frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

GPT-5.3-Codex System Card [pdf]

https://cdn.openai.com/pdf/23eca107-a9b1-4d2c-b156-7deb4fbc697c/GPT-5-3-Codex-System-Card-02.pdf
1•tosh•1m ago•0 comments

Atlas: Manage your database schema as code

https://github.com/ariga/atlas
1•quectophoton•4m ago•0 comments

Geist Pixel

https://vercel.com/blog/introducing-geist-pixel
1•helloplanets•6m ago•0 comments

Show HN: MCP to get latest dependency package and tool versions

https://github.com/MShekow/package-version-check-mcp
1•mshekow•14m ago•0 comments

The better you get at something, the harder it becomes to do

https://seekingtrust.substack.com/p/improving-at-writing-made-me-almost
2•FinnLobsien•16m ago•0 comments

Show HN: WP Float – Archive WordPress blogs to free static hosting

https://wpfloat.netlify.app/
1•zizoulegrande•17m ago•0 comments

Show HN: I Hacked My Family's Meal Planning with an App

https://mealjar.app
1•melvinzammit•17m ago•0 comments

Sony BMG copy protection rootkit scandal

https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal
1•basilikum•20m ago•0 comments

The Future of Systems

https://novlabs.ai/mission/
2•tekbog•21m ago•1 comments

NASA now allowing astronauts to bring their smartphones on space missions

https://twitter.com/NASAAdmin/status/2019259382962307393
2•gbugniot•25m ago•0 comments

Claude Code Is the Inflection Point

https://newsletter.semianalysis.com/p/claude-code-is-the-inflection-point
3•throwaw12•27m ago•1 comments

Show HN: MicroClaw – Agentic AI Assistant for Telegram, Built in Rust

https://github.com/microclaw/microclaw
1•everettjf•27m ago•2 comments

Show HN: Omni-BLAS – 4x faster matrix multiplication via Monte Carlo sampling

https://github.com/AleatorAI/OMNI-BLAS
1•LowSpecEng•28m ago•1 comments

The AI-Ready Software Developer: Conclusion – Same Game, Different Dice

https://codemanship.wordpress.com/2026/01/05/the-ai-ready-software-developer-conclusion-same-game...
1•lifeisstillgood•30m ago•0 comments

AI Agent Automates Google Stock Analysis from Financial Reports

https://pardusai.org/view/54c6646b9e273bbe103b76256a91a7f30da624062a8a6eeb16febfe403efd078
1•JasonHEIN•33m ago•0 comments

Voxtral Realtime 4B Pure C Implementation

https://github.com/antirez/voxtral.c
2•andreabat•35m ago•1 comments

I Was Trapped in Chinese Mafia Crypto Slavery [video]

https://www.youtube.com/watch?v=zOcNaWmmn0A
2•mgh2•42m ago•0 comments

U.S. CBP Reported Employee Arrests (FY2020 – FYTD)

https://www.cbp.gov/newsroom/stats/reported-employee-arrests
1•ludicrousdispla•43m ago•0 comments

Show HN: I built a free UCP checker – see if AI agents can find your store

https://ucphub.ai/ucp-store-check/
2•vladeta•49m ago•1 comments

Show HN: SVGV – A Real-Time Vector Video Format for Budget Hardware

https://github.com/thealidev/VectorVision-SVGV
1•thealidev•50m ago•0 comments

Study of 150 developers shows AI generated code no harder to maintain long term

https://www.youtube.com/watch?v=b9EbCb5A408
1•lifeisstillgood•50m ago•0 comments

Spotify now requires premium accounts for developer mode API access

https://www.neowin.net/news/spotify-now-requires-premium-accounts-for-developer-mode-api-access/
1•bundie•53m ago•0 comments

When Albert Einstein Moved to Princeton

https://twitter.com/Math_files/status/2020017485815456224
1•keepamovin•55m ago•0 comments

Agents.md as a Dark Signal

https://joshmock.com/post/2026-agents-md-as-a-dark-signal/
2•birdculture•56m ago•0 comments

System time, clocks, and their syncing in macOS

https://eclecticlight.co/2025/05/21/system-time-clocks-and-their-syncing-in-macos/
1•fanf2•58m ago•0 comments

McCLIM and 7GUIs – Part 1: The Counter

https://turtleware.eu/posts/McCLIM-and-7GUIs---Part-1-The-Counter.html
2•ramenbytes•1h ago•0 comments

So whats the next word, then? Almost-no-math intro to transformer models

https://matthias-kainer.de/blog/posts/so-whats-the-next-word-then-/
1•oesimania•1h ago•0 comments

Ed Zitron: The Hater's Guide to Microsoft

https://bsky.app/profile/edzitron.com/post/3me7ibeym2c2n
2•vintagedave•1h ago•1 comments

UK infants ill after drinking contaminated baby formula of Nestle and Danone

https://www.bbc.com/news/articles/c931rxnwn3lo
1•__natty__•1h ago•0 comments

Show HN: Android-based audio player for seniors – Homer Audio Player

https://homeraudioplayer.app
3•cinusek•1h ago•2 comments
Open in hackernews

You can now uv run a GitHub gist

https://github.com/astral-sh/uv/pull/15058/files
33•BiteCode_dev•6mo ago

Comments

BiteCode_dev•6mo ago
You know how you can "uv run" python code from a text file using just a URL?

No? Well, you can:

uv run https://pastebin.com/raw/RrEWSA5F

And since yesterday, you can even run a github gist:

uv run https://gist.github.com/charliermarsh/ea9eab7f56b1b3d41e5196...

unglaublich•6mo ago
Or more generally, pipe your script into stdin.

> print("hi")' | uv run -

> curl https://pastebin.com/raw/RrEWSA5F | uv run -

abraham•6mo ago
You can also get text from Gists by add .txt

https://gist.github.com/charliermarsh/ea9eab7f56b1b3d41e5196...

BiteCode_dev•6mo ago
This is what the code does more or less.
charcircuit•6mo ago
"uv run" seriously needs a sandbox. Running arbitrary code from arbitrary dependencies with 0 version locking provides no guarantees on what you are actually running.
unglaublich•6mo ago
You can by set dependencies explicitly in the script's header.

https://docs.astral.sh/uv/guides/scripts/#declaring-script-d...

BiteCode_dev•6mo ago
uv run is using virtual envs, that's the de facto standard, and those are sandboxes for python deps. So it already is.

Plus inline deps mean you can pin python versions and 3rd party modules using pyproject.toml syntax in a comment of your script. This is not perfect locking, as it doesn't pin sub dependencies, but it's already more that any other tool out there.

If you want perfect locking, create a project, and use uv lock. You are already in a different category of code.

simonw•6mo ago
OP isn't talking about virtual environment style sandboxing, they're talking about sandboxes that prevent arbitrary code from deleting or stealing any information your user account has access to on your computer.
throwaway290•6mo ago
Run it in a Docker container?
cedws•6mo ago
Docker isn’t a sandbox and shouldn’t be treated like one. Admittedly if I’m going to run untrusted code I’ll run it in Docker, but I’m aware that whatever I’m running could break out. I wouldn’t blindly run some bullshit even in Docker unless I’m 90% sure it’s safe already.
throwaway290•6mo ago
How do you get to 90% sure for code that has any dependencies?
OutOfHere•6mo ago
Why is Docker (or extensions thereof) not a sandbox? Granted, it could access the internet, but that's necessary.
cedws•6mo ago
Docker's primary purpose is to give applications their own namespaces in which they can run without conflict. It does confine applications to their own root filesystem, own process namespace and so on, but this isn't intended as a security boundary. cgroup escapes happen.

Firecracker and gVisor provide much stronger isolation. Both are battle tested; clouds run millions of multi-tenant workloads on these every day. Docker would simply never even be a candidate for this purpose.

integralid•6mo ago
>but I’m aware that whatever I’m running could break out

If you have a working docker escape exploit at hand, that works on unprivileged containers, you can earn some good money. Just saying.

Docker was not created as a sandbox, but people rely on it for security and it is a sandbox at this point. Hell, containerd is one of kuberbetes backends and it absolutely relies on it being a secure sandbox.

BiteCode_dev•6mo ago
This has been attempted many times with python, and always been a failure because of the dynamism of the language, even by big actors.

The solution, therefor, as always been to use the OS tooling for that. Even the .Net ecosystem eventually went into that direction.

The JS ecosystem is making that mistake right now, and will of course, deprecate this API in 10 years after they realize they can't make it secure either unless they basically reimplement BSD jails entirely.

simonw•6mo ago
Deno has had this feature for five years already, since May 2020: https://deno.com/blog/v1
simonw•6mo ago
Implementing sandboxes is really hard... but Astral are demonstrable great at solving hard problems. I dream of them one day saying "we've solved sandboxing for Python scripts" ala Deno https://docs.deno.com/runtime/fundamentals/security/
indigodaddy•6mo ago
There’s lots of options not native to the tool. Just a few:

devbox on MacOS.

distrobox/toolbx on Linux.

Project Bluefin has some really good ideas and concepts about all this: https://docs.projectbluefin.io/bluefin-dx/

rjh29•6mo ago
That's the job of docker or systemd-nspawn. It shouldn't be implemented by every single command.
OutOfHere•6mo ago
devcontainer builds upon it to further the sandbox.
mvieira38•6mo ago
Why is it their job to check for security? Sandboxing would make the ergonomics significantly worse for running quick scripts with uv run --script
cipehr•6mo ago
I took gp’s comment to mean something more like deno. Deno is nice because you can explicitly allow/deny filesystem, network, etc. in an ergonomic way like `—-allow-fs`

So not sure it would necessarily be ergonomically worse. It could even be a new run command `uv srun` or something…

indigodaddy•6mo ago
But uv isn’t a framework, isn’t that the difference, ie why they wouldn’t necessarily think it’s appropriate to delve into that particular territory?
charcircuit•6mo ago
This is like asking why do web browsers need to sandbox javascript. Giving full permissions to untrusted code is an attacker's dream.
kortex•6mo ago
It might be a cool thing for them to provide some kind of container metadata in the `# /// script` block so that e.g. it automatically runs the script in a container.
vs4vijay•6mo ago
Maybe use along with "Pyodide"?
drewbitt•6mo ago
I have seen several Pyodide in Deno implementations lately.
paulbirch•6mo ago
This is an interesting development, especially considering the growing trend of code-sharing platforms. As others have pointed out, this move by GitHub to allow UV to run GitHub Gists blurs the lines between code hosting and execution environments. It's worth noting that this also puts UV in direct competition with other code execution services like Repl. it and Google Colab, both of which have been gaining traction in the developer community. I'm curious to see how UV will differentiate itself in this crowded space.
vs4vijay•6mo ago
Did you even read the article?
kelsolaar•6mo ago
Mmmmh I have been running from gists for ages, just use the full url as parameter...