Damus
Adam :redhat: :ansible: :bash: profile picture
Adam :redhat: :ansible: :bash:
@Adam :redhat: :ansible: :bash:

Adam Miller (He/Him)

https://maxamillion.sh/

Distinguished Engineer at Red Hat

Husband. Father. Leader. Pythonista. Gopher. Rustacean. SysAdmin. Hatter. Texan. Geek. Author. Speaker. Linux nerd. Goose, OpenShell, Ansible, Fedora hacker.

Nothing I say here is representative of my employer, this is my personal account.

Relays (1)
  • wss://relay.ditto.pub – read & write

Recent Notes

Adam :redhat: :ansible: :bash: · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnehyhhpw7qvl9wfet7nt3n63unxm95s7hcfgwqsql28jhjdz6syql8l5mx I don't fully understand your line of questions. Project Lightwell isn't just "we find...
Adam :redhat: :ansible: :bash: profile picture
@nprofile1q... this paragraph from the press release is of note:

"Lightwell operates under Red Hat’s proven upstream-always model, in which security fixes are actively submitted back to the originating open source community for review and acceptance. This ensures commercial protections and community health continually reinforce one another, preventing project fragmentation without risking in-production zero days."
1
Neal Gompa (ニール・ゴンパ) :fedora: · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqpz3mgzmt2xdvvqv5nkd4hfq74rlvhjl2vhefc5pavg6dma4lrvwq6lqkaw The reason I'm asking is because I'm a little burned out from announcements like this that don't necessarily result in things getting better for affected projects. Red Hat isn't the firs...
Neal Gompa (ニール・ゴンパ) :fedora: · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqpz3mgzmt2xdvvqv5nkd4hfq74rlvhjl2vhefc5pavg6dma4lrvwq6lqkaw Are there people actively getting committed to engaging in projects then? Like, where ...
Adam :redhat: :ansible: :bash: profile picture
@nprofile1q... I don't fully understand your line of questions. Project Lightwell isn't just "we find vulnerabilities and report them placing burden on the project" it's "we find them, fix them, and contribute them upstream in a responsible manner" (embargos and such). The value prop for customers is we will also backport those fixes to whatever version of the software (and its dependency chain) that the customer wants/needs. If those versions are still maintained upstream, we'll contribute to those too.
1
Adam :redhat: :ansible: :bash: · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnehyhhpw7qvl9wfet7nt3n63unxm95s7hcfgwqsql28jhjdz6syql8l5mx this paragraph from the press release is of note: "Lightwell operates under Red Hat’s proven upstream-always model, in which security fixes are actively submitted back to the originat...
Neal Gompa (ニール・ゴンパ) :fedora: · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqpz3mgzmt2xdvvqv5nkd4hfq74rlvhjl2vhefc5pavg6dma4lrvwq6lqkaw Are there people actively getting committed to engaging in projects then? Like, where people not only identify flaws but submit fixes and such? We all know how overloaded everyone is get...
Neal Gompa (ニール・ゴンパ) :fedora: · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqpz3mgzmt2xdvvqv5nkd4hfq74rlvhjl2vhefc5pavg6dma4lrvwq6lqkaw So, does any of this Lightwell work translate into helping out open source projects that this winds up covering? There seems to be a lot of fluff in the presser and the product page, so ...
Neal Gompa (ニール・ゴンパ) :fedora: · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqpz3mgzmt2xdvvqv5nkd4hfq74rlvhjl2vhefc5pavg6dma4lrvwq6lqkaw When will AArch64 images be made available? That's the real kicker, since the lack of nested virtualization for ARM makes it impossible to work around deficiencies in the existing runner...
Eric Curtin · 4w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq89nnanf0qr4dmg8f23lft53hmem0fm0up00txyrewh0570jkwt8smhnjch nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqpz3mgzmt2xdvvqv5nkd4hfq74rlvhjl...
Adam :redhat: :ansible: :bash: profile picture
@nprofile1q... @nprofile1q... I'm not sure I follow, it's the same goose package that's in Fedora and CentOS Stream. The only difference is without the x509 cert issued by subscription manager, you can't access the default inference provider that's preconfigured in goose-redhat.
Eric Curtin · 4w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq89nnanf0qr4dmg8f23lft53hmem0fm0up00txyrewh0570jkwt8smhnjch nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqpz3mgzmt2xdvvqv5nkd4hfq74rlvhjl...
Adam :redhat: :ansible: :bash: profile picture
@nprofile1q... @nprofile1q... I honestly don't know. I'm sure there's a public list somewhere, at a minimum it has to exist for CVE data. If you can't find it by web search or your AI agent of choice, I'll ask around next time I'm at my keyboard and get back to you.