

Whedonisms
What the heck is that? I liked buffy and firefly, so use those as an example if you could.


Whedonisms
What the heck is that? I liked buffy and firefly, so use those as an example if you could.


“you’ve got mail”?
“When Harry met Sally”?


I watched Lord of the Rings, which seems to be one long movie broken into pieces, and I don’t think it sucks as much as the formula suggests for a 720-min runtime.


That’s difficult. Openssh is coded in C, not js.


The world-first part must be the wind-power thing.
We’ve had small offshore data centers for years, passively cooled but powered by nuclear energy.
(And if you’re still not getting the joke, let’s discuss how a nuke sub would cool its massive computing power. Big boats are like floating data centers; submarines even more advanced. )


why avoid Flatpak? I get snap or AppImage,
Objectively, they all frustrate validation the same. When comparing with a SLSA3-compliant setup where every installed artifact has a signed checksum in a signed bundle from a signed resource on a signed repository, and the endpoint to this is readily available from something like authenticated SNMP into the single source of truth, they all tends to compare poorly.
The chart below completely ignores that Debs are consolidated into a single source of truth as well, and I feel violating SSoT should cost significantly because of dependency holes when artifact registry is incomplete, but SLSA doesn’t care about that part.
| Ecosystem / Format | Estimated SLSA Level | Update Reliability / Model | Trust Chain & Provenance Comments |
|---|---|---|---|
| (withheld) | 3–4 | Very high; repo-based, transactional updates | Strong: signed packages + signed repo metadata + central DB; distros enforce reproducible builds. |
| OCI containers (hardened pipeline: cosign + Tekton/in-toto) | 3 | High if using automated CI/CD and policy enforcement | Strong if you use signed images + non-falsifiable provenance; this is rare but achievable. |
| DEB (distro repos) | 2 | High; repo-based, APT handles dependencies | Medium: repo metadata signed, but per-package signatures not mandatory; weaker checksum chain. |
| Flatpak runtimes (Flathub) | 2 | High; centralized runtimes, predictable updates | Medium: signed OSTree commits; build infra more centralized, but not full end-to-end provenance. |
| Flatpak apps | 1–2 | High; repo-based, automatic updates | Mixed: OSTree signing helps, but build provenance varies by publisher; no uniform SLSA guarantees. |
| Snap (strict confinement) | 1–2 | High; centralized store, auto-updates | Centralized signing by Canonical, but opaque build pipelines; trust is “trust the store operator.” |
| OCI containers (typical public images) | 0–1 | Medium; pull-latest model, tag drift common | Usually unsigned; mutable tags; no guaranteed provenance—trust is mostly social and reputation-based. |
| Snap (classic confinement) | 1 | High; same store/auto-update model | Same store trust, but classic snaps bypass sandbox; even more reliance on publisher integrity. |
| AppImage | 0–1 | Low–medium; ad-hoc self-update or manual downloads | Almost no chain of custody; signatures optional; no central repo or provenance expectations. |
| npm (JavaScript) | 0–1 | High frequency, but low reliability of safety; semver + lockfiles | Registry accounts can publish arbitrary tarballs; no default signed provenance; transitive deps explode risk. |
| PyPI / pip (Python) | 0–1 | Similar to npm; pip + requirements/lockfiles | Tarballs/wheels from arbitrary maintainers; no mandatory signing; provenance work (e.g., PEP 740) is emerging but not standard. |
| Composer / Packagist (PHP) | 0–1 | Good tooling, but same “trust the registry” model | Packages pulled from Packagist/VCS; no mandatory signatures; dependency graph trust is social, not cryptographic. |
| CPAN (Perl) | 0–1 | Mature ecosystem, but manual/legacy in many flows | Historically minimal provenance; mirrors and authors are trusted by convention, not by SLSA-style attestations. |
| Other language registries (RubyGems, crates.io, etc.) | 0–1 | Similar to npm/PyPI; lockfiles help reproducibility | Central registries, but no default SLSA provenance; integrity is mostly TLS + registry operator trust. |


Can I have yours?


Yep. I wasn’t a fan of raw fish BEFORE I took the fish-farm job for uni cash. The experience did not sway me positively!


Sea-bugs are awesome. Can I have yours?


I’ll downvote that too.
It seems to #bothsides an issue via a lot of hyperbole, and risks straw-manning one side just for a favourable comparison.
I don’t colour myself a tankie, but I do live in a more socialist country than America - low bar, such as it is. I sense I’m not in a position to properly understand how your argument can make sense, but the kneejerk comparison I feel needs some explanation before just throwing that smelly fish out there.
It’s not cut-and-dried, but presented as such. It’s not helpful and relevant by itself. Thus, downvote.


That’s the nokia hardware they installed win mobile on?
I was looking forward to a good nokia candybar phone, but gave up when they were bought and the hardware went under a win OS.


They tried; it must’ve been 4 times. But unless it’s a sure thing, they’ll give up.
I worry they don’t know how to compete on a level ground, slowly building trust and business on success after success.
shit got all fucked up because you added a third party repository
Dependency hell is always, always, self-inflicted.
apt is only SLSA1 or 2 anyway, so there’s a lot more wiggle room.
Parking lots need to be the 6 levels underneath a soccer field anyway.
Life will adapt
Life will recover:
https://www.ecoportal.net/en/foxes-use-solar-farm-as-natural-habitat/20424/
What motivated your change?
My laptop finally died on me. […] I’ve got Ubuntu on my desktop
No. What motivated the change? Your laptop dying was correlative and not causative.


It’s funny that we’ve had SLSA4-compliant package managers for 25 years, but we leave juniors un-mentored and this is what they build as they self-teach … over and over and over.


swimming in rancid meat juice
You’re aware the ocean has a number of fresh corpses - fish, whales - as well as a bunch of faeces in it at any moment, right? :-P


is anyone in Canada making a bourbon-like whiskey?
yay! One’s in stock near me, and we’re already out near there tonight so it’s easy. I may have to try new things.
It’s weird that I grew up in the okanagan - picked grapes for summer cash; ugh - but I never figured they’d do Corn in Vernon. Then again, Shelter Point (yowza) opened up a few meters from the house of a grad-class chum, so I have a trend of moving away from places just as they’re getting ‘spiritual’. 🙃
Looking forward to trying the BRBN tonight if the BCLDB has it. Thanks for the pointer!
logos? Like regular pluralization?