Skip to main content

Posts

Upgrading Dependency Track from v4 to v5

Dependency Track is an open source component analysis platform from OWASP. You upload the SBOM of your application, and Dependency Track keeps track of the components inside it. It checks those components against vulnerability sources like the National Vulnerability Database, GitHub Advisories and OSV. It also lets you define policies and send notifications when something new shows up. In short: it tells you which of your applications are affected when the next vulnerable library hits the news. Recently Dependency Track got an upgrade and version 5 was released. So, time to upgrade! However, that turned out not to be as easy as expected. It took us 2 attempts. Our first attempt failed completely, so we took a different route. Here is what we tried and the two things that cost us the most time. Big shout out to Jef, who looked over my shoulder during the upgrade and helped tackling the issues when we got stuck. Two approaches in the documentation The Dependency Track documenta...
Recent posts

Docker: No space left on device

Recently I tried to spin up a new container and Docker refused with this error: OSError: [Errno 28] No space left on device: Not the most helpful message, but the root cause was simple: the disk used by the Docker engine was full. As you can see in the screenshot below, I was eating up almost the full 250GB available for Docker: Where did my disk space go? Before deleting anything, let's find out what is actually using the space. Docker has a built-in command for this: docker system df This gives you a summary of the space used by images, containers, local volumes and build cache. Want more detail per item? Add the verbose flag: docker system df -v In my case, the usual suspects were to blame: old images, stopped containers and build cache that had been piling up for months. Cleaning up Start with the safest options and work your way up. Remove all stopped containers: docker container prune Remove dangling images (untagged layers that are no longer refer...

Auto-accepting AI edits in VS Code

When you let Copilot edit your code in agent mode, every change waits for a decision: Keep or Undo. For a small change that's fine. After ten prompts in a row, you're clicking Keep more than you're reading code. VS Code has a setting to take that click away. Why do we need this? By default, edits from chat are pending until you accept or discard them. The pending state survives closing VS Code, so you can come back later and still decide. That's a good default. But if you already review everything in a diff before you commit, the extra step per edit adds little. Accept edits after a delay Add this to your settings.json : "chat.editing.autoAcceptDelay": 5 Edits are now accepted automatically after the delay. The default is 0 , which means auto-accept is disabled. You are not locked out. While the countdown runs, hover over the editor overlay controls to cancel it, and you can still Undo afterwards. Keep approval for sensitive files Auto-...

Guid.CreateVersion7() is NOT a sequential guid for SQL Server

I think that is the clearest blog title I used in years. Why do I mention this? Let me explain... Some time ago we stumbled over a performance issue in our applications. The root cause was a fragmented index, caused by the usage of a standard guid instead of a sequential guid. While looking for the right fix, I had to revisit one of my own posts: Sequential GUIDs with .NET 9 . In that post I mentioned that you can use Guid.CreateVersion7() to create a sequential guid. That is technically correct, but it is NOTa solution for SQL Server. Why does a random guid hurt? A clustered index in SQL Server is a sorted B-tree. When the key is random, every insert lands on a random page. If that page is full, SQL Server has to split it, which leaves you with half-empty pages, a fragmented index and more I/O. A sequential key always appends at the end, so pages fill up and stay put. Why is a version 7 guid not sequential for SQL Server? A UUID version 7 (RFC 9562) starts with a 48-bit U...

GitHub Copilot auto mode: should you disable models?

An architect in one of our teams selected auto mode in GitHub Copilot and ended up on a high-cost model. Nothing was broken, auto did what it is designed to do. But it was the trigger for a broader discussion: Should we disable some (of the more expensive) models? What does auto actually do? Auto looks at every prompt and selects the model that is best suited for it. The choice is based on task complexity and model availability. Usage is charged based on the model auto selects, so a heavy reasoning model means a heavy bill. The models auto can choose from are limited by your plan and by policy. Organization owners can enable or disable a model under Settings > Copilot > Models . However, be aware that by default every model that becomes generally available is on by default for GitHub Copilot Business and Enterprise. If you want to approve every model yourself, disable the "Default availability for released models" policy. Disable a model here and auto will...

Hot Exit in Visual Studio

Hot Exit. It sounds like what you do when the fire alarm goes off. Or like Visual Studio leaving the room in a hurry. It's neither. Hot Exit means you can close Visual Studio with unsaved changes and find everything still there when you start it again. That solves a problem you probably know. You close Visual Studio at the end of the day with a few files half-edited, and it asks what to do with them. Save them and you end up with code that doesn't compile. Discard them and the work is gone. So you click Save All, tell yourself you'll fix it tomorrow, and hope you remember what you were doing. VS Code users stopped worrying about this a long time ago. Hot exit arrived in VS Code 1.8. Visual Studio finally has its own version. What is Hot Exit? When you close Visual Studio, Hot Exit stores the state of your session. The next time you start it, your open documents, edits and unsaved changes are restored, so you don't have to save anything manually. Hot Exit p...

A weekly stocktake for your skills

After my posts about automations, I got some questions about other examples where I use this feature. One I like to share is a weekly check that validates my current list of installed skills. Why do we need this? Skills are easy to add and easy to forget. Over time you collect skills that overlap, skills that point to tools that changed, and skills you no longer use. I wanted a recurring check that tells me how to cleanup my skills list. Starting from an existing skill I didn't start from scratch. The ECC repository contains a skill-stocktake skill for Claude Code. It's a /skill-stocktake slash command that audits the skills in ~/.claude/skills/ and the project-level .claude/skills/ , and it has two modes: Quick Scan: re-evaluates only the skills that changed since the last run. Full Stocktake: a complete review. Under the hood it uses shell scripts, a results.json cache, and subagents that evaluate the skills in batches of about 20. That's a ...