# sha256

Published articles for sha256.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Ruby 4.0.7 Released

DevFeed: [Ruby 4.0.7 Released](<https://devfeed.tech/articles/ruby-4-0-7-released-26578.md>)

Original publisher: [Read original article](<https://www.ruby-lang.org/en/news/2026/09/15/ruby-4-0-7-released/>)

Published: 2026-09-15T00:25:58Z

Content type: release

Language: en

Sources: [Ruby-lang](<https://devfeed.tech/sources/ruby-lang.md>)

Topics: [Ruby](<https://devfeed.tech/topics/ruby.md>), [releases](<https://devfeed.tech/topics/releases.md>), [bug](<https://devfeed.tech/topics/bug.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [bugfixes](<https://devfeed.tech/tags/bugfixes.md>), [contributions](<https://devfeed.tech/tags/contributions.md>), [download](<https://devfeed.tech/tags/download.md>), [release](<https://devfeed.tech/tags/release.md>), [release-schedule](<https://devfeed.tech/tags/release-schedule.md>), [releases](<https://devfeed.tech/tags/releases.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [xz](<https://devfeed.tech/tags/xz.md>), [zip](<https://devfeed.tech/tags/zip.md>)

### AI overview

Ruby 4.0.7 has been released as a routine update containing bugfixes. The article says Ruby 4.0.8 is planned for November, with earlier release possible if a significant user-impacting change arises.

### Source excerpt

Ruby 4.0.7 has been released. This is a routine update that includes bugfixes. Please see the GitHub releases for further details. Release Schedule We intend to release the latest stable Ruby version (currently Ruby 4.0) every two months following the most recent release. Ruby 4.0.8 will be released in November. If a change arises that significantly affects users, a release may occur earlier than planned. Download https://cache.ruby-lang.org/pub/ruby/4.0/ruby-4.0.7.tar.gz SIZE: 23937964 SHA1: 730d4f8cebb60a1f5b556e7b58d86d0301772558 SHA256: 911ace20f90d068ca0e4dda6d0e4f0f81e52e52f2dd4f4004c721e253412e82d SHA512: ca6fb2df4b39967f1a92399ab70579216f2a87e600d127a616d4a81a3c92b25ebf35849502a2c12e2251d69e67eade3888af4a41b8844054d5c774f07c237c6d https://cache.ruby-lang.org/pub/ruby/4.0/ruby-4.0.7.tar.xz SIZE: 17995980 SHA1: 7d2307f975b1fef4e0ffe5cfe13067f993b5a4c2 SHA256: 47ef59413f7a4587ba6a6b78b14036eb5e36eec2ec0b90964801e88d56a3d375 SHA512: d1d345c25bff43aa86f536b22cd04746a7d3372077bf47ec75ef1820c0b43d0dbe3573dd5e5c55ee517796f46f0cdbd22c7506aebd06581241eefb5ffd9d2e5f https://cache.ruby-lang.org/pub/ruby/4.0/ruby-4.0.7.zip SIZE: 29248954 SHA1: 82b1bce8abb650e3080b96a0beff810b690dafa4 SHA256: c6f889c6dccd2625ae8d595bdee8e92afb3ddae3a1669bad67bb9f24d6af30ab SHA512: 5456ee1260921589cad5f0c57e84715e9c26b1f438a4c141157093c8e37e7e5d499a96c0ed35641f3cea1b741ecda2d72bfa3ce79fdbd5491784d9e6d181ac09 Release Comment Many committers, developers, and users who provided bug reports helped us make this release. Thanks for their contributions. Posted by k0kubun on 15 Sep 2026

## Ruby 3.4.10 Released

DevFeed: [Ruby 3.4.10 Released](<https://devfeed.tech/articles/ruby-3-4-10-released-19154.md>)

Original publisher: [Read original article](<https://www.ruby-lang.org/en/news/2026/06/30/ruby-3-4-10-released/>)

Published: 2026-06-30T12:00:00Z

Content type: release

Language: en

Sources: [Ruby-lang](<https://devfeed.tech/sources/ruby-lang.md>)

Topics: [Ruby](<https://devfeed.tech/topics/ruby.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [security](<https://devfeed.tech/tags/security.md>), [sha256](<https://devfeed.tech/tags/sha256.md>)

### AI overview

Ruby 3.4.10 is a regular stable package release that updates the bundled net-imap gem, including security fixes. The release provides source downloads in tar.gz, tar.xz, and ZIP formats with checksums.

### Source excerpt

Ruby 3.4.10 has been released. This release is a regular stable package release contains the version update of bundled gem net-imap. The net-imap.gem update contains some security fixes. Please see the release note of net-imap v0.5.15 for the detailed update of net-imap.gem. Please see the GitHub releases for further details. Download https://cache.ruby-lang.org/pub/ruby/3.4/ruby-3.4.10.tar.gz SIZE: 22476870 SHA1: 5eac73bce00e770e19b50b69032578df9b2bb41c SHA256: ecee2d072a14f2d14347dd56dfd8fe5c3130abf5117bfaacbda0f4ef9cc429ec SHA512: 493c9be80a78a4ddf983620295c79ae9f1c8e4c60da8237e12965fa6f95dda6548b3ff3cd311fe774cc8237e18ad2b2514dd029c46c8f4eabea6613a39d7745b https://cache.ruby-lang.org/pub/ruby/3.4/ruby-3.4.10.tar.xz SIZE: 16709188 SHA1: 8655291cc2e7547d10db5e81f9baac8cdbbbf702 SHA256: 6f32ad662baafc228d12030dbcd284f83b034dd4337b300dc84ac74d11a1eb68 SHA512: c28d59946c0a1b8e4385a772e0651c6f4154c18ab8a2a62289c3213eb4fe937cec0942e0076cda429576e58ad277b18f4b5611e644d15b122c1cd96baf10f284 https://cache.ruby-lang.org/pub/ruby/3.4/ruby-3.4.10.zip SIZE: 27697773 SHA1: 09dd69e25c393071bd0550da5f4983ee4d9550a3 SHA256: 3b18a22a2ea1bed8df645b1568ba13eb659baeed3a2a1a7f67a21ca604e68a13 SHA512: 1516ee66d878480b8d7164a002d3087268a79c380ba4807172b26260644f39bac4b7f781b62a815e46bc1107edf578f6cf4eae9aebc8fe86416978e737865278 Release Comment Many committers, developers, and users who provided bug reports helped us make this release. Thanks for their contributions. Posted by nagachika on 30 Jun 2026

## Eliminating Kubernetes Image Signature Replication

DevFeed: [Eliminating Kubernetes Image Signature Replication](<https://devfeed.tech/articles/eliminating-kubernetes-image-signature-replication-17597.md>)

Original publisher: [Read original article](<https://www.kubernetes.dev/blog/2026/06/05/image-signature-routing/>)

Author: The Kubernetes Authors

Published: 2026-06-05T00:00:00Z

Content type: article

Language: en

Sources: [Kubernetes Contributors Blog](<https://devfeed.tech/sources/kubernetes-contributors-blog.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Replication](<https://devfeed.tech/topics/replication.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [Latency](<https://devfeed.tech/topics/latency.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [latency](<https://devfeed.tech/tags/latency.md>), [manifest](<https://devfeed.tech/tags/manifest.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [registry](<https://devfeed.tech/tags/registry.md>), [replication](<https://devfeed.tech/tags/replication.md>), [route](<https://devfeed.tech/tags/route.md>), [routing](<https://devfeed.tech/tags/routing.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [signing](<https://devfeed.tech/tags/signing.md>), [verify](<https://devfeed.tech/tags/verify.md>)

### AI overview

This article explains how Kubernetes eliminated replication of image signatures across 22 regional registries. Because signatures are small and regional latency is negligible, archeio now routes signature requests to a canonical registry while image layers continue using geo-routing.

### Source excerpt

The image promoter rewrite laid the groundwork for simplifying how Kubernetes delivers container image signatures. One of the rewrite phases (Phase 6) separated image signing from signature replication into distinct pipeline stages. This follow-up covers the next step: eliminating signature replication entirely. The problem After promoting container images to registry.k8s.io, the promoter signs them using cosign with keyless (OIDC) signatures. These signatures are stored as OCI artifacts alongside the images, tagged with the convention sha256-<digest>.sig and sha256-<digest>.att. The registry.k8s.io domain is backed by archeio , a thin redirector that routes container image requests to the nearest regional Google Artifact Registry backend. When a user in Europe pulls an image, archeio redirects them to europe-west2-docker.pkg.dev; a user in Asia gets redirected to asia-east1-docker.pkg.dev, and so on across 22 regional backends. This geo-routing is great for image layers, where download locality matters for performance. But it created a problem for signatures: if the promoter only wrote a signature to one region, cosign verify would fail for users redirected to any other region. The solution was a dedicated replication pipeline that copied every .sig and .att tag to all 22 regional backends. This pipeline ran as a periodic Prow job every 2 hours on weekdays, performing thousands of API calls per run: listing tags across all repositories, diffing what existed where, and copying the missing signatures. The insight Signatures and attestations are small metadata artifacts, typically a few kilobytes each. Unlike image layers where geo-locality provides meaningful download performance improvements, fetching a signature from a non-local region adds negligible latency. The entire replication pipeline existed to optimize for a latency difference that users would never notice. The solution Instead of replicating signatures everywhere, archeio was taught to route signature req

## Ruby 4.0.4 Released

DevFeed: [Ruby 4.0.4 Released](<https://devfeed.tech/articles/ruby-4-0-4-released-19151.md>)

Original publisher: [Read original article](<https://www.ruby-lang.org/en/news/2026/05/11/ruby-4-0-4-released/>)

Published: 2026-05-11T21:41:38Z

Content type: release

Language: en

Sources: [Ruby-lang](<https://devfeed.tech/sources/ruby-lang.md>)

Topics: [Ruby](<https://devfeed.tech/topics/ruby.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [bugfixes](<https://devfeed.tech/tags/bugfixes.md>), [contributions](<https://devfeed.tech/tags/contributions.md>), [developers](<https://devfeed.tech/tags/developers.md>), [download](<https://devfeed.tech/tags/download.md>), [release](<https://devfeed.tech/tags/release.md>), [release-schedule](<https://devfeed.tech/tags/release-schedule.md>), [releases](<https://devfeed.tech/tags/releases.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [xz](<https://devfeed.tech/tags/xz.md>), [zip](<https://devfeed.tech/tags/zip.md>)

### AI overview

Ruby 4.0.4 has been released as a routine update containing bug fixes. The article provides download links, checksums, the planned Ruby 4.0 release schedule, and acknowledgments to contributors.

### Source excerpt

Ruby 4.0.4 has been released. This is a routine update that includes bugfixes. Please see the GitHub Releases for further details. Release Schedule We intend to release the latest stable Ruby version (currently Ruby 4.0) every two months following the most recent regular release. Ruby 4.0.5 will be released in July, 4.0.6 in September, and 4.0.7 in November. If a change arises that significantly affects users, a release may occur earlier than planned, and the subsequent schedule may shift accordingly. Download https://cache.ruby-lang.org/pub/ruby/4.0/ruby-4.0.4.tar.gz SIZE: 23816838 SHA1: 3633db75e6b4848b509ecccc64704d8f4467f068 SHA256: f35f6edfa3dabb3f723f9d0cf1906c6512ae77f4e412ab1e68cc6e91d230fa80 SHA512: b0cc9af75ee25628483a32ecd5ea6477d637ee3c75795f411bc4ebde7d86ab754fddf96385cfc5955b9dbd016418cbd7178c82dad7876b2b7119238f5159ed3a https://cache.ruby-lang.org/pub/ruby/4.0/ruby-4.0.4.tar.xz SIZE: 17899740 SHA1: 9e070a8a78e6faa35382360b47526042657b236d SHA256: 6ff9d2d6e75f5a6f997222ecc45f79209d663737eceb3689d1f42ab952673fb7 SHA512: cccc041379fd4e46a736a5c10ccf81627766a7175113c34754797b915bebcd0ce821d9cd7b42cc616b0a1f9ee38eee5ab7560c1840fa6672819c293e498a3f6f https://cache.ruby-lang.org/pub/ruby/4.0/ruby-4.0.4.zip SIZE: 29122429 SHA1: 5edc7ce0adc2851a355673a5bb42b75efd4cf2b2 SHA256: 508bc83baed022c20671d69dd264e6783d61b89767b5d387c0f8efea00b62219 SHA512: b5db7ba616c56bdac9a61362d88d6350c8a8b59b5d812c1395476db73cb60fb403994e0bc3285aa2f57acbef3e30bcfce4bee4c5c8433b39d8f0a7c6dbb9bd29 Release Comment Many committers, developers, and users who provided bug reports helped us make this release. Thanks for their contributions. Posted by k0kubun on 11 May 2026

## Ruby 3.2.11 Released

DevFeed: [Ruby 3.2.11 Released](<https://devfeed.tech/articles/ruby-3-2-11-released-19148.md>)

Original publisher: [Read original article](<https://www.ruby-lang.org/en/news/2026/03/27/ruby-3-2-11-released/>)

Published: 2026-03-27T00:00:00Z

Content type: release

Language: en

Sources: [Ruby-lang](<https://devfeed.tech/sources/ruby-lang.md>)

Topics: [Ruby](<https://devfeed.tech/topics/ruby.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Zip](<https://devfeed.tech/topics/zip.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [download](<https://devfeed.tech/tags/download.md>), [github](<https://devfeed.tech/tags/github.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [security](<https://devfeed.tech/tags/security.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [zip](<https://devfeed.tech/tags/zip.md>)

### AI overview

Ruby 3.2.11 has been released with an update to the zlib gem addressing CVE-2026-27820. It is the final Ruby 3.2 release, with no further updates or security fixes planned for the series; users are recommended to upgrade to Ruby 3.4 or 4.0.

### Source excerpt

Ruby 3.2.11 has been released. This release includes an update to the zlib gem addressing CVE-2026-27820. Please see the GitHub releases for further details. This is the final release of the Ruby 3.2 series. We will not provide any further updates, including security fixes, for the Ruby 3.2 series. We recommend upgrading to Ruby 3.4 or 4.0. Download https://cache.ruby-lang.org/pub/ruby/3.2/ruby-3.2.11.tar.gz SIZE: 19984344 SHA1: 9534a3aa08d2ccb4d3c50b1301b2da9a9b91c4ab SHA256: b3eeabd6636f334531db3ffdc3229eb05e524740e6c84fdc043720573cf2f8b2 SHA512: 95896bbf519604da0dc3d82066ac92c3f661b2ee9ffd8e2c9effce4773677445f1dcc43b05539050024b57f4f94f43984a734a03015ac6e29679e79d5a093a67 https://cache.ruby-lang.org/pub/ruby/3.2/ruby-3.2.11.tar.xz SIZE: 14695828 SHA1: 501cecc15ba079087967888ae455d62e5886fbc1 SHA256: c13aec0c206725d5d356acbae6e5fd8bffd92dc325aec14fd5dd7795d4b763d2 SHA512: 418739d476d34e2467e7f1ee60ff63a1969a362b49871bdc488676c1ac7d28b198deee85e2bd951a23f5b0e8425bc89ca59d5c8cb8415fa5ed835555e3d3af8d https://cache.ruby-lang.org/pub/ruby/3.2/ruby-3.2.11.zip SIZE: 24594356 SHA1: 7e84c9433f32a758da123d3b5532cc632d19d503 SHA256: 08ab90aa4ada9268e96aa47fb6c3a77fdb3b2f792f2671053e3b55a6141618ce SHA512: 133d63cd9bb7c9fe38eecd18c996013de0a56fef09c89c42f4fc9c383f09ab4ab3b0b31edbadd1fd1aaa797fbb9c86128ded51c6e5263cd3225754e714b3d195 Release Comment Since the initial release of Ruby 3.2.0 on December 25, 2022, the Ruby 3.2 series has been supported for over three years. We would like to thank all committers, developers, and users who provided bug reports and contributions throughout the life of the Ruby 3.2 series. Posted by hsbt on 27 Mar 2026

## ESPHome 2026.1.0: Automatic WiFi roaming and ESP-IDF by default

DevFeed: [ESPHome 2026.1.0: Automatic WiFi roaming and ESP-IDF by default](<https://devfeed.tech/articles/esphome-2026-1-0-automatic-wifi-roaming-and-esp-idf-by-default-16705.md>)

Original publisher: [Read original article](<https://esphome.io/blog/2026/01/21/esphome-2026-1/>)

Author: Jesse Hills

Published: 2026-01-21T00:00:00Z

Content type: release

Language: en

Sources: [ESPHome - Smart Home Made Simple - Blog](<https://devfeed.tech/sources/esphome-smart-home-made-simple-blog.md>)

Topics: [esphome](<https://devfeed.tech/topics/esphome.md>), [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [ESP32](<https://devfeed.tech/topics/esp32.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>)

Tags: [encryption](<https://devfeed.tech/tags/encryption.md>), [esp](<https://devfeed.tech/tags/esp.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [esphome](<https://devfeed.tech/tags/esphome.md>), [optimization](<https://devfeed.tech/tags/optimization.md>), [ota](<https://devfeed.tech/tags/ota.md>), [performance](<https://devfeed.tech/tags/performance.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [wifi](<https://devfeed.tech/tags/wifi.md>)

### AI overview

ESPHome 2026.1.0 adds automatic WiFi roaming, makes ESP-IDF the default framework for supported ESP32 targets, requires API encryption and SHA256 authentication for OTA updates, and introduces performance, platform, hardware, and parsing improvements.

### Source excerpt

ESPHome 2026.1.0 adds automatic WiFi roaming, makes ESP-IDF the default on ESP32, requires API encryption and SHA256 OTA, and lands broad performance work.

## Building towards OCI v1.1 support in cosign

DevFeed: [Building towards OCI v1.1 support in cosign](<https://devfeed.tech/articles/building-towards-oci-v1-1-support-in-cosign-12913.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-towards-oci-v1-1-support-in-cosign>)

Published: 2023-02-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [releases](<https://devfeed.tech/topics/releases.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>)

Tags: [cosign](<https://devfeed.tech/tags/cosign.md>), [http](<https://devfeed.tech/tags/http.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [manifest](<https://devfeed.tech/tags/manifest.md>), [oci](<https://devfeed.tech/tags/oci.md>), [oci-registry](<https://devfeed.tech/tags/oci-registry.md>), [oci-v1-1](<https://devfeed.tech/tags/oci-v1-1.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [registry](<https://devfeed.tech/tags/registry.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

The article discusses progress toward OCI v1.1 and its implications for cosign. It explains how OCI proposals and approved pull requests address relationships between objects in registries, and introduces the Referrers Tag Schema as a more interoperable alternative to cosign's existing tag-based approach.

### Source excerpt

Learn about OCI, which is inching closer to a v1.1 release which provides official guidance on how to connect things in a registry.

## Ultimate Go: Advanced Engineering Episode 2

DevFeed: [Ultimate Go: Advanced Engineering Episode 2](<https://devfeed.tech/articles/ultimate-go-advanced-engineering-episode-2-22188.md>)

Original publisher: [Read original article](<https://www.ardanlabs.com/blog/2022/12/ultimate-go-advanced-engineering-episode-2.html>)

Published: 2022-12-13T00:00:00Z

Content type: tutorial

Language: en

Sources: [William Kennedy](<https://devfeed.tech/sources/william-kennedy.md>)

Topics: [Go Language](<https://devfeed.tech/topics/go-language.md>), [Dependency management](<https://devfeed.tech/topics/dependency-management.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Algorithm](<https://devfeed.tech/topics/algorithm.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Database](<https://devfeed.tech/topics/database.md>)

Tags: [algorithm](<https://devfeed.tech/tags/algorithm.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [cli](<https://devfeed.tech/tags/cli.md>), [database](<https://devfeed.tech/tags/database.md>), [dependency-management](<https://devfeed.tech/tags/dependency-management.md>), [go](<https://devfeed.tech/tags/go.md>), [go-blockchain](<https://devfeed.tech/tags/go-blockchain.md>), [golang-blockchain](<https://devfeed.tech/tags/golang-blockchain.md>), [hash-algorithms](<https://devfeed.tech/tags/hash-algorithms.md>), [hash-collision](<https://devfeed.tech/tags/hash-collision.md>), [hashing](<https://devfeed.tech/tags/hashing.md>), [sha-256](<https://devfeed.tech/tags/sha-256.md>), [sha256](<https://devfeed.tech/tags/sha256.md>)

### AI overview

This video tutorial explains how dependency management in Go relates to reproducible builds, blockchain hashing, and trust in a centralized dependency database. It introduces hashes as distributed identifiers, explains collisions, and discusses the use of SHA-256 to reduce collision risk.

### Source excerpt

Introduction In episode 1, Bill finished by describing the dependency management conundrum Go faced in its early days. Prior to the Go team providing the module system, developers were on their own to find a solution. Engineers in the Go community did propose different solutions, but there was no general consensus on which tool to use for dependency management. In this video, Bill will begin to architect a solution to the reproducible build problem. By doing so, you will learn how blockchain hashing works and then Bill will share how centralizing this dependency database will cause other problems. One of these problems is people eventually losing trust in the database because only one stakeholder, Bill, can make changes to it without a means for users to detect the change. He closes this segment with an important question, "how do we establish trust for this CLI's database?"

## Searching for RH Counterexamples -- Scaling Up

DevFeed: [Searching for RH Counterexamples -- Scaling Up](<https://devfeed.tech/articles/searching-for-rh-counterexamples-scaling-up-40444.md>)

Original publisher: [Read original article](<https://www.jeremykun.com/2021/02/16/searching-for-rh-counterexamples-scaling-up/>)

Published: 2021-02-16T09:00:00Z

Content type: article

Language: en

Sources: [Jeremy Kun](<https://devfeed.tech/sources/jeremy-kun.md>)

Topics: [Mathematics](<https://devfeed.tech/topics/mathematics.md>), [hashing](<https://devfeed.tech/topics/hashing.md>), [scaling](<https://devfeed.tech/topics/scaling.md>), [sha256](<https://devfeed.tech/topics/sha256.md>), [hash](<https://devfeed.tech/topics/hash.md>), [Database](<https://devfeed.tech/topics/database.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [disk-space](<https://devfeed.tech/tags/disk-space.md>), [hashing](<https://devfeed.tech/tags/hashing.md>), [mathematics](<https://devfeed.tech/tags/mathematics.md>), [performance](<https://devfeed.tech/tags/performance.md>), [postgres](<https://devfeed.tech/tags/postgres.md>), [programming](<https://devfeed.tech/tags/programming.md>), [refactor](<https://devfeed.tech/tags/refactor.md>), [riemann-hypothesis](<https://devfeed.tech/tags/riemann-hypothesis.md>), [scaling](<https://devfeed.tech/tags/scaling.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [software](<https://devfeed.tech/tags/software.md>)

### AI overview

This article describes scaling a search for counterexamples to the Riemann Hypothesis. It focuses on reducing storage by keeping deterministic SHA-256 summaries instead of every witness value and refactoring the application into a worker architecture.

### Source excerpt

We're ironically searching for counterexamples to the Riemann Hypothesis. Setting up Pytest Adding a Database Search Strategies Unbounded integers Deploying with Docker Performance Profiling Last time we made the audacious choice to remove primary keys from the RiemannDivisorSums table for performance reasons. To help with that, we will do two things in this post Reduce the storage footprint of the whole application (it was 60 GiB when it crashed, and we got up to 84 prime factors).

## How (not) to sign a JSON object

DevFeed: [How (not) to sign a JSON object](<https://devfeed.tech/articles/how-not-to-sign-a-json-object-29172.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2019/07/24/how-not-to-sign-json/>)

Published: 2019-07-24T12:50:00Z

Content type: tutorial

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [JSON](<https://devfeed.tech/topics/json.md>), [API](<https://devfeed.tech/topics/api.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [ECDSA](<https://devfeed.tech/topics/ecdsa.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [ecdsa](<https://devfeed.tech/tags/ecdsa.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [json](<https://devfeed.tech/tags/json.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [signing](<https://devfeed.tech/tags/signing.md>)

### AI overview

The article explains how to authenticate JSON data in transit. It recommends HMAC-based symmetric signing for most cases, while noting that embedding a signature inside a JSON object creates parsing and interoperability challenges.

### Source excerpt

Last year we did a blog post on interservice auth. This post is mostly about authenticating consumers to an API. That's a related but subtly different problem: you can probably impose more requirements on your internal users than your customers. The idea is the same though: you're trying to differentiate between a legitimate user and an attacker, usually by getting the legitimate user to prove that they know a credential that the attacker doesn't.

## ESP32 OTA Updates -- Amazon FreeRTOS

DevFeed: [ESP32 OTA Updates -- Amazon FreeRTOS](<https://devfeed.tech/articles/esp32-ota-updates-amazon-freertos-13856.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/esp32-ota-updates-amazon-freertos/>)

Author: John Lee

Published: 2018-09-30T00:00:00Z

Content type: tutorial

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP32](<https://devfeed.tech/topics/esp32.md>), [Embedded Software Dev](<https://devfeed.tech/topics/embedded-software-dev.md>), [Security](<https://devfeed.tech/topics/security.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>)

Tags: [amazon](<https://devfeed.tech/tags/amazon.md>), [aws](<https://devfeed.tech/tags/aws.md>), [blog](<https://devfeed.tech/tags/blog.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [ecdsa](<https://devfeed.tech/tags/ecdsa.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [firmware-update](<https://devfeed.tech/tags/firmware-update.md>), [framework](<https://devfeed.tech/tags/framework.md>), [freertos](<https://devfeed.tech/tags/freertos.md>), [iot](<https://devfeed.tech/tags/iot.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [s3](<https://devfeed.tech/tags/s3.md>), [secure-boot](<https://devfeed.tech/tags/secure-boot.md>), [security](<https://devfeed.tech/tags/security.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [signing](<https://devfeed.tech/tags/signing.md>)

### AI overview

This tutorial explains how to perform secure Over-the-Air firmware updates on ESP32 using Amazon FreeRTOS and AWS services. It covers storing firmware in Amazon S3, signing and transmitting updates through an AWS OTA Job, verifying firmware on the device, and using ESP32 hardware security features such as secure boot.

### Source excerpt

ESP32 now supports secure Over-the-Air firmware updates with Amazon FreeRTOS. This enables users of ESP32 with Amazon FreeRTOS to: - Deploy new firmware on ESP32 in secure manner (single or group of devices, along with dynamic addition of new/re-provisioned device) - Verify authenticity and integrity of new firmware after its deployed - Extend OTA update security scheme to take leverage of hardware security features in ESP32 Working# At a high level, - The firmware image (or any other...

## The False Allure of Hashing for Anonymization

DevFeed: [The False Allure of Hashing for Anonymization](<https://devfeed.tech/articles/the-false-allure-of-hashing-for-anonymization-29671.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/hashing-for-anonymization/>)

Author: info@goteleport.com (Kevin Nisbet)

Published: 2018-04-30T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [hashing](<https://devfeed.tech/topics/hashing.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [data](<https://devfeed.tech/topics/data.md>), [sha256](<https://devfeed.tech/topics/sha256.md>)

Tags: [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [data](<https://devfeed.tech/tags/data.md>), [hashing](<https://devfeed.tech/tags/hashing.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [sha256](<https://devfeed.tech/tags/sha256.md>)

### AI overview

The article explains why cryptographic hashing, including SHA-256, does not by itself make personal data anonymous. Hashes of predictable values such as usernames and email addresses can be tested against guesses and identified.

### Source excerpt

Why using cryptographic hashes doesn't make data anonymous.

## Monolith to Microservice: Architecture Behind V2 Webhooks

DevFeed: [Monolith to Microservice: Architecture Behind V2 Webhooks](<https://devfeed.tech/articles/monolith-to-microservice-architecture-behind-v2-webhooks-35100.md>)

Original publisher: [Read original article](<https://engineroom.teamwork.com/monolith-to-microservice-architecture-behind-v2-webhooks-27789c36ace9?source=rss----cea4eecd5960---4>)

Author: Paulius Jakimavičius

Published: 2017-09-11T15:09:33Z

Content type: article

Language: en

Sources: [Teamwork](<https://devfeed.tech/sources/teamwork.md>)

Topics: [Microservice](<https://devfeed.tech/topics/microservice.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [JSON](<https://devfeed.tech/topics/json.md>), [XML](<https://devfeed.tech/topics/xml.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [callback](<https://devfeed.tech/topics/callback.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [go](<https://devfeed.tech/tags/go.md>), [http](<https://devfeed.tech/tags/http.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [json](<https://devfeed.tech/tags/json.md>), [microservice-architecture](<https://devfeed.tech/tags/microservice-architecture.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [teamwork](<https://devfeed.tech/tags/teamwork.md>), [teamwork-project](<https://devfeed.tech/tags/teamwork-project.md>), [webhooks](<https://devfeed.tech/tags/webhooks.md>), [xml](<https://devfeed.tech/tags/xml.md>)

### AI overview

This article explains the redesign of Teamwork Projects webhooks from a monolithic implementation to a Go microservice. The update supports multiple webhooks per event, sends complete datasets in JSON, XML, or form format, adds SHA-256 checksums, and uses more frequent retry intervals.

### Source excerpt

We've recently released an update to the Teamwork Projects webhooks feature and I was asked to do a tech talk on the topic, a recording of which can be found below. This article is a rough summary of the talk with further elaboration of the thought process behind some of our decisions, but in summary: We have a microservice written in Go. We now support multiple webhooks per-event We send full datasets in chosen format (JSON, XML or Form) We offer better security and integrity with sha256 checksums We have more frequent retry intervals. https://medium.com/media/1208334bf98663ab7d55e4d2eaad4c95/hrefWhat are Webhooks? The basic idea of webhooks is simple -- it's a HTTP POST call triggered when some event occurs. You can think of it like a JavaScript callback, except it's a HTTP POST that can be sent anywhere, to anyone -- not limited to a single codebase or domain. In the case of Teamwork Projects, we have a set list of possible events you can subscribe to, denoted in OBJECT.ACTION style, so for example TASK.CREATED or MESSAGE.DELETED. Previous Approach (v1) Our original approach was no more complicated than the concept of webhooks itself -- when any of the supported actions are taken in Projects, a "fireWebhook" function is called, which checks if they're enabled and if there is a webhook set up for that event. If all is good -- we make a cfhttp call to the relevant URL with the item ID, item type and the action taken, all encoded as form data. Now there are a few limitations with this approach which showed up as the number of webhook users increased over time: Only one webhook per event -- although it made sense as a sort of anti-spam measure initially, this resulted in a few inconveniences for our customers. For example, a user sets up a TASK.CREATED webhook that notifies a custom service which adds the task ID to their internal database. This would make it impossible for them to later set up, say a Zapier zap using TASK.CREATED event as it is already "in use". Limited

## FAQ: Upcoming Ethereum Hard Fork

DevFeed: [FAQ: Upcoming Ethereum Hard Fork](<https://devfeed.tech/articles/faq-upcoming-ethereum-hard-fork-16783.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2016/10/18/faq-upcoming-ethereum-hard-fork>)

Author: Hudson Jameson

Published: 2016-10-18T01:05:51Z

Content type: article

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Network](<https://devfeed.tech/topics/network.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Transactions](<https://devfeed.tech/topics/transactions.md>)

Tags: [blockchain](<https://devfeed.tech/tags/blockchain.md>), [communication](<https://devfeed.tech/tags/communication.md>), [community](<https://devfeed.tech/tags/community.md>), [consensus](<https://devfeed.tech/tags/consensus.md>), [developers](<https://devfeed.tech/tags/developers.md>), [download](<https://devfeed.tech/tags/download.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [fork](<https://devfeed.tech/tags/fork.md>), [network](<https://devfeed.tech/tags/network.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [protocol-announcements](<https://devfeed.tech/tags/protocol-announcements.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [sync](<https://devfeed.tech/tags/sync.md>), [transactions](<https://devfeed.tech/tags/transactions.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

This FAQ explains the planned Ethereum hard fork at block 2463000, including the need for clients to upgrade and the consequences of remaining on the pre-fork chain. It also describes network delays caused by a denial-of-service attack and the protocol changes intended to address it.

### Source excerpt

The Ethereum network will be undergoing a hard fork at block number 2463000, which will likely occur between 12:00 and 13:00 UTC on Tuesday, October 18, 2016. A countdown timer can be seen at https://fork.codetract.io/....

## 3 Wrong Ways to Store a Password

DevFeed: [3 Wrong Ways to Store a Password](<https://devfeed.tech/articles/3-wrong-ways-to-store-a-password-32089.md>)

Original publisher: [Read original article](<https://adambard.com/blog/3-wrong-ways-to-store-a-password/>)

Published: 2013-07-11T00:00:00Z

Content type: tutorial

Language: en

Sources: [Adam Bard](<https://devfeed.tech/sources/adam-bard.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [hashing](<https://devfeed.tech/topics/hashing.md>), [PHP](<https://devfeed.tech/topics/php.md>), [Web Development](<https://devfeed.tech/topics/web-development.md>), [Database](<https://devfeed.tech/topics/database.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [database](<https://devfeed.tech/tags/database.md>), [hashing](<https://devfeed.tech/tags/hashing.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [php](<https://devfeed.tech/tags/php.md>), [salt](<https://devfeed.tech/tags/salt.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [web-development](<https://devfeed.tech/tags/web-development.md>)

### AI overview

This tutorial explains common unsafe password-storage approaches, including plaintext storage, unsalted hashing, and fast hashing with a salt. It describes how database compromise, dictionary attacks, and rainbow tables can expose passwords, and introduces safer password-storage practices without fully detailing them in the supplied excerpts.

### Source excerpt

Sooner or later, in the field of Web Development, you're going to need to store someone's password. This is easy to get wrong, but easy to get right, too. Today, let's take a tour of the wrong ways, and then find out how to do it the (current) right way. Plaintext Alice just learned PHP, and are making an app with user authentication. Her database stores an email and password in a table called users.