HN user

popey

1,942 karma

Developer Relations at Tessl.io

Posts59
Comments158
View on HN
arxiv.org 1mo ago

Position: Coding Benchmarks Are Misaligned with Agentic Software Engineering

popey
1pts1
tessl.io 3mo ago

A Proposed Framework for Evaluating AI Agent Skills

popey
2pts0
tessl.io 4mo ago

A 'high blast radius': Amazon probes surge in outages linked to AI coding tools

popey
5pts0
tessl.io 5mo ago

Skills on Tessl: the package manager for agent skills

popey
1pts0
tessl.io 6mo ago

Kilo bets on context as the bridge between AI coding agents and chat apps

popey
1pts0
blog.popey.com 6mo ago

Malware Peddlers Are Now Hijacking Snap Publisher Domains

popey
3pts0
wimpysworld.com 1y ago

Conventional commit generator using local LLMs

popey
2pts1
github.com 1y ago

Show HN: I made a script to automate removing your Twitter/X followers

popey
2pts0
www.theverge.com 1y ago

Google launches a 'neutral' Chromium development fund

popey
6pts1
github.blog 1y ago

GitHub offering security tools, advice to Open Source Projects

popey
3pts0
gld.mcphail.uk 2y ago

Ubuntu Security Updates Are a Confusing Mess

popey
88pts38
russolsen.com 2y ago

The Best Programming Advice I Ever Got (2012)

popey
4pts0
skilldrick.github.io 2y ago

Easy 6502 – Get started writing 6502 assembly language

popey
3pts0
www.reversinglabs.com 2y ago

NVD delays highlight vulnerability management woes: Put malware first

popey
2pts0
determinate.systems 2y ago

On Community in Nix

popey
54pts11
arxiv.org 2y ago

Generative AI Model Openness Framework Whitepaper

popey
4pts1
www.youtube.com 2y ago

DEF Con 31. Terminally Owned. 60 Years of Escaping [video]

popey
2pts1
blog.hpc.qmul.ac.uk 2y ago

Benchmarking Grace Hopper CPU+GPU "Superchip"

popey
3pts0
popey.com 2y ago

Hand over the PCMCIA Card, Sir

popey
4pts0
popey.com 2y ago

The 90Mph Office

popey
2pts0
popey.com 2y ago

Outdated snap packages – improving Ubuntu snap store

popey
2pts2
popey.com 2y ago

Backup the caravan

popey
34pts6
www.findmycat.io 2y ago

FindMyCat – Open-Source Pet Tracker

popey
615pts368
popey.com 2y ago

Charting EV Car Charging Data

popey
1pts0
determinate.systems 3y ago

The Determinate Nix Installer

popey
250pts76
thepcspy.com 4y ago

What Happened to RSS?

popey
83pts84
do-not-ship.it 4y ago

Do not ship work in progress

popey
15pts6
snapcraft.io 4y ago

How are we improving Firefox snap performance? Part 1

popey
2pts1
www.gamingonlinux.com 4y ago

The deb-get tool helps Ubuntu (and derivative distro) fans grab extra apps

popey
2pts0
medium.com 6y ago

Flutter Linux Alpha with Canonical

popey
12pts4

My worry with the confidence scoring is that it conflates "an agent used this and didn't obviously break" with "this is correct". An agent can follow bad advice for several steps before anything fails. So a KU gaining confirmation weight doesn't tell you much about whether it's actually true, just that it propagated. You're crowd-sourcing correctness from sources that can't reliably detect their own mistakes.

It's why at Tessl we treat evals as a first-class part of the development process rather than an afterthought. Without some mechanism to verify quality beyond adoption, you end up with a very efficient way to spread confident nonsense at scale.

The agents are smart enough to write the evals too.

It's agents all the way down!

Submit a GitHub repo containing skills to Tessl, and it will generate the evals, run them, and present the results. https://tessl.io/registry/skills/submit

The evals and results are all shown, no login necessary, so you can assess them yourself. e.g. https://tessl.io/registry/skills/github/coreyhaines31/market... (click details to see the eval texts).

The vulnerability database search didn't find CVE-2024-9990 - a valid CVE according to NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-9990

I submitted a package-lock.json file to the playground and got a vulnerability report after processing. The sort order next to the pie chart is weird. Medium / High / Critical / Low. I'd expect Critical / High / Medium / Low?

The vuln report ended up in my email spam folder.

I had to hit 'resend' multiple times to receive the verification email. Once I did, I had to either create a new account or login. I don't yet have a password. When I tried to create an account, it said my email was already taken. This onboarding flow seems quite janky.

Is Vulert Open Source software? I couldn't find any links or repos. What does "Join the Open-Source Security Movement" mean in this context?

I submitted two open-source tools. The submission form has a field for 'License' in which the only two options are 'Free' and 'Commercial'. Those aren't licenses. Maybe adjust that field to either say 'cost' or 'terms', or actually have a license field which lets you paste an SPDX entry (or entries) or pick a license from a list.

There certainly used to be a strong push to have internal people use the product a lot more during the development cycle. There was also a real desire to make the devel version actually usable. That fell by the wayside, sadly.

Having your developer workstation break while you have a backlog full of stuff to do, would absolutely make you less motivated to run the developer release. Especially if you're not on the desktop team.

First comment on the video - from the maker of the video - is " FIX (worked for me): write Ubuntu ISO to USB flash with dd"

So, yeah. Okay.

(Speaking as ex-Canonical, and still Ubuntu user. I upgraded my ThinkPad 2 days before release, and it was a catastrophe I had to manually un-fudge with the help of the apt maintainer. It was a packaging problem).

My feeling on this particular release is that it was rushed out, and should probably have been kept back for a month or two. The xz and t64 (2038) issues occupied some unexpected time this cycle.

Also, there used to be a dedicated QA lab which did a whole slew of automated tests. I don't believe that still exists.

Also, also. The Ubuntu community has shrunk, which means fewer people doing QA.

Also, also, also. The guy running the desktop team left the day after the release. Read into that what you will.

Been using and contributing to (and working for) Ubuntu on everything since 2005 or so.

I still use it for everything. I don't have time or inclination to switch. However I have been somewhat convinced to take a look at Nix (packaging) for some of the tools I use. But all my existing systems are fine. So likely when I next get a work machine (next week) I'll probably (if allowed) use Nix to install anything developer related over and above the stock image and supplied packages.

No, the Ubuntu community is pushing Flutter, not upstream GNOME.

Like the desktop app store, the Ubuntu installer is now written in Flutter.

Abstract: Generative AI (GAI) offers unprecedented possibilities but its commercialization has raised concerns about transparency, reproducibility, bias, and safety. Many "open-source" GAI models lack the necessary components for full understanding and reproduction, and some use restrictive licenses, a practice known as "openwashing." We propose the Model Openness Framework (MOF), a ranked classification system that rates machine learning models based on their completeness and openness, following principles of open science, open source, open data, and open access. The MOF requires specific components of the model development lifecycle to be included and released under appropriate open licenses. This framework aims to prevent misrepresentation of models claiming to be open, guide researchers and developers in providing all model components under permissive licenses, and help companies, academia, and hobbyists identify models that can be safely adopted without restrictions. Wide adoption of the MOF will foster a more open AI ecosystem, accelerating research, innovation, and adoption.

I further thought about your feedback and the comments from the owner of exchangerate-API and have removed that section from the blog and mentioned it in a follow-up post.

I appreciate your comments, as they made me think more about that topic.

Back in the day, we had long internal conversations about doing verification 'properly' with government-issued IDs, third-party verification agencies and the like. But that never amounted to anything, sadly.

They might consider it further if the store got to a decent scale (like the contemporaries like iOS, Play and Microsoft). But with "only" 6K applications published, and the money canon being pointed in other directions, I can't see it happening any time soon.

Indeed, the victim, in this case, did mention on the linked 4chan thread that they realised their mistake. While we only see a small part of their world through text communication on forums, I suspect they're kicking themselves in the real world.

Or perhaps not, and they have a ton of other wallets full to the brim with crypto-nonsense.

Sure, there was a bit of guesswork on my part. I could analyse the traffic in more detail, but when I wrote this all up, it was Sunday evening, and I wanted to do the minimum analysis to get a response to the unlucky rube.

I still have the snap, and could test further, but I suspect the endpoint linode boxes will disappear and popup somewhere else sometime.

When I signed up and put in my credit card details, they immediately cancelled my order and completely deleted my account. I had to resort to moaning at them on twitter to get them to unblock me, which they did. Bit of a rubbish start to the journey though.