Fully agree!
12.02.2025 17:11 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0@pelson.bsky.social
Scientific Python engineer & problem solver. Builder of communities and tools, including SciTools (Iris, cartopy), conda-forge, and former maintainer of matplotlib. Working on accelerator controls at CERN.
Fully agree!
12.02.2025 17:11 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Is this a core GitHub actions infra vulnerability, or for specific actions which were using the branch name insecurely?
06.12.2024 07:48 โ ๐ 3 ๐ 0 ๐ฌ 1 ๐ 0Find it humourous too. The "MLWP" singularity is when we can rely on them for analysing the output as well as generating it... That is when it gets super interesting IMO. For now, I think the only (huge) win is in the speed of the models vs NWP - we will still need NWP research for the foreseeable.
05.12.2024 10:14 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0Sounds like there is a (security) problem with wheel unpacking if you can write outside of the cache root?
13.11.2024 19:56 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0go.bsky.app/LAkKWpR
If youโre a Python person, wave frantically so I can add you to my Python starter pack!
๐ bsky.app/profile/pels...
12.11.2024 12:59 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0๐ I'm a scientific Python engineer & general problem solver. I seem to have some success building open-source communities and tools, including conda-forge and SciTools (notably Iris, cartopy, cf-units), and I was previously a maintainer of matplotlib. Bringing Python to accelerator controls at CERN.
12.11.2024 12:58 โ ๐ 4 ๐ 1 ๐ฌ 0 ๐ 1I agree. Lock files are good from a reproducibility POV, but there isn't an obvious functional improvement on a simple timestamp. I have a prototype which allows you to run a package repo server with the equivalent uv functionality for this reason (like pypi-timemachine, but in the general case)
12.11.2024 12:44 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0