.
Do you know of examples of a software library's test suite catching a bug in its upstream dependencies? I've seen a few of these over the years, and I'd like to put together a small list. Things like:
- A programming language implementation's test suite uncovering a bug in other implementations - A library's test suite uncovering a bug in the language implementation itself - A framework addon's / extension's test suite uncovering a bug in the framework
When @nprofile1q... and I joined an episode of @nprofile1q... a bit ago (https://fosstodon.org/@djangochat/114268050638878390), we talked a bit about carrying the excitement and energy from a conference into post-conference projects. It's fun watching some of that manifest as people join projects as contributors, start their own projects, and generally continue their enthusiasm following #PyConUS.
The CFP due dates for both @nprofile1q... and @nprofile1q... are ~2.5 weeks away and fast approaching. I should probably get working on those outlines if I want to get a proposal ready in time.