2026-08-02 02:00:00
Long-time Slashdot reader Qbertino writes: The northern German City of Hamburg is currently in the process of replacing one of its bridges in one single gigantic piece. The new replacement weighs 3700 metric tons and was carefully moved into place over a stretch of 500 meters, requiring extreme patience and precision maneuvering. Some places leave only 40 cm of room to neighbouring buildings.
Read more of this story at Slashdot.
2026-08-02 01:00:00
"GitHub and the Python Package Index (PyPI) have introduced new policies meant to boost supply chain security," reports SecurityWeek, "by preventing the fast propagation of poisoned package versions and the poisoning of old and long-stable releases." To prevent the fast delivery of malicious code through the immediate fetching of brand-new releases, GitHub has introduced a Dependabot cooldown, where the automation tool waits for at least three days after a release has been published before opening a pull request. "Waiting a few days before adopting a new release gives maintainers, security researchers, and automated scanners time to spot a malicious version and get it pulled before it ever reaches your pull requests," GitHub explains. The three-day cooldown only applies to non-security version bumps, and the behavior can be modified through the configuration option in the dependabot.yml. "Three days as the default balances two goals: it pushes you past the window where most of these attacks live, and it doesn't hold your dependencies back longer than necessary," GitHub notes. And the Python Package Index (PyPI) "now rejects new files being uploaded to releases that are older than 14 days," according to a recernt blog post from the Python Software Foundation's security developer-in-residence Seth Larson: This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised... The discussion of this behavior began during PEP 740 (Digital Attestations) back in January 2024. The discussion was restarted in March 2026 after the popular packages LiteLLM and Telnyx were compromised. These packages were compromised due to a "mutable reference" in these projects' usage of the Trivy GitHub Action... To quantify how disruptive this change would be to existing workflows, the PyPI database was queried for projects that have published new files to old releases... [O]nly 56 projects of 15,000 had published a [Python] 3.14-compatible wheel more than 14 days after a release was available. This topic was brought to the Packaging Summit at PyCon US 2026 by PyPI Safety & Security Engineer, Mike Fiedler. The rough consensus of the discussion was that the summit attendees thought it was "acceptable to require users to bump to the next version" to support new Python versions. With the data and consensus in hand, Seth moved forward with a patch to reject new files on old releases which was merged July 8th, 2026.
Read more of this story at Slashdot.
2026-08-02 00:00:00
Electric vehicles have historically been "notorious" for losing their resale value, reports CNBC. But this year prices for used EVs in the U.S. "are up 5.1% from January to June 2026, according to a Recurrent analysis published this month." The trend continued into the second half of the year: Prices are up 7% year to date through mid-July, it said. Recurrent compared EVs according to the same make and model year across 108 combinations and weighted price growth according to inventory volume. "Used EVs are appreciating, which almost never happens," according to an e-mailed Recurrent statement about the analysis. Other auto analysts found a similar trend... Price growth for used EVs has been broad-based, said Stephanie Valdez Streaty, the director of industry insights at Cox Automotive, a market research firm. Twenty-one of the 25 used EV models with the highest sales volume increased in price between January and June this year, she said... [T]he price growth for used EVs this year has been all the more surprising because it has happened despite a high supply of used EVs hitting the market — which, all else being equal, would generally cause prices to fall, experts said... There are several factors juicing consumer demand for used EVs, experts said. Among them are high gasoline prices due to the Iran war, which have pushed more consumers to consider fuel-efficient options, experts said... Overall affordability is another big factor, against a backdrop of inflation that has remained above policymakers' target of 2% for five or so years, auto experts said. The dynamic has pushed more consumers toward the used car market more broadly. Two interesting statistics from the article: "Used EV sales were up 20% in June versus a year earlier, while sales of new EVs were down about 28%, according to Cox Automotive data." New EVs accounted for 5.4% of total new-vehicle sales in June, while the market share for used EVs was just 2.4%, according to Cox Automotive data.
Read more of this story at Slashdot.
2026-08-01 23:00:00
An anonymous reader quotes a report from Ars Technica: We are a month away from the initial rollout of Google's Android developer verification system, and the company contends this policy does not impinge on the platform's open nature. Still, the restrictions will be a big change, and there are still some unanswered questions. An issue that has come up repeatedly in the run-up to verification is what will happen to devs who can't verify because of where they live. It turns out that Google has a cryptic answer for that buried in an FAQ. Developer verification will soon block the installation of apps from unverified developers on any Android device running Google services, which is functionally all Android phones outside Russia and China. Developers who want to keep releasing software, even if it's not in the Play Store, have to provide Google with their ID and pay a small fee. But what if you're an Android developer living in a sanctioned nation? Currently, the U.S. sanction list includes Iran, Cuba, North Korea, and occupied areas of Ukraine. Given the current uncertain state of US foreign policy, that list could change in the future. Google doing any business with developers in those places is a thorny issue, and it seems like the company has decided to just leave them hanging. A rather lengthy FAQ a few levels deep on the Google developer site addresses various issues around dev verification. Smack in the middle is this: "How does this program impact developers in sanctioned countries? Devices in sanctioned countries will be excluded from Android developer verification checks. This allows any developer to continue distributing apps in these regions without verification, though users there won't benefit from the enhanced security benefits of the program." [...] A Google spokesperson has expanded on the FAQ and confirmed to Ars that people living in sanctioned nations will not be allowed to go through the verification process. That means they will not be able to effectively distribute software through any channel internationally. Today, someone making an app in, say, Cuba can distribute it freely around the world, as well as at home. Anyone can install it and see their work in action after tapping through a few sideloading alerts. In the coming months, that will no longer be the case. These unverified apps will only be easily installable in the sanctioned countries where verification doesn't exist.
Read more of this story at Slashdot.
2026-08-01 19:00:00
The U.S. company Meteomatics has created an automated weather-monitoring system that uses drones to collect atmospheric data at multiple altitudes before returning to recharge and upload their findings. The so-called Meteobase, which consists of a base station on the ground with a drone that can be launched and recovered automatically, "is highly weather resistant and keeps the drone at a comfortable temperature," reports The Guardian. "It can send out one data-gathering mission a day, or multiple flights to monitor fog, icing, an advancing weather front, or other fast-changing conditions." The report says the reusable drones could offer a cheaper, more controllable alternative to helium weather balloons, especially for tracking rapidly changing conditions.
Read more of this story at Slashdot.
2026-08-01 15:00:00
"Space.com and The Guardian are reporting that the Falcon 9 upper stage leftover from the launch of the Firefly Blue Ghost-1 lander on Jan. 15, 2025 is due to impact the Moon on Aug. 5, 2026," writes longtime Slashdot reader fahrbot-bot. From a report: Onboard the same flight was the Hakuto-R Mission 2, called Resilience, a robotic lunar lander developed by the Japanese company ispace. According to a new study by an international team, the resulting impact plume may briefly be bright enough to see against the dark sky near the moon's edge. That means it might be visible to moongazers with sufficiently sensitive telescopes. This head-on collision of the errant stage is expected to occur near the Einstein and Bell craters near the western lunar limb. It may well be visible to ground and space-based assets. Using special physics simulations to model the impact, William Jo, a graduate research assistant at the University of Texas, Austin and colleagues predict the debris plume from the impact will have the central ejecta spike reaching roughly 47 miles to over 60 miles (75 kilometers to 100 kilometers) altitude. "Our calculations suggest the plume should be several orders of magnitude brighter than the dark-sky background for the first few minutes after impact," Jo told Space.com. "So the plume should be visible, though I'd stress this is a single nominal case. The real one will look different, and the numbers are on the optimistic side. But the point worth making is that the flash isn't really the story here." Jo emphasized that there's great slam-dunk science to be had. "Watching this one gives us a rare chance to open up ejecta-plume science and calibrate those models against a real event, which matters for every future thing we deliver to the moon," Jo said.
Read more of this story at Slashdot.