• Drop #467 (2024-05-15): Wonkish Wednesday

    Today’s proper Drop covers how Trail of Bits collaborates with Alpha-Omega and OpenSSF to enhance Homebrew’s security with cryptographically verifiable attestation; it also looks at Nimble and Lance V2 as Parquet replacements, and points to a sober piece on “The Heat Death of the Internet”.


  • Bonus Drop #47 (2024-05-05): Publisher DoS Recovery Edition

    The Drop is off of hiaitus! Today, we cover Debian’s efforts to address the “2038 problem” by transitioning to a 64-bit time_t, the benefits of the REST Client extension for VS Codium, and the value of curated, opinionated lists of programming tools and libraries.


  • Drop #454 (2024-04-18): Happy ThursdAI!

    Today’s AI-focused edition of the Drop discusses the usefulness of a Rust-based disk-usage tool, dua, for managing space occupied by AI models. It also explores a concerning development where LLM agents can autonomously exploit one-day vulnerabilities and a new experimental extension, DuckDB VSS, that accelerates vector similarity search using DuckDB’s new fixed-size ARRAY type.


  • Drop #425 (2024-03-12): Typography Tuesday

    Three fontastic resources await intrepid Drop readers! The Canva Engineering Blog discusses the complexities and security concerns of font processing software and formats, highlighting vulnerabilities like CVE-2024-25081 and the importance of tools like OpenType-Sanitizer for protection. Fontpreview is a command-line tool for quickly previewing fonts, while UNCUT.wtf is a free typeface catalogue featuring 152 contemporary…