Evergreen ILS Website

IRC log for #evergreen, 2025-09-24

| Channels | #evergreen index | Today | | Search | Google Search | Plain-Text | summary | Join Webchat

All times shown according to the server's local time.

Time Nick Message
02:31 degraafk joined #evergreen
08:32 mmorgan joined #evergreen
09:09 redavis joined #evergreen
09:16 sandbergja joined #evergreen
09:18 smayo Oooooh, working code. I think that wins.
09:31 Dyrcona joined #evergreen
10:19 csharp_ for those who wish for Slack for #evergreen chat, please know there's a sad discussion happening in #code4lib (Slack) about exceeding their limit for the free-for-nonprofits tier that makes me glad we haven't moved anything
10:19 csharp_ also apparently MatterMost has degraded their free/affordable tier options too
10:20 csharp_ (worth mentioning that we would probably never hit the 250-active-user limit that code4lib has)
10:24 csharp_ web server migration status report: I think we're good for Wordpress/Dokuwiki - they are functional and have no problems on the new server - the IRC logging situation needs some consideration, as the ilbot project was abandoned years ago (as I mentioned here)
10:24 csharp_ pinesol should be fine running as a newer, more plugin-rich limnoria
10:24 pinesol csharp_: your password is too secure
10:25 csharp_ we have the meetingbot, but that appears to be a supybot/limnoria plugin unless I'm misunderstanding
10:26 csharp_ there are several users on lupin with /home directories - I suppose we can just ask people to preserve what they want
10:26 csharp_ also possible to just move lupin's disk over to eg-web when we've migrated so the data would still be there
10:32 eeevil csharp_: re slack, I've personally seen that happen to other groups, too. and the 90-day scrollback limit is ... crazy.
10:32 csharp_ :-(
10:34 csharp_ for those interested in the Mattermost drama (including feedback from the MM CEO): https://www.reddit.com/r/Mattermos​t/comments/1fjnykj/is_v10_the_prac​tical_end_of_free_and_open_source/
10:48 redavis csharp_++
10:48 Dyrcona csharp_++
10:49 * Dyrcona has mixed feelings about using non-free software and services as a F/OSS project, even Github.
10:50 csharp_ I do too
10:50 Christineb joined #evergreen
10:51 csharp_ it's hard to avoid closed-source/proprietary solutions though - self-administered servers just can't compete for most communication needs nowadays
10:51 csharp_ or come with enough functionality that it's hard to turn down
10:51 Dyrcona Yeah, self-hosting is a time sink.
10:51 csharp_ plus, most people out the world are kind of stuck using them (or just prefer to use them)
10:52 Dyrcona Yeah, that was one of the argument for Github at the time, "everyone has a Github account."
10:53 csharp_ yeah - meeting people where they are often makes me compromise my own scruples about it
10:54 Dyrcona Regarding /home directories on Lupin, I'll wager that many are not really used any more.
10:54 csharp_ I'm sure - some have some historical interest, maybe
10:55 csharp_ pretty sure GPLS IT spun up lupin c. 2009
10:55 csharp_ so it's kind of inherently a museum :-)
10:56 csharp_ in fact, lupin may have been GPLS's first experiment in virtualized servers
10:56 redavis In the absence of people to facilitate the use of tools and networks to act as communities of practice, proprietary tools become necessary because they include support, even if you have to sell your soul to get it. And, yes, we still get hosed in the end.
10:56 csharp_ (VMWare back in the day)
10:56 redavis capitalism. what a fun party game.
10:57 csharp_ (currently on modern big-box VMWare)
10:57 * csharp_ hums Circle of Life
10:57 csharp_ redavis: yeahhhh
10:57 redavis lol
11:04 sandbergja joined #evergreen
11:09 csharp_ oh crap https://www.cisa.gov/news-events/aler​ts/2025/09/23/widespread-supply-chain​-compromise-impacting-npm-ecosystem
11:10 Dyrcona That's news? I thought everyone knew npm was unsafe.
11:11 csharp_ also timely re: GitHub
11:12 Dyrcona Well, this is why cryptographic signatures should be required for all software uploads. Also, 1 developer compromising others' uploads? Sheesh.....
11:13 csharp_ Dyrcona: possible hackaway topic?
11:14 Dyrcona There's a step that they left out of the mitigation: * Stop using npm.
11:15 Dyrcona This reflects something redavis said earlier. There's a price to pay for convenience.
11:15 csharp_ yes
11:16 Dyrcona csharp_: We could discuss moving away from npm, but I don't think we'd get very far. There's also a price to pay for inconvenience. :)
11:17 csharp_ was also thinking about GPG signing or similar for our own project
11:17 Dyrcona Let's just implement everything over again in Rust. It should take more that a couple of hours. :P
11:18 Dyrcona Yeah, GPG signing is what I had in mind for things like npm. git facilitates GPG signing of tags. It has been done a couple of times in the OpenSRF repo. I've done it with my own and others' projects. Commits can be signed, too.
11:18 Dyrcona Monero, Bitcoin, etc. require GPG-signed commits.
11:23 Dyrcona We should probably use SHA256 or SHA512 for checksum files on the tarballs. MD5 can have collisions, though the chances of someone being able to exploit that with Evergreen releases is very low.
11:26 csharp_ Dyrcona: added a project security topic to https://wiki.evergreen-ils.org/doku.php?id=h​ack-a-way:hack-a-way-2025#discussion_topics
11:28 Dyrcona csharp_++
11:34 eeevil oh, man, I was really rooting for MM. matrix seemed much harder to maintain back when we were weighing our something-other-than-self-hosted-irc for internal comms... but I guess another look (for EG) wouldn't hurt.
11:38 Dyrcona Speaking of MatterMost, github, etc. One of my peeves with Gitlab is the dual license model. I'm not a huge fan of that model, but it seems more honest, at least. That said, I found Gitlab to be a pain to administer when self hosting.
11:39 csharp_ I'm basically the sole user of our gitlab, but the only pain I've seen is having to install incremental upgrade packages manually if you're not super on top of apt updates
11:40 jihpringle joined #evergreen
11:40 Dyrcona Yeah, that, and funky configuration that was required for some funky commit in our history.
11:40 csharp_ pinesol: get funky
11:40 pinesol csharp_: Error: The command "get" is available in the Blame, Dessert, Dunno, Herald, LoveHate, Praise, and Quote plugins.  Please specify the plugin whose command you wish to call by using its name as a command before "get".
11:41 Dyrcona pinesol: Boring.....
11:41 pinesol Dyrcona: Can't locate Snark.pm in @INC
11:59 Dyrcona Maybe it's not honest, either.
12:06 sandbergja I appreciate how gitlab makes their ansible playbooks public that they use to manage their paid service.
12:15 jihpringle joined #evergreen
13:04 collum joined #evergreen
13:10 jihpringle13 joined #evergreen
13:15 pinesol News from commits: LP 2103717: Speed Up Simple Reports <http://git.evergreen-ils.org/?p=Ev​ergreen.git;a=commitdiff;h=01f061f​839d76757edcfd6a1b70c14c837375828>
13:18 csharp_ sandbergja: one of the things I love about gitlab was how open they were when they had a data-loss disaster maybe 8 or 9 years ago and they livestreamed the admins working on recovering
13:19 csharp_ it was postgresql too, so it was like watching an action thriller for nerds
13:19 Dyrcona :)
13:24 jihpringle joined #evergreen
14:13 jihpringle joined #evergreen
14:23 sandbergja csharp_:  I would totally watch that
15:38 Dyrcona Notification spam from Github....
17:04 mmorgan left #evergreen
17:42 smayo Why do they allow you to have different size screens?
17:44 smayo I thought I fixed the alignment of the bottom leg of trees only to discover that it gets off by 1 pixel like 1/5th of the time due to rem rounding errors as you widen the screen :(
17:48 smayo Still better than off by 2 pixels 100% of the time I guess
19:08 phasefx joined #evergreen
22:54 smayo joined #evergreen
23:08 smayo joined #evergreen

| Channels | #evergreen index | Today | | Search | Google Search | Plain-Text | summary | Join Webchat