HN user

taleodor

154 karma
Posts103
Comments56
View on HN
worklifenotes.com 6d ago

The IDE Is Now Just a Large Attack Surface

taleodor
3pts0
worklifenotes.com 1mo ago

CI/CD Security Principles in 2026

taleodor
2pts0
worklifenotes.com 1mo ago

The last line of defense must not be AI

taleodor
2pts2
www.youtube.com 1mo ago

ReARM: Governing AI Coding Agents Demo [video]

taleodor
2pts0
rearmhq.com 1mo ago

ReARM 26.06.5: Agentic Coding Guardrails and DevOps

taleodor
2pts0
worklifenotes.com 2mo ago

When the Paradigm Shifts: A Zero-Trust Model for AI Agents

taleodor
1pts0
www.youtube.com 3mo ago

Why QA and Cyber Security Matter More Than Ever [video]

taleodor
1pts0
medium.com 3mo ago

Release Management in the Agentic Era

taleodor
2pts0
worklifenotes.com 3mo ago

Time to Start Treating Dev Machines as Untrusted

taleodor
3pts0
rearmhq.com 3mo ago

Using Evidence Platform as CI/CD Security Layer

taleodor
4pts0
rearmhq.com 4mo ago

ReARM 26.03.59: More CycloneDX Usage in APIs and Better Bear Enrichment

taleodor
2pts0
rearmhq.com 4mo ago

New Major ReARM Release Brings Real-Time Widget of Most Vulnerable Components

taleodor
1pts0
worklifenotes.com 4mo ago

Want to Survive Current Tech Era – Learn to Be a Good QA

taleodor
3pts1
rearmhq.com 5mo ago

Show HN: ReARM – Release-Level Supply Chain Evidence Platform

taleodor
3pts0
worklifenotes.com 5mo ago

Towards Perfect Vulnerability Management System

taleodor
1pts0
rearmhq.com 5mo ago

ReARM 26.01.173: VDR Export, Finding Changelogs, and More

taleodor
1pts0
www.youtube.com 6mo ago

How to Search Releases by Security Findings Using ReARM [video]

taleodor
1pts0
rearmhq.com 6mo ago

Dockerfile.sbom

taleodor
1pts0
rearmhq.com 7mo ago

Reliza and ShiftLeftCyber Announce Integration of SecureSBOM Signing into ReARM

taleodor
2pts0
www.youtube.com 7mo ago

How to use ReARM to check if Shai-Hulud 2.0 infiltrated your dependencies [video]

taleodor
1pts0
www.youtube.com 8mo ago

Vulnerability Analysis in ReARM [video]

taleodor
1pts0
worklifenotes.com 8mo ago

SBoM Diffing: Next Frontier for Supply Chain Security

taleodor
2pts0
github.com 8mo ago

Show HN: Oolong – Lightweight Transparency Exchange API Implementation

taleodor
2pts0
rearmhq.com 8mo ago

New Major ReARM Release Includes Vulnerability Analysis Functionality

taleodor
2pts0
worklifenotes.com 8mo ago

AI Proof Businesses

taleodor
1pts0
worklifenotes.com 10mo ago

NPM Has Become a Russian Roulette

taleodor
4pts1
rearmhq.com 10mo ago

New ReARM Release: SPDX and User Groups

taleodor
1pts0
rearmhq.com 10mo ago

New ReARM Release: Sarif, CycloneDX VDR/BOV, and Artifact Versioning

taleodor
1pts0
github.com 11mo ago

ReARM Announces Alerts on SBoM Dependency Changes

taleodor
1pts0
www.youtube.com 1y ago

Windsurf Planning Mode at Reliza [video]

taleodor
1pts0

We support this with ReARM - https://rearmhq.com/

It's an open-core product (there is an option to self-host FOSS ReARM CE yourself) that gives you per-release vulnerability posture. It consumes various artifacts (e.g., SBOMs) generated during CI phase and does scan on them, doesn't need access to source code. Apart from SBOMs it consumes files with findings from other tools (reports in SARIF format, VDRs, VEXs).

It's not about that we should drop LLM completely from the mix, but something like AI -> LLM control -> old-school classifier control -> script / human oversight is the way. If something has potential to cause millions in damages, it should be subjected to human oversight (likelihood / impact analysis needs to happen early in the system design).

Frankly I don't buy atrophy argument at all. I (and I believe many other people) switched multiple frameworks and languages over the years. I.e., I was an expert in Chef more than 10 years ago, and nowadays I hardly remember anything about it. Calling this a cognitive decline is a significant stretch.

If you're afraid of cognitive decline - try to get to proper orchestration using multiple agents. That's a fun exercise.

I have completely opposite experience. To me Traefik is the easiest thing to work with on the market. It should be even easier now to setup using Agentic AI.

This link you are sharing is an example of low quality journalism or propaganda - whatever you want to call it.

I'll give you some context - in 1948 Egypt declared war on Israel, which ended with a cease fire in 1949. From this context, it should become obvious that Israeli espionage operations in Egypt in early 1950s are warranted.

Even Avi Shlaim referenced in your article admits that it was mainly Arab nationalists who were driving the Jews out. These reactions are very similar to modern day shootings at Jewish schools in Canada or airport pogrom in Dagestan - https://www.bbc.com/news/world-europe-67258332

Pro-Palestinian crowd is unable to admit that they have imperfections and blames all these events on Israel / Zionists as well (I read a lot of forums from both sides). A common reference is "they made us do it" / "it was a Zionist school / plane". Drawing parallels between today and 1950s, it becomes very clear that it's old propaganda playbook trick. I would go even further and say it's a millenia-old antisemitism, where people would blame everything on Jews / witches / etc.

Now, back to the article you shared - "undeniable proof" - is an interview of a 89-year old man, who did not even hold the leadership role in an underground Jewish cell and did not claim first-hand participation in any of the events. More so, his interview is full of contradictory statements, including dates and attributions of who did what - I encourage you to do more research on that.

So on one hand, you have this "undeniable proof", and on the other hand you have many well documented actions of Arab nationalists and Iraqi government. And you choose to believe (even contradictory to Avi Shlaim) that it's all Zionists.

Next, thinking logically, there was no need for Mossad to do false flag operations, because there were enough actions by Arab nationalists and before 1950 there was a policy in place by Iraqi government banning Jews from emigrating to Israel - like if Jews didn't want to emigrate, why would they ban this? Once they lifted the policy, everybody left. This is very similar to USSR where millions of Jews left in early 1990s after the fall of the USSR. Probably propagandists will soon be explaining that this was Mossad false flag operations or some other Zionist tricks - I wouldn't be surprised.

It would be fantastic to see a single Israeli/Palestinian state with a slight arab majority, but everyone with their voice represented, all living in peace and harmony.

Single state is a construct of few people with far-left views. They already tried something like that in USSR where they put for example Armenians and Azerbaijanians in the same state (and many other smaller examples within USSR). Look what happened.

I don't see even a single chance this will ever work, also it has zero support on the ground by both sides.

More generally, the demographics around the Eastern Mediterranean have changed surprisingly little since the Bronze Age.

This type of claims only shows lack of understanding of history as a science. It is actually impossible right now to make claims about this with any significant degree of confidence.

A lot of people are in lower income brackets and don't have the means nor understanding where and how to leave the country.

Another big factor is that many countries have essentially closed borders for Russian nationals - i.e. US is now deporting those who are fleeing - https://www.theguardian.com/us-news/2023/mar/18/biden-admini...

There are also few people who do want to stay in Russia and try to fight Putin there (like Navalny or Yashin).

Part of the functionality we built in Reliza Hub is to generate automatic version increments that are guaranteed to be unique on each request and have special rules for versioning on feature and release branches.

My usual versioning convention for a feature branch is BRANCH_NAME.PATCH

Generally, I believe getting versioning right requires an external versioning service that ensures uniqueness and routing between branches. Otherwise there will always be "gotchas".

These were exactly my thoughts when I first saw the critics of this book some time ago (btw I don't see much added value in this publication relative to what Alexey Guzey wrote initially).

Like I agree that removing the bar is bad, but Walker's takeaway is pretty much the same as that of the original paper from which the graph is taken - the paper states that predictor for injury is sleeping less than 8 hours, which Walker points out as well.

Deploys at Slack 6 years ago

This is part of what we're doing with Reliza Hub - https://relizahub.com (note, we're in a very early stage).

Apart from tracking deployments, we're really focused on tracking bills of materials and communication between Business and Tech teams.

First and foremost - it's not about you. Millions of people are getting laid off daily now due to the exceptional circumstances.

It's ok to feel down for some time, but it's important to understand the broad picture and not take this personally - regardless of what you were told.

Now, regarding leadership resources, I would recommend to start with the following (in this order):

Moneyball (movie), books: The Goal, The Phoenix Project, The Mythical Man-Month, The Hard Thing About Hard Things, The Culture Code and in-between those - various Simon Sinek videos.

If you read this far, you should be able to continue finding materials on your own from here ;)

Best of luck!