frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: Slow Down

10•jacquesm•3h ago
The number of supply chain attacks and the blast radius as a result of these is ever increasing. The big culprits are languages that are not just languages but whole eco-systems, where stuff that should be 'batteries included' ends up in a massive stack of libraries and modules that nobody can be bothered to review.

This doesn't scale. Reviewing all of this code by all of the potential users is just asking for it, the bulk of them did not have the resource to write the module/library in the first place so they most likely will not have the resources to review everything they ingest.

I'm trying to imagine Linux with not one distribution but several thousand each of which could become malicious at the drop of a hat. In the longer term this will not work. All of these systems can only work in a world where there are no bad actors and where you implicitly trust the source.

Please improve curation. The next supply chain bug may well be 'the big one' and I'm pretty sure that various nation states are aiming to achieve that kind of capability now that there are ample proofs of concept out there. We need fewer points of distribution with better curation and far stricter review before inclusion, something along the lines of the Linux Kernel.

We do not need these crazy high release speeds with daily updates all over the stack, then you should just slow down and do better QA.

Reliability comes from the ability to invest the time review and increase understanding, not from the ability to release at breakneck speed, use your downstream as QA and then to fix things when you get them wrong. If it was coded today the world does not need it until tomorrow or even the day after tomorrow. Having a 'hot path' from your development environment to release that is fast also has the potential to export any compromise of your environment to your releases. More so if you accept external contributions to your code.

Comments

throwaw12•2h ago
> We do not need these crazy high release speeds with daily updates all over the stack

Although I like this, but I understand this is not easily achievable in companies where everyone is trying hard to grab the part of the market and AI FOMO and push by investors to release AI features

mikert89•2h ago
This isnt the problem, the problem is open source software became a status marker/way to build a company.
thiago_fm•1h ago
We can't slow down.

Executives want to see numbers go up, even if it's a vanity metric like LOC or PRs merged.

It feels we're mostly building liabilities, rather than assets.

Management will later grind us to fix it all, as this will trigger a huge crisis as nothing works anymore, and we will have to do it and pretend they didn't create the problems themselves, so we keep our jobs, in the most optimistic scenario.

Companies with good tech leadership will thrive in that environment, but they are so few...

kojeovo•46m ago
> The number of supply chain attacks and the blast radius as a result of these is ever increasing

Holy vague post... can u be specific?

Ask HN: Is Antigravity code search dropping results recently?

3•sankalpnarula•31m ago•0 comments

Ask HN: How do you feel when your coding assistant loses context?

3•noduerme•3h ago•8 comments

Tell HN: Slow Down

10•jacquesm•3h ago•4 comments

Claude Is Down Again

3•Venkymatam•1h ago•0 comments

Lazy Tmux – Lazy-loading tmux sessions with a tree view

2•Alchemmist•5h ago•0 comments

Claude Is Down

12•haebom•1h ago•8 comments

LLMs learn what programmers create, not how programmers work

37•noemit•1d ago•14 comments

Ask HN: AI productivity gains – do you fire devs or build better products?

107•Bleiglanz•3d ago•199 comments

Ask HN: Any recommended engineering/dev related Slack channels?

2•Kuraptka•11h ago•1 comments

Ask HN: How do you offload all coding to AI?

9•makingstuffs•14h ago•11 comments

Tell HN: Russians may soon lose access to the global internet

32•taminka•20h ago•14 comments

Ask HN: Do you feel less happy when coding with agent?

4•zane__chen•16h ago•9 comments

Does nobody care about not being able to copy from Slack anymore?

5•neal_caffrey•16h ago•3 comments

Is Trusttunnel easy for people to use?

2•AnonyMD•17h ago•0 comments

Ask HN: Founders of estonian e-businesses – is it worth it?

11•udl•1d ago•4 comments

Ask HN: Does the World need more software?

3•Vektorceraptor•18h ago•9 comments

Ask HN: Is anyone here also developing "perpetual AI psychosis" like Karpathy?

29•jawerty•1d ago•24 comments

Ask HN: Is using AI tooling for a PhD literature review dishonest?

9•latand6•1d ago•26 comments

Does it make sense to ask Blackberry to re-license ancient QNX sources?

4•ymz5•23h ago•3 comments

Ask HN: Analog Model of Transformers

7•JPLeRouzic•1d ago•2 comments

Ask HN: $50 monthly budget, which coding models would you recommend now?

10•klueinc•1d ago•18 comments

Ask HN: How does one get rich in 2026?

7•roschdal•4h ago•4 comments

Tell HN: H&R Block tax software installs a TLS backdoor

150•yifanlu•4d ago•12 comments

Ask HN: Is the AI software developer demand destruction narrative accurate?

4•RyanShook•15h ago•2 comments

Tell HN: MS365 upgrade silently to 25 licenses, tried to charge me $1,035

24•davidstarkjava•3d ago•8 comments

Anonymize / de-identify LLM chat history export, post-processing

2•msiraj1•1d ago•1 comments

Veevo Health – book a CT angiogram to see plaque buildup in your arteries

5•arvindsr33•1d ago•3 comments

Ask HN: If there has been no prompt injection, is it safe?

7•sayYayToLife•2d ago•8 comments

SparkVSR: Video Super-Resolution You Can Control with Keyframes

3•steveharing1•2d ago•0 comments

Anyone know how long it will take to re-start Qatar's helium plants?

9•megamike•3d ago•6 comments