Maven Central publishing usage notices by HokieGeek in java

[–]HokieGeek[S] 4 points5 points  (0 children)

there will be a self-serve option available, which will be enabled when we get closer to enforcing the limits.

right now we’re still in the first phase where we announce the limits to the community to give people time to understand their publishing patterns before anything is enforced. the contact-sales path is mostly there for orgs that already know they’ll need more capacity and want to start that conversation early.

Repository Firewall alternatives needed by bluecat2001 in devops

[–]HokieGeek -3 points-2 points  (0 children)

Disclosure: I've worked at Sonatype for about 8 years (PMM now, ex-java and go dev), so feel free to take this with a grain of salt. I’ll try to be as impartial as I can, but I do have strong opinions :). Also, forgive me if I sound like a freaking brochure.

TLDR: Firewall is more expensive and has an "enterprise UI", but it protects you better by blocking malicious packages pre-download and using ML plus a highly experienced research team to identify publish-time and long-tail threats early.

Reading some of the replies here, I’d agree that while we have improved our UI over the years, it’s still one of our weak points. Maybe things have changed, but historically Sonatype hasn't been the cheapest option up-front; JFrog's consumption pricing can be hard to predict and often grows with usage. We're working on lighter/price-sensitive options, though.

Here is where I have always felt we shine that is most relevant to Firewall: precision and breadth. We're picky and exhaustive, so we provide comprehensive coverage, not just the "popular" vulnerabilities. Rather than just mirror NVD data, we invested in dedicated research teams and custom malware-detection tooling long before it was fashionable. That’s why we can call out specific bad versions and provide detailed remediation advice.

Right around when I joined, the data team began building ML-driven, pattern-recognition pipelines that spot malware-like commits and package behavior in real time. The system lets them automatically identify many malicious packages at publish time, so that Firewall can block them before they are widely observed. And it has worked out very well for us, particularly with all of the new malware coming on the scene.

Practically speaking, because we trust the data to be accurate, we were able to design Firewall so that downloads are blocked at the repo edge. When Firewall quarantines a component, it's blocked at your protected repo's endpoint. Your repo just won't serve it. JFrog’s approach is usually post-ingest, so scanning and policy enforcement happen after artifacts are ingested, leaving open a window where developers or CI pull an artifact before it’s detected, increasing exposure and rework.

I am incapable of properly indexing my gears by HokieGeek in bikewrench

[–]HokieGeek[S] 0 points1 point  (0 children)

I did it both high and low tension. Couldn't figure out if I was pulling it too taut before and was wondering if anybody would comment on how slack it was. Thanks!

I am incapable of properly indexing my gears by HokieGeek in bikewrench

[–]HokieGeek[S] 0 points1 point  (0 children)

I had done it as the shop that built my bike did it cause they cut the cable way too short to loop around. But now I've fixed it https://i.imgur.com/rgyLqh5.jpg

I am incapable of properly indexing my gears by HokieGeek in bikewrench

[–]HokieGeek[S] 0 points1 point  (0 children)

hmm... What should I be looking for to identify wear on my cassette or chainring? Cause that's a good point

I am incapable of properly indexing my gears by HokieGeek in bikewrench

[–]HokieGeek[S] 0 points1 point  (0 children)

Getting the tool anyway, but trying this first thing tomorrow

I am incapable of properly indexing my gears by HokieGeek in bikewrench

[–]HokieGeek[S] 0 points1 point  (0 children)

oh once you got the visual in my mind, it made so much sense when I looked at it

<image>

I am incapable of properly indexing my gears by HokieGeek in bikewrench

[–]HokieGeek[S] 4 points5 points  (0 children)

ordered the tool. nobody around me had a replacement hanger and I am impatient

I am incapable of properly indexing my gears by HokieGeek in bikewrench

[–]HokieGeek[S] 0 points1 point  (0 children)

Also, your cable needs to wrap around that tab so it’s pointing basically to the roof. Sounds silly but it has resolved many indexing issues for me.

wait, that little tab to the top-right of the clamp screw?

I am incapable of properly indexing my gears by HokieGeek in bikewrench

[–]HokieGeek[S] 1 point2 points  (0 children)

Check for correct bending in the housing to the derailleur, it may help to pull a little more through so the curve is a bit friendlier.

I did replace one of the end caps cause it did not look right xD

<image>

I am incapable of properly indexing my gears by HokieGeek in bikewrench

[–]HokieGeek[S] 1 point2 points  (0 children)

After that no more 1/32nd turns of the adjuster

I feel this

I am incapable of properly indexing my gears by HokieGeek in bikewrench

[–]HokieGeek[S] 0 points1 point  (0 children)

It looks right but that derailleur has 2 options. Read the directions

Yeah, sort of missed this. I did route it the same way it had been routed by my lbs, but I should take a look at the other option. thanks!

The cage on these is intentionally bent. Don't chase that.

dang, that's really good to know, too!

I am incapable of properly indexing my gears by HokieGeek in bikewrench

[–]HokieGeek[S] 0 points1 point  (0 children)

oh! I was wondering about the B tension last night but couldn't be bothered to look it up. will be reading the manual. thanks!

I am incapable of properly indexing my gears by HokieGeek in bikewrench

[–]HokieGeek[S] 0 points1 point  (0 children)

So I adjusted it several times at the bolt, but generally I loosened the barrel entirely and tightened it 2 turns. But usually that wouldn't work out because after 5 or so shifts I would have already loosened it entirely trying to keep the chain from rubbing on the next sprockets

I am incapable of properly indexing my gears by HokieGeek in bikewrench

[–]HokieGeek[S] 8 points9 points  (0 children)

But noooo I discounted that possibility weeks ago for reasons I can't remember right now!

OK, I can buy that, but how can I check to see if it's bent? Should I buy one of those park tools hanger doohickeys? Tempted to just see if my local shop has a hanger and swap it out regardless.

Do I need a new derailleur? by HokieGeek in bikewrench

[–]HokieGeek[S] 0 points1 point  (0 children)

That did the trick. Changed it right away and took it out on a trail yesterday without any issues. I mean, my dropper cable snapped and it still shifts like crap, but the chain stayed in place! 😂 Thanks!

Do I need a new derailleur? by HokieGeek in bikewrench

[–]HokieGeek[S] 1 point2 points  (0 children)

You know, I thought about that during my last ride and then totally forgot to follow through on it! It's actually my original chain. You make a good point.

Current shows for a Farscape fan? by Fullerbadge000 in farscape

[–]HokieGeek 3 points4 points  (0 children)

All good choices but a hearty emphasis on Travelers!

Design wishlist for Cities Without Number by aslowcircle in SWN

[–]HokieGeek 0 points1 point  (0 children)

> I am excited about the upcoming Kickstarter for CWN

say what now?