Local models exist as part of the solution to privacy invasion. Not saying google has never been nefarious, but the whole point of local models is that your data doesn't leave your device.
HN user
zachrip
I think the accessibility checks only take into account the text color, not the actual real world readability of given text which in this case is impossible to read because of the font weight.
Where did they say the prompt cache is shortened?
That is a way to approximate it, though I'd be curious to know the semantics compared to xhr - would they both show the same value at the same network lifecycle of a given byte?
Fetch has also lacked support for features that xhr has had for over a decade now. For example upload progress. It's slowly catching up though, upload progress is the only thing I'd choose xhr for.
This is a pretty widely known acronym
Oauth with mcp is more than just traditional oauth. It allows dynamic client registration among other things, so any mcp client can connect to any mcp server without the developers on either side having to issue client ids, secrets, etc. Obviously a cli could use DCR as well, but afaik nobody really does that, and again, your cli doesn't run in claude or chatgpt.
Can you clarify what you mean?
I actually think the title is misleading. I'm not sure actual existing deployments are affected? Seemingly just new ones are not working?
I've been using railway a while now, and I've basically never paid them but I would. It's even better than heroku. Super easy to use.
Is the code in the eval also turned into wasm first then? Does this work as a JIT for wasm?
Would like to see the eval version - the dialogue version just seems like normal code with extra steps?
Can you give a real world example?
64 bit ints are a thing in JS for a while now
Why do they obfuscate if they're just going to provide the mappings?
I'm low vision and I have to zoom to 175% on HN to read comfortably, this is basically the only site I do to this extreme.
They're also working on mRNA treatments, there is the LUNA study currently underway. Unfortunately I have a rare variant that isn't covered by this treatment. I'm hopeful but alas I live my life like treatment isn't coming because it's probably not.
I was prescribed vit a palmitate, lutein, and DHA. The vit prescribed was a high dose, like 10k iu per day. I cut back on that dose, I'm going blind but I also need to consider my general health. I have ushers syndrome, not md, but it's a retinal disease (retinitis pigmentosa).
To be clear, this is prescribed as a "we can't do anything else for you" thing, since there is no cure for RP. This may or may not actually help.
Heroku's pricing model made me shy away even from using them for small stuff. Why get comfortable on a stack that disincentivizes success?
They did mention their adhd diagnosis..
The worst part is that I pay for the privilege!
Gmail is dogsh*t at search. It's so bad. I can search the EXACT word I want and not a single email will come up, or it will bring up the most irrelevant emails.
When I found out I am going blind, I traveled around Europe solo for a summer and I found myself at La Sagrada Familia...once inside I almost cried because the light was so beautiful. And finding a special spot to just sit and enjoy an espresso on a sunny day with it in the background is blissful. I'm not religious at all, but many of the nicest buildings throughout my travels were places of worship.
Packages are not auto updated if you have a package-lock. Agreed that post-install, left-pad, etc have been overall problematic tho.
What about if pw or 2fa change, your tokens go on a 24hr cooldown? I think the debug package maintainer even provided his 2fa to the phishing site. Obviously doesn't fix the case where they just exfiltrate and use tokens, but there's no fix that solves all of this, there needs to be layers. I also think npm should be scanning package updates for malicious code and pumping the brakes on potentially harmful updates for large packages.
Do you think companies using node don't analyze supply chains? That's nonsense. Have you cargo installed a rust app recently? This isn't just a js issue. This needs to be solved across the industry and npm frankly has done a horrible job at it. We let people with billions of downloads a month with recently changed password/2fa publish packages? Why don't we pool assets as a collective to scan newly published packages before they're allowed to be installed? These types of things really should exist across all package registries (and my really hot take is that we probably don't need a registry for every language, either!).
I can tell a lot about a dev by the fact that they single out npm/js for this supply chain issue.
It was also packages that in my experience don't often find themselves on the frontend.
It's down, so there's some good news. Probably worth submitting to IC3 as well.
Thanks for sounding the alarm. I've sent an abuse email to porkbun to hopefully get the domain taken down.