<?xml version="1.0" encoding="utf-8" standalone="yes"?><?xml-stylesheet type="text/xsl" href="https://perrotta.dev/rss.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Fosdem on ¬ just serendipity 🍀</title>
    <link>https://perrotta.dev/</link>
    <description>Recent content in Fosdem on ¬ just serendipity 🍀</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <managingEditor>serendipity@perrotta.dev (Thiago Perrotta)</managingEditor>
    <webMaster>serendipity@perrotta.dev (Thiago Perrotta)</webMaster>
    <copyright>© 2013 - 2026 Thiago Perrotta ·
  a fork of [hugo ʕ•ᴥ•ʔ bear](https://github.com/janraasch/hugo-bearblog/)
</copyright>
    <lastBuildDate>Mon, 16 Feb 2026 16:52:58 +0100</lastBuildDate>
    <atom:link href="https://perrotta.dev/tags/fosdem/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>★ Open Source security in spite of AI
      </title>
      <link>https://perrotta.dev/2026/02/open-source-security-in-spite-of-ai/</link>
      <pubDate>Sat, 07 Feb 2026 11:12:24 +0100</pubDate><author>serendipity@perrotta.dev (Thiago Perrotta)</author>
      <category>ai</category>
      <category>bestof</category>
      <category>dev</category>
      <category>fosdem</category>
      <category>meta</category>
      <category>posse</category>
      <category>security</category>
      <category>serenity</category>
      <guid>https://perrotta.dev/2026/02/open-source-security-in-spite-of-ai/</guid>
      <description>&lt;p&gt;♠ &lt;a href=&#34;https://daniel.haxx.se/blog/2026/02/03/open-source-security-in-spite-of-ai/&#34;&gt;Open Source security in spite of&#xA;AI&lt;/a&gt;&#xA;by &lt;a href=&#34;https://daniel.haxx.se/blog/&#34;&gt;Daniel Stenberg&lt;/a&gt;&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;https://perrotta.dev/2026/02/open-source-security-in-spite-of-ai/#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; (of &lt;em&gt;curl&lt;/em&gt; fame):&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;The title of my ending keynote at FOSDEM February 1, 2026.&lt;/p&gt;&#xA;&lt;p&gt;As the last talk of the conference, at 17:00 on the Sunday lots of people had&#xA;already left, and presumably a lot of the remaining people were quite tired&#xA;and ready to call it a day.&lt;/p&gt;&#xA;&lt;p&gt;Still, the 1500 seats in Janson got occupied and there was even a group of&#xA;more people outside wanting to get in that had to be refused entry.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;They say: &lt;a href=&#34;https://en.wiktionary.org/wiki/never_meet_your_heroes&#34;&gt;&amp;ldquo;never meet your&#xA;heroes&amp;rdquo;&lt;/a&gt;:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;It is unwise to seek personal acquaintance with people whom one has regarded&#xA;with high esteem, as they often fail to fulfill one&amp;rsquo;s expectations, resulting&#xA;in disappointment&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;I had the opportunity to meet Daniel in person and I&amp;rsquo;m glad to state that I am&#xA;not disappointed.&lt;/p&gt;&#xA;&lt;p&gt;I was the volunteer who held the Q&amp;amp;A at the end for his talk, and that was a&#xA;pleasure.&lt;/p&gt;&#xA;&lt;p&gt;In my opinion, this was the best talk from FOSDEM 2026.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://perrotta.dev/2026/02/open-source-security-in-spite-of-ai/open-source-security-in-spite-of-ai-daniel-stenberg.webp&#34; alt=&#34;Open Source security in spite of AI — Daniel Stenberg&#34;&#xA;  loading=&#34;lazy&#34; decoding=&#34;async&#34; /&gt;&#xA;&lt;/p&gt;&#xA;&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;&#xA;&lt;hr&gt;&#xA;&lt;ol&gt;&#xA;&lt;li id=&#34;fn:1&#34;&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=6wYSwZ20NJU&#34;&gt;Recording&lt;/a&gt;.&#xA;&lt;a href=&#34;https://daniel.haxx.se/media/FOSDEM%202026%20OSS%20security%20in%20spite%20of%20AI.pdf&#34;&gt;Slides&lt;/a&gt;.&amp;#160;&lt;a href=&#34;https://perrotta.dev/2026/02/open-source-security-in-spite-of-ai/#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;— § —&lt;/p&gt;&lt;p&gt;Reply via &lt;a href=&#34;mailto:serendipity@perrotta.dev?subject=Reply to: Open Source security in spite of AI&#34;&gt;email&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&#34;https://perrotta.dev/tags/ai/&#34;&gt;#ai&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/bestof/&#34;&gt;#bestof&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/dev/&#34;&gt;#dev&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/fosdem/&#34;&gt;#fosdem&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/meta/&#34;&gt;#meta&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/posse/&#34;&gt;#posse&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/security/&#34;&gt;#security&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/serenity/&#34;&gt;#serenity&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>atuin: new machine setup
      </title>
      <link>https://perrotta.dev/2026/01/atuin-new-machine-setup/</link>
      <pubDate>Sat, 24 Jan 2026 18:46:02 +0100</pubDate><author>serendipity@perrotta.dev (Thiago Perrotta)</author>
      <category>dev</category>
      <category>fosdem</category>
      <category>selfhosted</category>
      <guid>https://perrotta.dev/2026/01/atuin-new-machine-setup/</guid>
      <description>&lt;p&gt;♠ &lt;a href=&#34;https://perrotta.dev/2025/11/atuin/&#34;&gt;Previously&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Problem statement&lt;/strong&gt;: you&amp;rsquo;re already using &lt;code&gt;atuin&lt;/code&gt;, and have sync configured.&#xA;You just got a new machine. Now, configure &lt;code&gt;atuin&lt;/code&gt; in it.&lt;/p&gt;&#xA;&lt;p&gt;If you self-host, configure your sync server first:&lt;/p&gt;&#xA;&#xA;&lt;pre&gt;&lt;code class=&#34;language-bash&#34;&gt;$EDITOR ~/.config/atuin/config.toml&#xA;# ---&#xA;## address of the sync server&#xA;# sync_address = &amp;#34;https://api.atuin.sh&amp;#34;&#xA;sync_address = &amp;#34;https://{your-server-here}&amp;#34;&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;Then log in to your server:&lt;/p&gt;&#xA;&#xA;&lt;pre&gt;&lt;code class=&#34;language-bash&#34;&gt;atuin login --username {username}&#xA;&amp;lt;type in password&amp;gt;&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;You can also provide the password with the &lt;code&gt;--password&lt;/code&gt; switch, but keep in mind&#xA;it will be logged to your shell history unless you take precautions.&lt;/p&gt;&#xA;&lt;p&gt;The next step is to import your current history into atuin. If this is a&#xA;fresh new machine then there&amp;rsquo;s no need to do so.&lt;/p&gt;&#xA;&lt;p&gt;If you had been using it for a while but didn&amp;rsquo;t set up &lt;code&gt;atuin&lt;/code&gt; from the&#xA;beginning, go on:&lt;/p&gt;&#xA;&#xA;&lt;pre&gt;&lt;code class=&#34;language-bash&#34;&gt;atuin import auto&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;Finally, sync it once:&lt;/p&gt;&#xA;&#xA;&lt;pre&gt;&lt;code class=&#34;language-bash&#34;&gt;atuin sync&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;Syncing happens automatically, but it&amp;rsquo;s sensible to manually kick-off the&#xA;initial sync upfront.&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;Fin&lt;/em&gt;.&lt;/p&gt;&#xA;&lt;p&gt;— § —&lt;/p&gt;&lt;p&gt;Reply via &lt;a href=&#34;mailto:serendipity@perrotta.dev?subject=Reply to: atuin: new machine setup&#34;&gt;email&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&#34;https://perrotta.dev/tags/dev/&#34;&gt;#dev&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/fosdem/&#34;&gt;#fosdem&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/selfhosted/&#34;&gt;#selfhosted&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>atuin: limit scope to current directory
      </title>
      <link>https://perrotta.dev/2025/12/atuin-limit-scope-to-current-directory/</link>
      <pubDate>Tue, 23 Dec 2025 12:08:44 -0300</pubDate><author>serendipity@perrotta.dev (Thiago Perrotta)</author>
      <category>dev</category>
      <category>fosdem</category>
      <guid>https://perrotta.dev/2025/12/atuin-limit-scope-to-current-directory/</guid>
      <description>&lt;p&gt;♠ &lt;a href=&#34;https://perrotta.dev/2025/12/atuin-delete-history-entries/&#34;&gt;Previously&lt;/a&gt;,&#xA;&lt;a href=&#34;https://perrotta.dev/2025/11/atuin/&#34;&gt;previously&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Pressing &lt;code&gt;C-r&lt;/code&gt; opens the global history search by default.&lt;/p&gt;&#xA;&lt;p&gt;To limit the history lookup to the current directory only, keep pressing &lt;code&gt;C-r&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The scope will cycle through:&lt;/p&gt;&#xA;&lt;p&gt;Global &amp;gt; Host &amp;gt; Session &amp;gt; Workspace &amp;gt; Directory&lt;/p&gt;&#xA;&lt;p&gt;This makes it easier to find commands previously executed in a given directory.&lt;/p&gt;&#xA;&lt;p&gt;— § —&lt;/p&gt;&lt;p&gt;Reply via &lt;a href=&#34;mailto:serendipity@perrotta.dev?subject=Reply to: atuin: limit scope to current directory&#34;&gt;email&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&#34;https://perrotta.dev/tags/dev/&#34;&gt;#dev&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/fosdem/&#34;&gt;#fosdem&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Atuin: delete history entries
      </title>
      <link>https://perrotta.dev/2025/12/atuin-delete-history-entries/</link>
      <pubDate>Mon, 01 Dec 2025 13:35:27 -0300</pubDate><author>serendipity@perrotta.dev (Thiago Perrotta)</author>
      <category>dev</category>
      <category>fosdem</category>
      <guid>https://perrotta.dev/2025/12/atuin-delete-history-entries/</guid>
      <description>&lt;p&gt;♠ Deleting, scrubbing, redacting old shell history entries is now easier&#xA;than ever, thanks to &lt;a href=&#34;https://github.com/atuinsh/atuin&#34;&gt;atuin&lt;/a&gt;.&lt;/p&gt;&#xA;&#xA;&lt;pre&gt;&lt;code class=&#34;language-bash&#34;&gt;% atuin search &amp;#39;^aws_login_headless&amp;#39; --delete&#xA;deleting 019ad59e973b7c139c4a1d67fe2155be&#xA;deleting 019ad59e973b7c139c4a1d40a0da15f1&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;First do the search without &lt;code&gt;--delete&lt;/code&gt;, and then re-run the command with&#xA;&lt;code&gt;--delete&lt;/code&gt; if the output is what you expect.&lt;/p&gt;&#xA;&lt;p&gt;You would want to do so in these two scenarios:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;prevent irrelevant entries from showing up in &lt;code&gt;C-r&lt;/code&gt; (history search), reducing&#xA;clutter&lt;/li&gt;&#xA;&lt;li&gt;delete sensitive entries e.g. passwords (&lt;code&gt;docker login --password {foo}&lt;/code&gt;)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://perrotta.dev/2025/11/atuin/&#34;&gt;Previously&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;— § —&lt;/p&gt;&lt;p&gt;Reply via &lt;a href=&#34;mailto:serendipity@perrotta.dev?subject=Reply to: Atuin: delete history entries&#34;&gt;email&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&#34;https://perrotta.dev/tags/dev/&#34;&gt;#dev&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/fosdem/&#34;&gt;#fosdem&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>★ Atuin
      </title>
      <link>https://perrotta.dev/2025/11/atuin/</link>
      <pubDate>Sun, 30 Nov 2025 13:35:54 -0300</pubDate><author>serendipity@perrotta.dev (Thiago Perrotta)</author>
      <category>bestof</category>
      <category>dev</category>
      <category>fosdem</category>
      <guid>https://perrotta.dev/2025/11/atuin/</guid>
      <description>&lt;p&gt;♠ My current workflow to manage shell history is simple, I have this config in&#xA;my &lt;code&gt;~/.zshrc.d/&lt;/code&gt;&lt;/p&gt;&#xA;&#xA;&lt;pre&gt;&lt;code class=&#34;language-bash&#34;&gt;# fzf: fuzzy file finder&#xA;if (( $&amp;#43;commands[fzf] )); then&#xA;        # alpine/arch, debian&#xA;        src_files {/usr/share/fzf,/usr/share/doc/fzf/examples}/{completion,key-bindings}.zsh&#xA;&#xA;        # brew&#xA;        if (( $&amp;#43;commands[brew] )); then&#xA;                src_files &amp;#34;$(brew --prefix)&amp;#34;/opt/fzf/shell/{completion,key-bindings}.zsh&#xA;        fi&#xA;fi&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/junegunn/fzf&#34;&gt;&lt;code&gt;fzf&lt;/code&gt;&lt;/a&gt; does it all.&lt;/p&gt;&#xA;&lt;p&gt;I hit &lt;code&gt;C-r&lt;/code&gt; and get fuzzy finding over all my &lt;code&gt;history&lt;/code&gt;, this has been&#xA;overpowering my productivity for ages, likely since university.&lt;/p&gt;&#xA;&lt;p&gt;Then I found out I could go one step further.&lt;/p&gt;&#xA;&lt;p&gt;Enter &lt;a href=&#34;https://atuin.sh&#34;&gt;Atuin&lt;/a&gt;:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Making your shell magical&lt;/p&gt;&#xA;&lt;p&gt;Sync, search and backup shell history with Atuin.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;Installing &lt;code&gt;atuin&lt;/code&gt; is simple: it&amp;rsquo;s available &lt;a href=&#34;https://repology.org/project/atuin/versions&#34;&gt;everywhere&lt;/a&gt;:&lt;/p&gt;&#xA;&#xA;&lt;pre&gt;&lt;code class=&#34;language-bash&#34;&gt;brew install atuin&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;Configuring &lt;code&gt;atuin&lt;/code&gt; is simple, start by adding this snippet to your &lt;code&gt;/.zshrc&lt;/code&gt;&#xA;file&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;https://perrotta.dev/2025/11/atuin/#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;:&lt;/p&gt;&#xA;&#xA;&lt;pre&gt;&lt;code class=&#34;language-bash&#34;&gt;# atuin: https://docs.atuin.sh/&#xA;(( $&amp;#43;commands[atuin] )) &amp;amp;&amp;amp; eval &amp;#34;$(atuin init zsh --disable-up-arrow)&amp;#34;&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;Now run &lt;code&gt;atuin import auto&lt;/code&gt; to import your shell history entries to &lt;code&gt;atuin&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;By default, &lt;code&gt;atuin init&lt;/code&gt; binds both &lt;code&gt;C-r&lt;/code&gt; and the up arrow. I find the up&#xA;arrow binding disruptive.&lt;/p&gt;&#xA;&lt;p&gt;I want my workflow to stay as close as possible to &lt;code&gt;fzf&lt;/code&gt; &lt;code&gt;C-r&lt;/code&gt;.&#xA;&lt;a href=&#34;https://docs.atuin.sh/configuration/key-binding/#disable-up-arrow&#34;&gt;&lt;code&gt;--disable-up-arrow&lt;/code&gt;&lt;/a&gt;&#xA;is essential for that.&lt;/p&gt;&#xA;&lt;p&gt;Pressing &lt;code&gt;C-r&lt;/code&gt; will invoke a fuzzy find window that behaves similarly to &lt;code&gt;fzf&lt;/code&gt;,&#xA;though it&amp;rsquo;s more powerful. It&amp;rsquo;s hard to describe, you must try it out.&lt;/p&gt;&#xA;&lt;p&gt;This is enough to make the migration. Which makes me feel bad for having&#xA;procrastinated for so long to do so. Trying out &lt;code&gt;atuin&lt;/code&gt; has been in my TODO list&#xA;for ages!&lt;/p&gt;&#xA;&lt;p&gt;There&amp;rsquo;s an optional step of syncing your history with their remote cloud. Or&#xA;with your own, because there&amp;rsquo;s an option of self-hosting a server (&lt;code&gt;atuin server start&lt;/code&gt;). Self-hosting is optimal, but trying out their cloud first to get a feel&#xA;of the sync experience is reasonable.&lt;/p&gt;&#xA;&lt;p&gt;Syncing happens every hour by default, but this is configurable.&lt;/p&gt;&#xA;&lt;p&gt;See &lt;a href=&#34;https://docs.atuin.sh/reference/sync/&#34;&gt;sync docs&lt;/a&gt;:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Atuin can back up your history to a server, and use this to ensure multiple&#xA;machines have the same shell history. This is all encrypted end-to-end, so the&#xA;server operator can never see your data!&lt;/p&gt;&#xA;&lt;p&gt;Anyone can host a server (try atuin server start, more docs to follow), but I&#xA;host one at &lt;a href=&#34;https://api.atuin.sh&#34;&gt;https://api.atuin.sh&lt;/a&gt;. This is the default server address, which&#xA;can be changed in the config. Again, I cannot see your data, and do not want&#xA;to.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;You can create a &lt;code&gt;~/.config/atuin/config.toml&lt;/code&gt; to customize &lt;code&gt;atuin&lt;/code&gt;. I added&#xA;this:&lt;/p&gt;&#xA;&#xA;&lt;pre&gt;&lt;code class=&#34;language-toml&#34;&gt;## With workspace filtering enabled, Atuin will filter for commands executed&#xA;## in any directory within a git repository tree (default: false).&#xA;##&#xA;## To use workspace mode by default when available, set this to true and&#xA;## set filter_mode to &amp;#34;workspace&amp;#34; or leave it unspecified and&#xA;## set search.filters to include &amp;#34;workspace&amp;#34; before other filter modes.&#xA;# workspaces = false&#xA;workspaces = true&#xA;&#xA;## which filter mode to use when atuin is invoked from a shell up-key binding&#xA;## the accepted values are identical to those of &amp;#34;filter_mode&amp;#34;&#xA;## leave unspecified to use same mode set in &amp;#34;filter_mode&amp;#34;&#xA;# filter_mode_shell_up_key_binding = &amp;#34;global&amp;#34;&#xA;filter_mode_shell_up_key_binding = &amp;#34;directory&amp;#34;&#xA;&#xA;## Defaults to true. If enabled, upon hitting enter Atuin will immediately execute the command. Press tab to return to the shell and edit.&#xA;# This applies for new installs. Old installs will keep the old behaviour unless configured otherwise.&#xA;# Similarly to fzf C-r&#xA;enter_accept = false&#xA;&#xA;## Defaults to &amp;#34;emacs&amp;#34;.  This specifies the keymap on the startup of `atuin&#xA;## search`.  If this is set to &amp;#34;auto&amp;#34;, the startup keymap mode in the Atuin&#xA;## search is automatically selected based on the shell&amp;#39;s keymap where the&#xA;## keybinding is defined.  If this is set to &amp;#34;emacs&amp;#34;, &amp;#34;vim-insert&amp;#34;, or&#xA;## &amp;#34;vim-normal&amp;#34;, the startup keymap mode in the Atuin search is forced to be&#xA;## the specified one.&#xA;# keymap_mode = &amp;#34;auto&amp;#34;&#xA;keymap_mode = &amp;#34;vim-insert&amp;#34;&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;&lt;code&gt;enter_accept&lt;/code&gt; is an important tweak to resemble &lt;code&gt;fzf&lt;/code&gt;. By default, pressing&#xA;Enter when looking up history entries in &lt;code&gt;atuin&lt;/code&gt; will automatically execute the&#xA;command. In &lt;code&gt;fzf&lt;/code&gt; you have an opportunity to edit/tweak the command before&#xA;execution, which is what I prefer. Set &lt;code&gt;enter_accept = false&lt;/code&gt; to achieve the&#xA;same behavior in &lt;code&gt;atuin&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;atuin&lt;/code&gt; has an option to manage&#xA;&lt;a href=&#34;https://docs.atuin.sh/guide/dotfiles/&#34;&gt;dotfiles&lt;/a&gt;:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;While Atuin started as a tool for syncing and searching shell history, we are&#xA;building tooling for syncing dotfiles across machines, and making them easier&#xA;to work with.&lt;/p&gt;&#xA;&lt;p&gt;At the moment, we support managing and syncing of shell aliases and&#xA;environment variables — with more coming soon.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;&amp;hellip;but I don&amp;rsquo;t feel the need to use this.&lt;/p&gt;&#xA;&lt;p&gt;The magic of &lt;code&gt;atuin&lt;/code&gt;, when using multiple computers is its shell history&#xA;synchronization. Picking up the slack in my personal computer would reveal my&#xA;work computer history and vice-versa. In some environments this is very&#xA;welcome!&lt;/p&gt;&#xA;&lt;p&gt;Also cool: &lt;code&gt;stats&lt;/code&gt; for free:&lt;/p&gt;&#xA;&#xA;&lt;pre&gt;&lt;code class=&#34;language-bash&#34;&gt;% atuin stats&#xA;[▮▮▮▮▮▮▮▮▮▮] 4540 git commit&#xA;[▮▮▮▮▮▮    ] 3062 ack&#xA;[▮▮▮▮▮     ] 2636 vim&#xA;[▮▮        ] 1304 cd&#xA;[▮▮        ] 1240 fd&#xA;[▮▮        ] 1186 tsh&#xA;[▮▮        ]  915 grep&#xA;[▮▮        ]  913 just&#xA;[▮         ]  822 git add&#xA;[▮         ]  818 git nb&#xA;Total commands:   29464&#xA;Unique commands:  20610&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;Query past entries with a SQL-like CLI:&lt;/p&gt;&#xA;&#xA;&lt;pre&gt;&lt;code class=&#34;language-bash&#34;&gt;% atuin search --exit 0 --after=&amp;#34;4 months ago&amp;#34; &amp;#34;^skopeo&amp;#34;&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;Clearly I&amp;rsquo;m a die-hard &lt;a href=&#34;https://beyondgrep.com/&#34;&gt;&lt;code&gt;ack&lt;/code&gt;&lt;/a&gt; fan. Will I ever switch&#xA;to &lt;a href=&#34;https://github.com/BurntSushi/ripgrep&#34;&gt;&lt;code&gt;rg&lt;/code&gt;&lt;/a&gt;?&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://just.systems/&#34;&gt;&lt;code&gt;just&lt;/code&gt;&lt;/a&gt; is starting to become part of my core tool belt.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;See also&lt;/strong&gt;: &lt;a href=&#34;https://archive.fosdem.org/2023/schedule/event/rust_atuin_magical_shell_history_with_rust/&#34;&gt;Tech&#xA;Talk&lt;/a&gt;,&#xA;including&#xA;&lt;a href=&#34;https://archive.fosdem.org/2023/schedule/event/rust_atuin_magical_shell_history_with_rust/attachments/slides/5735/export/events/attachments/rust_atuin_magical_shell_history_with_rust/slides/5735/Atuin_FOSDEM_1.pdf&#34;&gt;slides&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Next chapter: &lt;a href=&#34;https://github.com/atuinsh/desktop&#34;&gt;Atuin Desktop&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;&#xA;&lt;hr&gt;&#xA;&lt;ol&gt;&#xA;&lt;li id=&#34;fn:1&#34;&gt;&#xA;&lt;p&gt;&lt;code&gt;bash&lt;/code&gt;, &lt;code&gt;fish&lt;/code&gt;, &lt;code&gt;xonsh&lt;/code&gt; are also supported at the time of this writing.&amp;#160;&lt;a href=&#34;https://perrotta.dev/2025/11/atuin/#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;— § —&lt;/p&gt;&lt;p&gt;Reply via &lt;a href=&#34;mailto:serendipity@perrotta.dev?subject=Reply to: Atuin&#34;&gt;email&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&#34;https://perrotta.dev/tags/bestof/&#34;&gt;#bestof&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/dev/&#34;&gt;#dev&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/fosdem/&#34;&gt;#fosdem&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>★ zizmor
      </title>
      <link>https://perrotta.dev/2025/10/zizmor/</link>
      <pubDate>Fri, 03 Oct 2025 12:44:21 +0200</pubDate><author>serendipity@perrotta.dev (Thiago Perrotta)</author>
      <category>alpine-linux</category>
      <category>bestof</category>
      <category>dev</category>
      <category>fosdem</category>
      <category>security</category>
      <guid>https://perrotta.dev/2025/10/zizmor/</guid>
      <description>&lt;p&gt;♠ I originally heard of &lt;a href=&#34;https://docs.zizmor.sh/&#34;&gt;zizmor&lt;/a&gt; at &lt;a href=&#34;https://fosdem.org/2025/&#34;&gt;FOSDEM 2025&lt;/a&gt;:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;zizmor is a static analysis tool for GitHub Actions. It can find and fix many&#xA;common security issues in typical GitHub Actions CI/CD setups.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;One month later, I adopted it in the most important repos of our company.&lt;/p&gt;&#xA;&lt;p&gt;A few months later, I &lt;a href=&#34;https://perrotta.dev/2025/06/alpine-linux-packaging-track-new-software-releases/&#34;&gt;added&lt;/a&gt; it to the&#xA;Alpine Linux repositories, and am happily&#xA;&lt;a href=&#34;https://pkgs.alpinelinux.org/packages?name=zizmor&#34;&gt;maintaining&lt;/a&gt; it there.&lt;/p&gt;&#xA;&lt;p&gt;Now I use it &lt;em&gt;everywhere&lt;/em&gt;, via a git &lt;a href=&#34;https://pre-commit.com/&#34;&gt;pre-commit&lt;/a&gt; hook:&lt;/p&gt;&#xA;&#xA;&lt;pre&gt;&lt;code class=&#34;language-yaml&#34;&gt;repos:&#xA;  - repo: https://github.com/woodruffw/zizmor-pre-commit&#xA;    rev: b933184438555436e38621f46ceb0c417cbed400 # frozen: v1.13.0&#xA;    hooks:&#xA;      - id: zizmor&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;The project has recently reached a milestone: &lt;a href=&#34;https://blog.yossarian.net/2025/09/14/one-year-of-zizmor&#34;&gt;it has turned one year&#xA;old&lt;/a&gt;. Its adoption,&#xA;community and feature set have all significantly increased during that time, in&#xA;a good way.&lt;/p&gt;&#xA;&lt;p&gt;The goal, impact and spirit of the project are all really great. And I&amp;rsquo;m sure&#xA;this is mainly thanks to the initiative and dedication of its author, &lt;a href=&#34;https://blog.yossarian.net/&#34;&gt;William&#xA;Woodruff&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;— § —&lt;/p&gt;&lt;p&gt;Reply via &lt;a href=&#34;mailto:serendipity@perrotta.dev?subject=Reply to: zizmor&#34;&gt;email&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&#34;https://perrotta.dev/tags/alpine-linux/&#34;&gt;#alpine-linux&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/bestof/&#34;&gt;#bestof&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/dev/&#34;&gt;#dev&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/fosdem/&#34;&gt;#fosdem&lt;/a&gt; &lt;a href=&#34;https://perrotta.dev/tags/security/&#34;&gt;#security&lt;/a&gt;&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
