frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Automating Firmware Security: CI for DBX and Microcode Updates in Dasharo

https://blog.3mdeb.com/2025/2025-05-29-dasharo-ci/
4•mkopec•5h ago

Comments

pietrushnic•5h ago
Keeping UEFI Secure Boot DBX and CPU microcode up to date in CI pipelines can be challenging, especially if you want to automate the process and stay in sync with upstream security updates.

One approach we explored involved adding mechanisms for automatic DBX updates (UEFI Secure Boot revocation lists) and CPU microcode refresh to CI workflows, as described in this blogpost. The goal was to reduce manual steps when integrating updated DBX payloads and microcode packages, while enabling early detection of regressions during firmware validation.

By making these updates part of the reproducible build process, it becomes easier to maintain supply-chain transparency and strengthen platform resilience against known vulnerabilities.

Presentation describing the implementation: https://cfp.3mdeb.com/developers-vpub-0xf-2025/talk/3KFCDR/

The Art of Incident Management Pt. 1

https://rootly.com/blog/the-art-of-incident-management-part-i
1•rootlyhq•2m ago•0 comments

Trusted Publishing for NPM Packages

https://docs.npmjs.com/trusted-publishers/
1•jmsmtn•3m ago•0 comments

Replacing SGX with GitHub Actions: Or How to Turn GitHub Actions into a Trusted

https://www.ethanheilman.com/x/35/index.html
1•todsacerdoti•3m ago•0 comments

Ukraine Unmanned Drone Tracker

https://sbs-group.army/
1•throwoutway•4m ago•1 comments

OCR and RAG for Tables

https://mrm1001.github.io/2025/09/09/ocr-to-rag-for-tables.html
1•mariarmestre•4m ago•0 comments

Rabbit have overhauled the OS as rabbitOS2

https://www.rabbit.tech
1•simonjgreen•5m ago•0 comments

How to Build Python Code with Bazel (and Why)

https://ohadravid.github.io/posts/2025-09-hello-bazel/
1•todsacerdoti•5m ago•0 comments

Show HN: Bifrost – The Build Service for NativePHP Apps

https://bifrost.nativephp.com/
1•simonhamp•5m ago•0 comments

AQAP likely to encourage further popular protests in Hadramaw

https://www.janes.com/osint-insights/defence-and-national-security-analysis/aqap-very-likely-to-e...
1•vinnyglennon•5m ago•0 comments

Google to Obey South Korean Order to Blur Satellite Images on Maps

https://www.barrons.com/news/google-to-obey-south-korean-order-to-blur-satellite-images-on-maps-6...
1•gnabgib•6m ago•0 comments

All unimaginery internet futures are in one place.(free) try now

https://sites.google.com/view/rrrpromex/alpha
1•RRR_pro_•7m ago•0 comments

Show HN: DJI360 – DJI Product News and Buying Guide Platform

https://dji360.com
1•sjdeak•8m ago•0 comments

How to Use Claude Code Subagents to Parallelize Development

https://zachwills.net/how-to-use-claude-code-subagents-to-parallelize-development/
2•zachwills•11m ago•1 comments

India turns to alternative motors amid China's rare earth cut offs

https://www.reuters.com/world/china/india-revs-up-alternate-ev-motor-tests-china-curbs-rare-earth...
2•chiffre01•11m ago•0 comments

Could a giant dam save the Atlantic currents that keep Europe warm?

https://www.science.org/content/article/could-giant-dam-save-atlantic-currents-keep-europe-warm
2•pseudolus•12m ago•0 comments

Eat Your Vegetables Before AI Dessert

https://writings.alethia.news/product-observability-institutions-the-vegetables-we-have-to-eat-ar...
3•truelson•14m ago•0 comments

Toolkit to help you get started with Spec-Driven Development

https://github.com/github/spec-kit
2•msis•14m ago•0 comments

Goals per Week: A Proven Productivity Method for Stem Professionals – Execute3

https://www.execute3.com/blog/stem
2•evchay•14m ago•0 comments

Show HN: Run any GUI app in the terminal with term.everything

https://github.com/mmulet/term.everything
2•ghub-mmulet•16m ago•0 comments

$1.1M for a Logo, Austin [video]

https://www.youtube.com/watch?v=z_ZuGECyCJs
2•thelastgallon•16m ago•0 comments

I love UUID, I hate UUID

https://blog.epsiolabs.com/i-love-uuid-i-hate-uuid
2•dkgs•17m ago•0 comments

Show HN: I built a Markdown to HTML converter that fixes AI-generated quirks

https://www.markdownhtmlgen.com/
2•zongheng•18m ago•0 comments

Show HN: Find Your Perfect Pair of Overalls

https://overallsshop.com/
2•yangyiming•18m ago•0 comments

Show HN: AI agent that clones viral content structures to automate social growth

https://synthmind.app/
2•Jilong121•19m ago•1 comments

New Data Science LLM Benchmark

https://proud-botany-7dd.notion.site/Benchmark-Evaluation-21c530f165ec806b877aefc635bed097?source...
2•cmendez•20m ago•0 comments

Microsoft inks AI infra deal with Yandex cofounder's biz for nearly $20B

https://www.theregister.com/2025/09/09/microsoft_inks_near_20b_deal/
2•rntn•20m ago•0 comments

Preparing for the Worst

https://daniel.haxx.se/blog/2025/09/09/preparing-for-the-worst/
2•renehsz•21m ago•0 comments

'It's back to the future': the 13th-century castle built by hand in France

https://www.theguardian.com/world/2025/aug/23/13th-century-castle-built-by-hand-in-france-guedelon
1•PaulHoule•21m ago•0 comments

Show HN: Next Home Game – Crowd-avoidance alerts for UK football matches

https://nexthomegame.co.uk/
1•richelectron•22m ago•0 comments

A Love Letter to Internet Relay Chat

https://hackaday.com/2025/09/08/a-love-letter-to-internet-relay-chat/
1•renehsz•23m ago•0 comments