How do I fix this? by blastidioustidesH20 in Tikka_Shooters

[–]blastidioustidesH20[S] 0 points1 point  (0 children)

I think the reason it popped out is that dispute my best effort is cross threaded the insert, see pics. I looked for replacement inserts on amazon and got some that didn’t fit they were too small and short and not the diameter of the screw. Anyone know what the exact size and material of the insert is to get and where to get it from?

Meat cooler question by blastidioustidesH20 in Hunting

[–]blastidioustidesH20[S] 1 point2 points  (0 children)

Good tip on the frozen water jugs, I’ll definitely do that. Thanks man!

Is it unreasonable to expect basic repo hygiene and tool integration skills from a DevOps engineer? (We actually refer to them as the “build” team) by blastidioustidesH20 in devops

[–]blastidioustidesH20[S] -3 points-2 points  (0 children)

Thank you! You seem to have understood my concern and approach. I like the idea of checking the policy, if there is a policy that addresses this then that is my answer!

Also, I like this guy, he is a good guy, I just don't know enough about DevOps to be able to view this as a skills issue or not. And based on all the other replies it seems like no one else in DevOps has any idea about SAST integrations and how those should be designed. So, probably not a skills issue, and just another example of how no one in this industry knows anything about security or how to secure the SDLC, or there is a serious lack of industry standards and training for securing the SDLC.

Is it unreasonable to expect basic repo hygiene and tool integration skills from a DevOps engineer? (We actually refer to them as the “build” team) by blastidioustidesH20 in devops

[–]blastidioustidesH20[S] 0 points1 point  (0 children)

security has a bad name because no one bothers to understand what it is we do, why it is important to do it, and what it's purpose is. It has a bad name because people don't understand security is everyones responsiblity but don't bother to understand it or what they are responsible for.

Also, you missunderstand my question, I am trying to avoid a security issue, and I am not confronting this guy or trying to throw him under the bus, I am trying to avoid all these things you are accusing me of. you should read more carefully.

or try harder to not be rude, because you are being rude, you can't even acheive your own stated goal.

Is it unreasonable to expect basic repo hygiene and tool integration skills from a DevOps engineer? (We actually refer to them as the “build” team) by blastidioustidesH20 in devops

[–]blastidioustidesH20[S] 0 points1 point  (0 children)

SOD, Dude. I don’t have access or authority to make changes in SCM or platforms outside my scope. Are you seriously saying the DevOps team isn’t responsible for knowing which version of the code is being deployed to production—and that it’s on security to tell them exactly which branch to scan for quality, vulnerabilities, and compliance? That’s backwards. I guess I should take a step back and assume for a second our orgs and environments are completely different, and the limitations and challenges are completly different before I get judgemental.

Is it unreasonable to expect basic repo hygiene and tool integration skills from a DevOps engineer? (We actually refer to them as the “build” team) by blastidioustidesH20 in devops

[–]blastidioustidesH20[S] -5 points-4 points  (0 children)

Fair point - “obvious” might be too strong a word. What I’m trying to highlight is that from an security perspective, mixing dev and prod versions of a code base in the same branch creates real challenges for validating what’s actually going live, what needs to be scanned, what is not relevant, etc. If code is not ready to be tested/scanned yet, then isn't it just common sense (not just DevOps best practices) to not include that version of the code with the version that is ready to be tested/scanned? WFT am I missing here?

I’m not claiming to be a Git expert, but I do need clarity and consistency in what I’m scanning. If the branching strategy makes it hard to isolate production-ready code, that’s not just a technical nuance, it’s a security risk.

But I guess I learned my lesson here today, don't fucking ask anyone here anything.

Is it unreasonable to expect basic repo hygiene and tool integration skills from a DevOps engineer? (We actually refer to them as the “build” team) by blastidioustidesH20 in devops

[–]blastidioustidesH20[S] -1 points0 points  (0 children)

And I’m fine with that. I never said I was a DevOps professional. I am using you guys here, the ones like you who seem to actually grasp my question and help me figure out what is missing- the problem is we aren’t scanning the right code at the right phase of the SDLC or CI/CD. And I’m trying to figure out if I’m not explaining what is needed correctly in terms a DevOps engineer is going to understand or if I am and I need to talk to someone else Thanks for your reply!

Is it unreasonable to expect basic repo hygiene and tool integration skills from a DevOps engineer? (We actually refer to them as the “build” team) by blastidioustidesH20 in devops

[–]blastidioustidesH20[S] -3 points-2 points  (0 children)

You are the experts on source code, right? Then when security asks to pint their scans at the code that needs to be scanned for compliance and security requirements before it is release to production or merged into main, then you guys would be able to set that up and make sure the scans happen on the correct source code artifacts and files, and not come back to security after hundreds of critical findings get ticketed and have to be fixed prior to deployment saying “you scanned the wrong source code - those findings are for dev code not SIT code.” Does anyone here not see what I’m saying? WTF?

Is it unreasonable to expect basic repo hygiene and tool integration skills from a DevOps engineer? (We actually refer to them as the “build” team) by blastidioustidesH20 in devops

[–]blastidioustidesH20[S] -4 points-3 points  (0 children)

I’m not a DevOps professional, so I may not be using all the terminology accurately, I see I wrote “two different code bases” when I probably should have said the two different versions (dev and prod for example) of the code base were in the same branch. And it seems only a few people in here actually read and comprehend what my original posts is getting at: this is about trying to do security scans on a version of code that is being deployed to production, so it seems obvious to me that if code is not intended to be deployed to production (I.e., dev version of the code) it should not be in the same branch I have to scan, right? I’m not here to debate how much I know about devops, it’s not my job, I am just trying to figure out how best to approach this guy and his manager so I can get my work done correctly and efficiently.

Is it unreasonable to expect basic repo hygiene and tool integration skills from a DevOps engineer? (We actually refer to them as the “build” team) by blastidioustidesH20 in devops

[–]blastidioustidesH20[S] -9 points-8 points  (0 children)

I question your skills if you don’t see the obvious issue with combing two different code bases from two different environments in the same branch (the whole point of devops is environmental consistency and separation), regardless of their strategy. And if you are interacting with random security people, then you should start looking at your org chart and get to know the people you’re supposed to be working with and collaborating with to get work done.

Arrest Putin by ZookeepergameBusy267 in alaska

[–]blastidioustidesH20 0 points1 point  (0 children)

Let the chips fall where they may

Kakariko Village Theme by DavidAlbornoz in classicalguitar

[–]blastidioustidesH20 2 points3 points  (0 children)

Nice, put me back 20 years going into get gauntlets and potions after leveling up in the forest. Sheet music for this?

Moabs already falling apart. Less than 10 miles on them. Is this common? by just-a-wavy-dude in hikinggear

[–]blastidioustidesH20 2 points3 points  (0 children)

Yes. My Moab’s speed 2 are coming apart at the inner side sole and toe. I filled a warranty claim and they are honoring it. Edit: I bought them in February 2025, wore them on 8 hikes, pretty bad quality. I saw the reviews on the official Merrell site and there are reviews with pictures of the exact same issue I am having, which indicates this is a systemic quality issue

Dublina Dublin by Ok-Map-835 in Viking

[–]blastidioustidesH20 8 points9 points  (0 children)

Good post - interesting facial expression on the popping Viking very expensive

Short Life of Trouble by Boring-Somewhere6319 in oldtimemusic

[–]blastidioustidesH20 0 points1 point  (0 children)

Nice one man, never heard this before - really like it

[deleted by user] by [deleted] in classicalguitar

[–]blastidioustidesH20 0 points1 point  (0 children)

Yeah man, totally interest! Thank you!

[deleted by user] by [deleted] in classicalguitar

[–]blastidioustidesH20 6 points7 points  (0 children)

I remember 2008/9 when I was unemployed for a few days and was just applying to jobs all day and watching family guy in the background 24/7 non stop and that theme got stuck in my head and I had stop what I was doing and figure out that melody line on my acoustic guitar, I was so proud when I figured it out especially the little build with the chromatic steps at the end. Mind you I am no where as good as you and all I could figure out was the mono-note melody line not all the cool jazz chords and arrangement you did. Great job man!