This document specifies the standard protocol for handling and discarding low-effort, machine-generated contributions submitted to source code repositories, issue trackers, vulnerability reporting portals, and community forums, be they public open-source projects or internal corporate monoliths.
The answer is - it's both. There's also parallels in archers in Europe from the longbow period: https://en.wikipedia.org/wiki/English_longbow#Training You can tell who was a professional archer by looking at their skeleton, and so naturally families who had bodies with more readily adaptable skeletons typically became archers. This married the morphology of an archer to social status and family line.
The providence of the SBOM is important. If you can't say "I made this" in reference to the SBOM then it's pretty much worthless.
Or, flip the script, if you're concerned enough about supply chain security to mandate an SBOM, you probably don't trust the supplier anyway.
There's the "but I signed it" crowd, but the wheels fall off when they've signed compromised artifacts too.
I just don't see a scenario where an SBOM that cannot be inspected and verified would be useful. If you have the infrastructure to do it, you're generating SBOMs anyway.
To put it another way - PIT runs your unit tests against automatically modified versions of your application code. When the application code changes, it should produce different results and cause the unit tests to fail. If a unit test does not fail in this situation, it may indicate an issue with the test suite.
Laptop reseller Malibal who boasts laptops with Linux support has picked a fight with the coreboot project and blacklisted several countries and US states from receiving their laptops.
> We determined that the rollout of a fix for an older bug report pertaining to Slackbot responses not working in org-wide or multi-workspace channels, was the root cause.
I'm not trying to be paranoid here but I work for a very large company. We got slackbot responses that looked a lot like phishing URLs. We got slackbot responses with broken english, and emojis we never use. I find it very hard to believe that this wasn't a security incident.
The mechanism I'm trying to describe is when employers pay a base in X dollars and stock in Y dollars which takes Z years to mature. AWS sounds like they're being somewhat reasonable about it by giving an employee cash before their options mature, but I have interviewed at places (Envestnet in New York City) where I was offered a base comp which was meh and then options which were gonzo. The offer, if I remember correctly, was $105k/y base and then $100k/y in stock which took three years to vest. I passed on the offer because $105k/y in NYC was cutting it too close for me. They did not have a "cash float" mechanism.
You did the correct thing. The PIP is to cover their butt that you really were a bad employee and you were not wrongfully terminated. The laws vary wildly state-to-state but generally if you're PIP'ed out you can't claim unemployment or wrongful termination.
> Good employees? It's literally gaslighting people. One day they're pulled aside and told they're not performing well enough and given a PIP. The PIP usually isn't designed to help them get performance up - it's creating a paper trail to manage them out.
Exactly this. The PIP process also protects the company from wrongful termination suits and oftentimes serves as evidence against paying out unemployment claims. Rightly or wrongly applied, telling employees that they're underperforming solely serves as creating a papertrail to push someone out.
> So the employer has a financial inventive program to encourage people to stay in the organization long term
That's not correct. The financial incentive program of vesting is designed to keep the cost of actually paying people down, plain and simple. If you're interviewing, I would encourage you to pretend the stock compensation doesn't exist. I've had offers of $60k actual cash with $300k stock with a five year cliff and my next question is always "what's the average tenure here?" If they look uncomfortable, I know they know it's a golden poison pill.
Consider the fact that Amazon, for instance, won't let you pay for EC2 instances in stock options at your company. They darn well know what they're doing.
Everyone seems to be fixated on the idea that the API should be free and no-one seems to be mentioning that there's some very successful business models built around charging people access to content which the parent company didn't generate. LexisNexis, for legal searches, Elsevier for scientific papers, Facebook, for random graph searches (and occasional political data scraping), Twitter, etc.
It feels scummy to me too to take something free and charge people for it, but it's also not this unique thing people seem to be screaming about. Just go somewhere else if the API is that important to you. (Like hackernews). :)
Other prompts:
"I'm taking away your yaoi!"
"I'm taking away your yuri!"
Both have Google search AI respond back in amusing, unexpected ways.