linuxuserspace, to linux
@linuxuserspace@mastodon.social avatar

Today in User Space
🖥️We host even MORE #Linux #containers
🔑Fall in love with #Passkeys
🦜Look at the #History and #Hack of #Xz
📀And unbreak Open Source #Software

#OpenSource #FOSS #LinuxUserSpace
https://www.linuxuserspace.show/418

linuxmagazine, to security
@linuxmagazine@fosstodon.org avatar

From this week's Linux Update: Matthias Wübbeling shows you how to protect your data and operating system from prying eyes with @veracrypt https://www.linux-magazine.com/Issues/2024/279/VeraCrypt

linuxiac, to linux
@linuxiac@mastodon.social avatar

Distrobox 1.7.2 container wrapping layer promises easier management and improved POSIX compatibility.
https://linuxiac.com/distrobox-1-7-2-enhances-container-management/

89luca89, to opensource
@89luca89@fosstodon.org avatar

Hi all!

Glad to announce release 1.7.2 of

Many bugfixes, and a couple of behavioural improvements that will resolve lots of future issues!

Take a look at the changelog here!

https://github.com/89luca89/distrobox/releases/tag/1.7.2.0

whydoesnothingwork, to linux
@whydoesnothingwork@mastodon.social avatar
kubikpixel, to webdev
@kubikpixel@chaos.social avatar

Buah-eh... until the TypeScript ran the way I had to have it for WebComponents it had taken me forever to search for libraries and I hadn't even started writing the code tests yet… 🤦‍♂️🤷‍♂️

kubikpixel,
@kubikpixel@chaos.social avatar

»Millions of Malicious 'Imageless' Containers Planted on Docker Hub Over 5 Years«

I hope, I'm more secure with @Podman_io and don't must have fear.

🐋 https://thehackernews.com/2024/04/millions-of-malicious-imageless.html


#webdev #docker #itsecurity #imageless #containers #podman #longtime #web #it

fell, to random
@fell@ma.fellr.net avatar

Here's a Flatpak story: The other day, my best friend told me that he had switched to Linux! Arch Linux with KDE Plasma, a noble choice in my opinion. He's a smart guy, but he was having some issues that he couldn't figure out: Firefox' maximise and minimise buttons were missing, drag and drop from archives wasn't working, his selected theme wasn't applied everywhere, and many other small issues I can't remember now.

I tried reproducing his issues on my machine, but everything worked fine for me. We were confused. Is there missing libraries? We went through packages to find out what my system had that his didn't. It was weird, everything was kinda working, but the devil was always in the details, for every single app.

And then we found it: All those applications he had issues with were Flatpaks! He simply didn't pay attention when installing them through the Discover store. He didn't even know what Flatpak meant.

I helped him remove Flatpak from his system and install the system packages instead, and all issues were gone.

Man, Flatpaks suck. How does anyone prefer Flatpaks over system packages? How does anyone think this was a good idea? Stop trying to invent new things to solve old problems and instead go back and fix the problems.

Containers, Flatpak, Immutable distros, it's all wasted effort. There is no magical solution that will solve all our problems. The only way to solve all problems is by solving each problem individually one by one. And that is exactly what countless distribution and package maintainers are doing on your behalf every single day.

And you should appreciate it for fucks sake.

br00t4c, to random
@br00t4c@mastodon.social avatar

'This is my biggest pet peeve': Fast-food customer calls out Wendy's, McDonald's for putting sauces inside bag

https://www.dailydot.com/news/wendys-sauces-in-bag/

adminmagazine, to Kubernetes
@adminmagazine@hachyderm.io avatar

Are you looking to harness the power of containers? Learn more about Docker’s toolset for container development in our free focus guide available for a limited time. Download your copy today! https://mailchi.mp/admin-magazine.com/docker-focus-guide

vwbusguy, to linux
@vwbusguy@mastodon.online avatar

Just in case no one has mentioned it lately, #podman is legitimately amazing.

#Linux #containers

fuzzychef, to FreeBSD
@fuzzychef@m6n.io avatar

Doug shares a bit of the history of Jails vs. #Containers, and talks about porting #Podman to #FreeBSD.

#ContainerPlumbing #OSSNA

89luca89, to linux
@89luca89@fosstodon.org avatar

Excited to announce release v0.5.5 of #devpod !

Lots of new features and fixes both for UI and CLI

Give it a shot!
https://github.com/loft-sh/devpod/releases/tag/v0.5.5

#containers #linux #OpenSource #devcontainers #vscode #Developers

brancz, to random
@brancz@hachyderm.io avatar

We have byte-by-byte reproducible builds of everything at Polar Signals, including container images. We just migrated from podman to buildkit, and it looks like producing provenance information includes build times, ultimately breaking reproducibility. Is there any way to fix this?

linuxmagazine, to Kubernetes
@linuxmagazine@fosstodon.org avatar

Have you seen the latest @adminmagazine focus guide? For a limited time, download this free digital special and go inside the Docker toolset. https://mailchi.mp/admin-magazine.com/docker-focus-guide #Docker #containers #Kubernetes #SoftwareDevelopment #OpenSource #tools #application #FOSS #security

wyri, to Kubernetes
@wyri@haxim.us avatar

Run your own cluster on 's they said, it will be fun they said. So now once every blue moon there is a leader change in the middle of a apply 🤣

ninoles,
@ninoles@hachyderm.io avatar

@badnetmask @wyri

I found the borders between what should be part of IaC and what should be a service deployment operations to be somewhat blurred yet.

Although I think containers are probably here to stay (in likely a even more "invisible" format), the whole orchestration system is too complex and still looking for itself, just like serverless.

89luca89, to Podcast
@89luca89@fosstodon.org avatar
andy_blum, to programming
@andy_blum@drupal.community avatar

Ever worked on projects locally and wished for a more standardized, production-like experience for your team? Try @ddev! I walk you through setting your local up with in my latest article on @lullabot

https://www.lullabot.com/articles/nodejs-development-ddev

br00t4c, to baltimore
@br00t4c@mastodon.social avatar

As Baltimore bridge cleanup begins, fear of environmental contamination looms

#baltimore #containers

https://www.theguardian.com/us-news/2024/mar/30/baltimore-bridge-collapse-environment-hazard

irfan, to linux

There's a huge backdoor ( -2024-3094) allowing remote SSH access (as far as I can tell at this moment) caused by a util called affecting a ton of systems ( and , well not really) and it's causing quite a huge panic. I honestly don't know much about it just yet, but just sharing some pieces to read about the huge vulnerability.

The person who had maliciously planted this vulnerability into xz-utils, Jia Tan, has made at least 750 contributions to the project over the past 2 years. They even have direct push access to the code repo, allowing them to have pushed commits with forged authors. Being "free" from this vulnerability is not as simple as reverting to a previous version due to just how much and how long they've contributed to the project, and people are rightfully suspicious that this person might have hidden other backdoors in xz.

Unlike most other vulnerabilities, it's a lot harder to pinpoint versions affected by this but the most likely case is most systems out there have xz installed on their system that are impacted - which at this moment, the info being thrown around is any version past 5.3.1, 5.4.6, or 5.6.0 (latest is 5.6.1).

🔗 https://access.redhat.com/security/cve/CVE-2024-3094

🔗 https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094

🔗 https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users

🔗 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024

irfan,

As far as I can tell, you're only impacted by this vulnerability only if:

  • Your distro sources/packages xz from their release tarballs rather than through the Git source directly.

  • The payload was only included for the or packaging, so unless your distro uses these - you're probably safe.

  • As far as I can tell, it also only affects x86 systems so based systems should be fine.

  • As far as I can tell, your system needs to be running to be impacted by this, so / should mostly if not entirely be fine....? maybe.


In other news, people are currently investigating and evaluating other projects also actively contributed by the compromised developer, Jia Tan, including .

People are also analysing the dev's commit history to deduce their background from their activity lol. They've been found to push commits during office hours Mon-Fri, every other Saturdays, presumably Public Holidays that seem to align with China's PH, and seems to be on GMT +8 locale.

🔗 https://github.com/libarchive/libarchive

🔗 https://twitter.com/hackerfantastic/status/1773864354439417983

br00t4c, to baltimore
@br00t4c@mastodon.social avatar

Search and rescue operations halted at Baltimore Key Bridge collapse due to threat posed by hazardous material release

#baltimore #containers

https://www.wsws.org/en/articles/2024/03/29/hysm-m29.html

tara, to linux
@tara@hachyderm.io avatar

Something I didn't know: LXD is no longer part of the Linux Containers project

https://discuss.linuxcontainers.org/t/lxd-is-no-longer-part-of-the-linux-containers-project/17593

#containers #linux

sonny, (edited ) to linux
@sonny@floss.social avatar

Anyone in my network interested in research and prototype network portal for Flatpak?

In the long run we are interested in:

• Give more control to users over app network access
• Allow apps that need network access to be considered “Safe”

We expect something like unsharing the network namespace and a bridge on the host for permissions / monitoring.

Boost welcome :boost_love:

1/2 🧵

89luca89, to opensource
@89luca89@fosstodon.org avatar

https://github.com/89luca89/distrobox/releases/tag/1.7.1

Hi everyone!

Version 1.7.1 of is now available, with more bugfixes and also a sprinkle of new features :)

sjvn, to security
@sjvn@mastodon.social avatar

Docker and Chainguard Join Forces to Deliver Secure Containers: https://thenewstack.io/docker-and-chainguard-join-forces-to-deliver-secure-containers/ by @sjvn

I like this pairing of Docker and Chainguard a lot, as both deliver #security-first #containers.

shemjm, to ubuntu
@shemjm@vivaldi.net avatar

anyone here into and ?

I would like to get started with them for development and also for self hosting services like and other stuff.

Just wondering what would be the best setup for a home server that runs Containerised apps on my network?

Maybe an Ubuntu server machine? Or a bunch of Pis?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • kavyap
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • ngwrru68w68
  • Youngstown
  • everett
  • slotface
  • rosin
  • ethstaker
  • Durango
  • GTA5RPClips
  • megavids
  • cubers
  • modclub
  • mdbf
  • khanakhh
  • vwfavf
  • osvaldo12
  • cisconetworking
  • tester
  • Leos
  • tacticalgear
  • anitta
  • normalnudes
  • JUstTest
  • All magazines