blog.rust-lang.org

The Rust Security Response WG was notified that Cargo did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user.

5
0
blog.rust-lang.org

The Rust Security Response WG was notified that Cargo did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user.

2
0
https://thisweek.gnome.org/posts/2023/07/twig-106/

Update on what happened across the GNOME project in the week from July 21 to July 28.

4
0
https://thisweek.gnome.org/posts/2023/07/twig-106/

Update on what happened across the GNOME project in the week from July 21 to July 28.

2
0
blog.rust-lang.org

Hello again from the Rust Leadership Council. In our first blog post, we laid out several immediate goals for the council and promised to report back on their progress. It has been about a month since our first update so we wanted to share how it's going and what we're working on now.

1
0
https://thisweek.gnome.org/posts/2023/07/twig-105/

Update on what happened across the GNOME project in the week from July 15 to July 22.

3
0
https://thisweek.gnome.org/posts/2023/07/twig-105/

Update on what happened across the GNOME project in the week from July 15 to July 22.

3
0
Firefox still doesn't have PWA support
  • Mr_Figtree Mr_Figtree Now 100%

    so I can totally ditch chromium/electron

    GNOME Web isn't Chromium-based and does support PWAs, so it might work for your usecase.

    3
  • My office has automatic faucets in the bathroom and I've started sticking my hands under the faucet at home and wondering for a second where the water is.
  • Mr_Figtree Mr_Figtree Now 100%

    Someone I know recently switched from automatic bathroom lights to manual ones. Remembering to turn them on isn't an issue, but months later everyone still forgets to turn them off.

    11
  • blog.rust-lang.org

    The Rust team is happy to announce a new version of Rust, 1.71.0. Rust is a programming language empowering everyone to build reliable and efficient software. What's in 1.71.0 stable ========== * C-unwind ABI * Debugger visualization attributes * raw-dylib linking * Upgrade to musl 1.2 * Const-initialized thread locals

    53
    2
    blog.rust-lang.org

    The Rust team is happy to announce a new version of Rust, 1.71.0. Rust is a programming language empowering everyone to build reliable and efficient software. What's in 1.71.0 stable ========== * C-unwind ABI * Debugger visualization attributes * raw-dylib linking * Upgrade to musl 1.2 * Const-initialized thread locals

    52
    0
    blog.rust-lang.org

    The Rust team is happy to announce a new version of Rust, 1.71.0. Rust is a programming language empowering everyone to build reliable and efficient software. What's in 1.71.0 stable ========== * C-unwind ABI * Debugger visualization attributes * raw-dylib linking * Upgrade to musl 1.2 * Const-initialized thread locals

    3
    0
    What hostname do you use for server? home.box or home.local?
  • Mr_Figtree Mr_Figtree Now 100%

    And .box has been registered as a generic TLD now, so you could run into external .box domains.

    10
  • Dutch government starts own Mastodon instance as reaction to the instability of Twitter
  • Mr_Figtree Mr_Figtree Now 100%

    They're not going to have open signups. It's government agencies only. Not that there's technically anything stopping Germans from joining the PR departments of our government agencies…

    25
  • So I tried signing up for Twitter to do a little trolling there...
  • Mr_Figtree Mr_Figtree Now 92%

    So what you're saying is that Twitter successfully kept out a bad actor.

    It's a shame that most of the users they have left are also in that category, but hey, they seem to be working on it.

    12
  • bevyengine.org

    Bevy is a refreshingly simple data-driven game engine built in Rust. It is free and open-source forever! --- Since our last release a few months ago we've added a *ton* of new features, bug fixes, and quality of life tweaks, but here are some of the highlights: * **Screen Space Ambient Occlusion (SSAO)**: Increase scene render quality by simulating occlusion of "indirect" diffuse light * **Temporal Anti-Aliasing (TAA)**: A popular anti-aliasing technique that blends the current frame with past frames using motion vectors to smooth out artifacts * **Morph Targets**: Animate vertex positions on meshes between predefined states. Great for things like character customization! * **Robust Constrast Adaptive Sharpening (RCAS)**: Intelligently sharpens renders, which pairs nicely with TAA * **WebGPU Support**: Bevy can now render on the web faster and with more features using the modern WebGPU web API * **Improved Shader Imports**: Bevy shaders now support granular imports and other new features * **Parallax Mapping**: Materials now support an optional depth map, giving flat surfaces a feel of depth through parallaxing the material's textures * **Schedule-First ECS APIs**: A simpler and more ergonomic ECS system scheduling API * **Immediate Mode Gizmo Rendering**: Easily and efficiently render 2D and 3D shapes for debugging and editor scenarios * **ECS Audio APIs**: A more intuitive and idiomatic way to play back audio * **UI Borders**: UI nodes can now have configurable borders! * **Grid UI Layout**: Bevy UI now supports CSS-style grid layout * **UI Performance Improvements**: The UI batching algorithm was changed, yielding significant performance wins

    1
    0
    UNOFFICIAL poll about OPT-OUT metrics proposal
  • Mr_Figtree Mr_Figtree Now 100%

    You'll still have the people who are opposed to any telemetry at all, but I think that would do a lot to alleviate the concerns.

    1
  • France passes bill to allow police remotely activate phone camera, microphone, spy on people
  • Mr_Figtree Mr_Figtree Now 100%

    These are all fine in the US, but in other countries not carrying proof of identity can get you into some trouble, as can refusing to talk to the police. Know your local laws.

    61
  • Firefox 115 can silently remotely disable my extension on any site
  • Mr_Figtree Mr_Figtree Now 100%

    Ah, I see. Looks like that should enable people to take individual domains off the list, too, if they want their extensions to work on just some of them.

    2
  • www.theregister.com

    One's a bit raw and touchy, but the other is vintage stuff, brought up to date

    0
    2
    Firefox 115 can silently remotely disable my extension on any site
  • Mr_Figtree Mr_Figtree Now 100%

    Is there a list somewhere of these “quarantined” domains?

    3
  • Firefox 115 can silently remotely disable my extension on any site
  • Mr_Figtree Mr_Figtree Now 100%

    uBlock Origin seems to be included in the whitelist, so I'm sure the point of this isn't to show you ads.

    7
  • The Current Challenges With Using Linux On Airplanes
  • Mr_Figtree Mr_Figtree Now 100%

    A FreeRTOS derivative has gone through the effort of getting certified for safety critical applications, but that derivative is sadly proprietary. Even if FreeRTOS itself can't meet that bar, though, the work wouldn't have to start from scratch.

    1
  • This misleading, GPT generated article is on the first page of Google results for "ECMAScript 2023"
  • Mr_Figtree Mr_Figtree Now 100%

    Looking at it optimistically, maybe we'll start seeing some improvements in documentation as everything else becomes useless.

    1
  • Is there an easy way to tell what instance a post is from?
  • Mr_Figtree Mr_Figtree Now 100%

    Kbin enhancement script to the rescue! One of its features is showing the domain on federated posts and users.

    1
  • https://thisweek.gnome.org/posts/2023/06/twig-101/

    Update on what happened across the GNOME project in the week from June 16 to June 23.

    2
    0
    Lemmy.world officially has 40k users, making it the #1 non-bot lemmy instance!
  • Mr_Figtree Mr_Figtree Now 100%

    kbin.social is a Kbin instance, not a Lemmy instance, so it's not stopping lemmy.world from being the biggest Lemmy instance.

    1
  • Looking for 64-bit RPi4 Server OS Distro suggestions
  • Mr_Figtree Mr_Figtree Now 100%

    Both of the RHEL clones, Rocky Linux and AlmaLinux, build images for the Raspberry Pi 4. Those should fit your needs nicely if you're looking for something familiar and stable.

    1
  • California restaurant had fake priest hear workers’ confessions, Labor Department says
  • Mr_Figtree Mr_Figtree Now 100%

    Yeah, a real priest understands that he is expected to die rather than reveal anything he heard in confession, while this guy was passing everything along to the boss.

    2
  • Mr_Figtree Now
    32 29

    Mr_Figtree

    Mr_Figtree@ kbin.social