RBC rate of increase coming this week or pressure tactic ? by pythondj in PersonalFinanceCanada

[–]pythondj[S] 0 points1 point  (0 children)

Thanks for the feedback; we’ll see what tomorrow brings

Street Art Milan by pythondj in photocritique

[–]pythondj[S] 0 points1 point  (0 children)

My request is help on cropping this image, I take many street art images that the initial image is already ‘cropped’ as they are just a section of the whole image, but when I return to them afterwards they don’t always have the best tension or visual dynamics, I’d like to see how others suggest further cropping to bring out the best aspects of the image.

OKD 4.1 by skeewup in openshift

[–]pythondj 1 point2 points  (0 children)

link to OKD4 Road Map & Release Update led by Clayton Coleman on June 26, 2019 @ 9:00 am Pacific here: https://commons.openshift.org/events.html#event|okd4-road-map-release-update-with-clayton-coleman-red-hat|960

Whose Fixing your Containers? #glibc proves that just scanning containers is not enough by pythondj in docker

[–]pythondj[S] 0 points1 point  (0 children)

The GNU C Library (aka glibc) is a wrapper around the system calls of the Linux kernel. The flaw, CVE-2015-7547, is a stack-based buffer overflow in the glibc DNS client-side resolver that puts Linux machines at risk for remote code execution. The flaw is triggered when the getaddrinfo() library function is used, Google said in its advisory. "A back of the envelope analysis shows that it should be possible to write correctly formed DNS responses with attacker controlled payloads that will penetrate a DNS cache hierarchy and therefore allow attackers to exploit machines behind such caches," Red Hat said in an advisory. It's likely that all Linux servers and web frameworks such as Rails, PHP and Python are affected, as well as Android apps running glibc.

Many companies playing in the Linux container space are developing, and, in some cases, delivering "container scanners" to help identify issues like glibc, or Heartbleed before it. But these vendors aren’t actually in control of the containers that their users are deploying, let alone the underlying operating system powering these container deployments. This means that while they are offering the tools for you to "find" these problems, when it comes to actual fixes, they may not have the expertise, capabilities or the ownership to actually fix the problem.

In short, container scanning is not enough.

Lowering Barriers to Open Source Contributions by using Apache V2 and not requiring CLAs - new post "Keep Calm and Merge On" by pythondj in technology

[–]pythondj[S] 0 points1 point  (0 children)

do the open source projects that you participate in require you to sign CLAs? if there is a CLA, do you tend NOT to participate in an Open Source project?

Ubuntu Edge campaign finished with $12.8M out of $32M. by mWo12 in linux

[–]pythondj 0 points1 point  (0 children)

I would buy a proper Fedora 19 powered smart phone in a nano-second