vault-conductor 0.3.1 is now available also on the Arch User Repository (AUR)! 🎉 aur.archlinux.org/pa... 1/3
Francesco Pira
@pirafrank.bsky.social
Human problem solver. Rust and AI. I shape my own tools. Working as XR Tech Lead to make simulators for specialized operators a reality
🐢 Windows 11 File Explorer Is Slow. I Built the Fix I Needed. Windows 11 File Explorer has been slow for so long that Microsoft is finally taking a serious look at the problem. 1/9
Wow! 🌑☀️ A total solar eclipse is coming to Europe, and it’s happening soon! Don’t miss this rare celestial event: tune in LIVE to ESA’s broadcast on 12 August, 19:30-20:45 CEST and watch it unfold in real time from anywhere in the world.
I wanted to avoid the repetitive tasks of publishing on AUR. So I built AURA. It generates `PKGBUILD` + `.SRCINFO`, resolves checksums, signs, and pushes to AUR via GitHub Actions. Read it in the second article of the automation series: fpira.com/blog/2026/... #ArchLinux #AUR
🎓 Two new certifications completed! I’ve earned the Nebius Agentic AI Builder Certification and the Nebius AI CloudOps Engineer Certification. Stay tuned for me to put them into practice in a new upcoming project, which will use the Nebius ecosystem to come to life.
🚀 `jekyll-ai-related` v0.3.0 is available. The release adds content-fingerprint caching that allows skipping unnecessary OpenAI API calls. It also includes Supabase migration support, new tests, refreshed docs, and fixes. github.com/pirafrank... #Jekyll #Ruby #OpenSource #AI
🔥 Qwen just announced Qwen3.8-Max and Qwen3.8-27B. - May be the strongest in its class - Runs on ~17 GB RAM/VRAM - Brings frontier-level capabilities within reach of consumer hardware. Open-weight AI keeps getting better. 👉 openlm.ai/qwen3.8/ #AI #LLM #LocalAI #Qwen
🤖 Ever struggled with tool releases? poof, vault-conductor, and more to come. The list of tools I am developing does not seem to end, so I have automated new version releases. The first of a 3-part series about that is out! Read it here: fpira.com/blog/2026/...
🚀 vault-conductor v0.3.1 is out, with 🛡️ security fixes and 📦 dependency updates The SSH Agent that provides SSH keys stored in Bitwarden Secrets Manager got a maintenance update. What's new? Find it here github.com/pirafrank... or read on. #Rust #Bitwarden 1/3
It looks like Arch User Repository is still undergoing maintenance. AURA pipelines have been since last night failing with message: "The AUR is down due to maintenance. We will be back soon."
Update AUR Package · pirafrank/aura@7922053
AURA - Arch User Repository Automation. Automated AUR repository of my CLI tools. Generates PKGBUILD from Jinja template and creates its .SRCINFO - Update AUR Package · pirafrank/aura@7922053
github.com
Well, 'Technically'... they are wrong. #Rust lang is not 'super difficult' to write, unless you compare it to Python or... English! Its syntax may not be the best part, but I do not find it harder than C++. Funny how a newsletter talks Rust like its 2016.
Saturday morning triaging dependabot issues for vault-conductor. RUSTSEC ones have priority. Checking them to plan a maintenance release. Curious about how's going? Check it here! github.com/pirafrank... #BuildInPublic #vaultconductor #Rust #Bitwarden #RUSTSEC
Issues · pirafrank/vault-conductor
An SSH Agent that provides SSH keys stored in Bitwarden Secrets Manager - Issues · pirafrank/vault-conductor
github.com
Cross-Origin Storage API: stop downloading twice. @morello.dev explains a proposed standard that stores large files by their SHA-256 hash, so origins share one device cache instead of downloading duplicates. #performance #browser morello.dev/blog/cro...
Google has recognised there might be some ways to abuse this new capability bsky.app/profile/gbru...
BREAKING: Google has rolled back its tool less than a day after it launched. Updated story coming soon.
🚀 Klarna is now powering Apple’s new hardware leasing program replacing the old iPhone Upgrade Program. Proof that the European FinTech story is now mature, and scale-ups have turned into resilient companies powering global financial infrastructure. www.businesswire.com...
💻 Tune-in-the-middle attack 😾 PoC of using LoRA as an offensive technique: fine-tune a model just enough to insert a malware in code it will generate. Imagine this behind an OpenAI-like API. The model behaves as you would expect 99.9% of the time. 1/3
I've just discovered another pre-compiled gem: glab-tui! An easy to use TUI for GitLab/GitHub, built on top of glab/gh CLI tools, and written in Rust. If you already have those two, download glab-tui and it just works! How to install it as fast in your terminal? 1/3
There's a new Rust framework for full-stack web apps, Topcoat. It's made by same devs behind tokio-rs. Now,v0.5.0 is out. It features: WebSockets, Server-Sent Events, Datastar support, emailing and more! Know more
Release v0.5.0 · tokio-rs/topcoat
Release notes Everything that changed since v0.4.0. The release carries breaking changes, so it goes out as 0.5.0. If you are upgrading an existing application, read Breaking changes first; every e...
github.com
GNOME needs help! The person behind GNOME Security Tracker is stepping down. And after August 1 security disclosure shorten from 90 to 30 days. If you know someone in the community wanting to step in, please tell maintainers so. Thank you!
GNOME Security Coordinator Steps Down, Changes Vulnerability Reporting Rules | It's FOSS posted on the topic | LinkedIn
For six years, one person has been manually tracking every security vulnerability reported to GNOME. That person is leaving. Michael Catanzaro has been GNOME's sole security coordinator since November 2020. No team. No automated system. Just one person triaging every report that comes in. He's stepping down by December 2026. And it gets more complicated. AI-generated vulnerability reports are now flooding his tracker. Low-quality, algorithmically-written submissions that look real enough to take seriously but rarely lead anywhere. So before he leaves, he's changing the rules. Starting August 1, the coordinated disclosure window drops from 90 days to 30. AI-suspected reports will be closed without forwarding to maintainers. Here's the part that surprised (read shocked) me: GNOME still tracks all of this on a wiki page. Not a proper bug tracker. Not searchable notices like Ubuntu or Fedora use. A wiki. One person, a wiki, and a deadline shrinking by two-thirds. GNOME needs someone experienced to step in. If you are part of the GNOME community or know someone who is, this is worth paying attention to.
linkedin.com
Cursor is tackling a major AI coding challenge: choosing the right model for every request. Its new Cursor Router classifies tasks by context, complexity, and domain, routing routine work to cheaper models while reserving frontier models for harder problems. 1/2
Tell me Hugging Faces has been attacked via Fable 5 by another Western company (Fable 5 access is still somehow restricted) without telling me. Also kinda crazy they defended themselves using Kimi K3, which is an open model. Open-weight models are the future.
New OPNsense update released, update and stay safe Hi all, This is a small stable release addressing some of the upgrade related issues that were reported last week as well as 4 new security advisories for the core code. Here are the full patch note…
OPNsense 26.7.1 released
OPNsense 26.7.1 released
forum.opnsense.org
In #AI open-weights and edge computing are the long term sustainable solutions, both financially and for privacy. China is winning right now, with EU lagging behind. US is still about closed models, but the math is against such business.
American AI is locked down and proprietary. It's losing.
China's open-weights AI strategy is winning: its companies are taking the lead. America's closed-first, locked-down strategy is doomed to failure - and it could take the US economy down with it.
werd.io
Loops are no longer cool. We discovered graphs once again.
Visor: The Modern Graphical UEFI Boot Manager That Makes GRUB Look Ugly www.fosslinux.com/159062/visor...
Visor: The Modern Graphical UEFI Boot Manager That Makes GRUB Look Ugly
Visor is a new graphical UEFI boot manager that combines GRUB speed with rEFInd beauty. Learn installation, configuration, theming, and Secure Boot on Ubuntu.
fosslinux.com
Late-night icon picker for terminal people 😍 🌃 latuicon — A TUI icon picker for emoji, kaomoji, Unicode & Nerd Font glyphs 💯 Fuzzy search, multiple icon sets, themes & mouse support 🦀 Written in Rust & built with @ratatui.rs ⭐ GitHub: github.com/coko7/latuicon #rustlang #tui #ratatui #emoji
#GitHub just made Dependabot package 'cooldown' the default. PRs will now wait up to 3 days after a new package release before being opened, giving time to spot broken or compromised releases. It's already enabled. You can disable it in dependabot.yml github.blog/changelog/20... #GitHub #DevOps
Dependabot version updates introduce default package cooldown - GitHub Changelog
Dependabot now waits until a new release has been available on its registry for at least three days before opening a version update pull request. This cooldown is now the…
github.blog
**ICYMI:** On June 18, Google has retired Gemini CLI for individual users in favor of the new Antigravity CLI. Free, Pro, and Ultra accounts need to migrate to Antigravity CLI (aka 'agy'). Enterprise and API are still supported. github.com/google-gemin... #AI #Gemini #CLI #OpenSource #MCP #LLM
An important update: Transitioning Gemini CLI to Antigravity CLI · google-gemini gemini-cli · Discussion #27274
As announced today in our full blog post, we are unifying our agent-first development tools to better support complex, multi-agent workflows that many of you now run. To deliver the single platform...
github.com
New OPNsense update released, update and stay safe What is up everyone, For over 11 a half years now, OPNsense is driving innovation through modularising and hardening the open source firewall, with simple and reliable firmware upgrades, multi-langua…
OPNsense 26.7 released
OPNsense 26.7 released
forum.opnsense.org