[–] 1 point 4 hours ago (1 child)

This HTMX article on security says it’s not ok to call HTMX with external sources.

Where does it say that? It says “Only call routes you control”. As I understood you, you do control those routes.

  • source
  • [–] 1 point 4 hours ago

    7-Zip 26.02, released 2026-06-25, undisclosed vulnerability fixes. Quite a while ago, if you keep stuff up to date.

    They mention Landon Peng as the one finding the vulnerability, but their blog has only a post about a vulnerability fixed in 25.01.

  • source
  • [–] 2 points 1 day ago

    several Member States are now blocking the EU Commission’s proposal to get rid of the cookie banner

    Which ones? Why's there no list here when the "take action" lists by country?

  • source
  • [–] 7 points 1 day ago (1 child)

    The EU never asked for cookie banners. The industry is just really bad at 1. following the law 2. following the spirit of law 3. designing good UI/UX

    So banner data-sharing dialogs don't offer a simple reject button. That's not lawful.

  • source
  • parent
  • context
  • [–] 3 points 2 days ago

    From the linked webpage readme:

    2.1 Classify. Each file is labelled permissive (at least one permissive license detected, no conflicting non-permissive license), no_license (no licenses detected, or only non-license legal texts such as CLAs), or non_permissive. The permissive allowlist follows the Blue Oak Council list plus licenses categorized as Permissive or Public Domain by ScanCode. Files classified as non_permissive are excluded from both released datasets.

    From https://www.bigcode-project.org/docs/about/the-stack/:

    v1.1: The three copyleft licenses (MPL/EPL/LGPL) were excluded and the list of permissive licenses extended to 193 licenses in total. The list of programming languages was increased from 30 to 358 languages. Also opt-out request submitted by 15.11.2022 were excluded from this ersion of the dataset. The resulting near-deduplicated dataset is 6TB in size.

    So MPL/EPL/LGPL are already not part of the dataset.

    So… why were they in there? Was this added for v1.1?

    "one permissive license" - So if my project includes a lib and I include the license file for that for the license notice…?

  • source
  • [–] 4 points 2 days ago

    with a Markdown list with all your repositories you want removed.

    The repo readme linked FAQ says

    You can choose to request either (1) all repos, or (2) you can specify select repos that you own to be removed.

    so "all of them" should be acceptable

  • source
  • parent
  • context
  • [–] 5 points 2 days ago*

    Noteworthy: They crawled only the default branch HEAD and inlined all source content.

    • The file contents are included inline. The decoded UTF-8 source text is embedded directly in the dataset, so it is fully self-contained — you can start training the moment the download finishes.
    • It reflects the state of GitHub in August 2025. The corpus is a direct crawl of GitHub repositories at their default-branch HEAD, capturing roughly two additional years of open-source code compared to The Stack v2.
  • source
  • [–] 20 points 2 days ago* (last edited 2 days ago) (1 child)

    We want to give developers agency over their source code by letting them decide whether or not it should be used to develop and evaluate machine learning models.

    crawled directly from GitHub and built to pre-train code LLMs with full-repository context

    Repositories that opted out are removed from the dataset before each patch release.

    "agency"

    Which AI company will not use v1 which has all of the data but will use later patch releases instead which have less data?

  • source
  • [–] [S] 9 points 3 days ago (1 child)

    Unfortunately, these crawlers instead try to read every single page from Codeberg, no matter if it makes sense. This includes all the different issue filter variants, Git history, as well as the actual files at any point in Git history - even if they are still equal.

    I'm surprised they don't lock some things behind account logins. Is it that hard to decide what would be acceptable to no longer serve without an account?

    Does the full commit and change history have to be available without an account, under these circumstances? If we think about what would be minimally enough:

    • Current branch head tree
    • Tag trees (you can link to release source state and [potentially/manually] compare between releases)

    Not having a change log history nor code change diff seems like a big loss to me, but you have to draw the line somewhere, and that seems acceptable to me.

    To me, Codeberg is in a better position to do so than smaller instances. I already have an account because it has many [relevant/significant] projects, is a home of public good, and is under an appropriate org.

  • source
  •  

    In Brief:

    • Two motions regarding "artificial intelligence" and Large Language Models (LLMs) were voted on among Codeberg e. V. members and passed.
    • We are promising to not use any of your data to train LLM and explain what the planned Terms of Use change mean for 'vibe-coded' projects.
    • We believe that LLMs endanger the free/libre software ecosystem as a whole.

    The blog/news post then goes extensively into where Codeberg understands itself to be in the development landscape, and their voting results. They present their interpretation of the current software development and hardware landscape under the influence of LLMs, and the consequences they take. And how it changes not only development in general, but FOSS collaboration and projects specifically.

    To us, it seems ridiculous to see projects with a single developer and virtually no users consuming as much or even more resources than some of the largest community projects on Codeberg, which operate frugal with CI/CD and storage resources. We do not believe it is reasonable for Codeberg to invest our precious donation money into hosting of large ghost projects.

     

    After loading a project, Cursor attempts to find git binaries at various locations including the current workspace. By creating a repository with a planted malicious git.exe in the root, the IDE will execute it with no user interaction and no prompting of the user. This occurs repeatedly on a cadence.

    [–] 4 points 1 week ago

    They share some real-world/practical example limitations and how they use AI as an accessibility tool.

    The uncomfortable truth is that if we'd done a better job of making the web accessible, if we'd let the web realise its accessibility potential, far fewer people would be turning to AI to compensate now.

    If you want to resist AI, make accessibility part of everything you do, every decision you make, every product you design and build. Remove the need for people to use AI to compensate, and remember, accessibility is resistance.

  • source
  •  

    Andrew Kelley quit his job in 2018 to build a programming language. Eight years later, Zig powers Ghostty, TigerBeetle and Uber's cross-compilation. It's top 5 most admired on Stack Overflow. There's just one thing missing: 1.0. Andrew Kelley explains why.

    Vitaly talked to Andrew about:

    • Why Zig has no 1.0 after a decade, and why that's deliberate
    • Why Zig left GitHub
    • Why Zig banned AI from Zig
    • What makes Zig better than C (and why every other C replacement failed)
    • Andrew’s take on Open Source

    It's a long interview, but I found it very interesting and worth it.

     

    ColorSym is a free, open-source color-identification system that pairs every color with a unique, memorable symbol. When color alone isn't enough to tell things apart, the symbol does the job, so the roughly 1 in 12 men and 1 in 200 women with color vision deficiency can read your components, charts, or UI with confidence.

     

    When using Central Package Management (Directory.Packages.props holds package versions), package version declarations can remain after package references have been removed. The package versions are unused and misleading.

    dotnet nuget why can be used to get a dependency tree across projects to answer how a package comes into the dependency tree. However, the extensive tree list result for a list of version declarations is not viable to simply determine what 'is in use' and what isn't.

    I am sharing my Nushell snippet which answers the question of what is declared but not referenced:

    # List Directory.Packages.props version declarations that are in no csproj
    def "dotnet unused-dirpackprops" [] {
      let defs = open Directory.Packages.props | from xml | get content | where tag == ItemGroup | get content.attributes.Include | flatten | sort --ignore-case --natural
      let refs = ls **/*.csproj | get name | each { open | from xml | get content | select content | flatten | flatten | where tag == PackageReference | get attributes.Include } | flatten | uniq | sort --ignore-case --natural
      $defs | difference $refs
    }
    
    ❯ dotnet unused-dirpackprops
    ╭───┬─────────────────────────────────────────╮
    │ 0 │ coverlet.collector                      │
    │ 1 │ System.Net.Http                         │
    │ 2 │ System.ServiceProcess.ServiceController │
    ╰───┴─────────────────────────────────────────╯
    

    Gaps: In this simple form, only covers the standard csproj package references. Package references included during build through other target or prop files are not covered (probably irrelevant for most users).

    submitted 3 weeks ago* (last edited 3 weeks ago) by to c/uiux@programming.dev
     

    They go over how the web and frameworks decided against horizontal, apart from deliberate emphasis, they go over some desktop layout attempts, failures and successes (more of the same vs navigation), a chapter about (paper) documents as the source, and endless panes now using horizontal.

    From the description:

    Almost every screen we use is a landscape rectangle, wider than it is tall. And on almost all of them, the content moves vertically. Always down.

    This video walks through a wrong question. If mobile scrolls down, why doesn't the desktop scroll sideways?

    The question turns out to be wrong.

    Chapters

    • [00:00] Introduction
    • [01:23] The Web Could, and Doesn't
    • [03:18] The Microsoft Bet - Windows 8 "Metro"/"Modern" failure
    • [06:18] What Makes a Difference - Layouts where horizontal works
    • [09:14] Horizontal Scrolling as Emphasis
    • [10:24] When Horizontal Axis Means Something
    • [12:13] The Document Model
    • [14:06] The Potential of a Glass Plane

    References

    view more: next ›