frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: TimeLock NPM Registry

https://github.com/pyoner/timelock-npm-registry
2•pyoner•1h ago
Hi, everyone!

I built a TimeLock NPM Registry to prevent supply chain attack. I was inspired by minimumReleaseAge of the pnpm, but I'm using bun for my projects.

TimeLock NPM Registry is an alternative npm package registry focused on supply chain security.

Its core feature is introducing a time lock before new package versions become available for installation. This protects developers from compromised releases: while packages are “on hold,” the community and security tools have time to detect and block malicious code.

Why it matters Reduces the risk of installing malicious packages. Lets you “wait out” 24 hours or more before updating. Increases trust in dependencies and builds.

How it works

A package author publishes a new version. TimeLock NPM Registry places it into a pending state for a set duration (e.g., 24 hours). Only after the timer expires does the package become available for installation.

Tech stack — Cloudflare Workers, Honojs.

Modern Microprocessors: A 90-Minute Guide (2016)

https://www.lighterra.com/papers/modernmicroprocessors/
1•solfleur•11s ago•0 comments

Show HN: Mdchat – Markdown-first terminal / CLI tool for LLM collaboration

https://www.npmjs.com/package/mdchat
1•sarvesh21•33s ago•0 comments

Show HN: Gh-dep – TUI to batch review/merge Dependabot/Renovate PRs across repos

https://github.com/jackchuka/gh-dep
1•jackchuka•4m ago•0 comments

Unconstitutionality of the Trump administration's student deportation efforts

https://www.lawdork.com/p/judge-william-youngs-ruling-against
2•perihelions•6m ago•0 comments

The Temporal Dead Zone, why TypeScripts codebase is littered with var statements

https://vincentrolfs.dev/blog/ts-var
3•W4G1•6m ago•0 comments

Writing high-performance matrix multiplication kernels for Blackwell

https://docs.jax.dev/en/latest/pallas/gpu/blackwell_matmul.html
2•lairv•8m ago•0 comments

Windows 7 marketshare jumps to nearly 10% as Windows 10 support is about to end

https://www.neowin.net/news/windows-7-marketshare-jumps-to-nearly-10-as-windows-10-enters-final-w...
3•sznio•8m ago•0 comments

Apple reportedly scraps lighter Vision Pro in favor of smart glasses

https://www.tomsguide.com/computing/smart-glasses/apple-reportedly-scraps-vision-pro-headset-foll...
3•geox•9m ago•1 comments

Images show how antibiotics pierce bacterial armour

https://www.imperial.ac.uk/news/269074/amazing-images-show-antibiotics-pierce-bacterial/
1•gmays•9m ago•0 comments

An Anarchic Hacktoberfest Repository

https://github.com/xatuke/ai-search
1•satuke•11m ago•0 comments

Wealth tax would be deadly for French economy, says Europe's richest man

https://www.theguardian.com/business/2025/sep/21/wealth-tax-would-be-deadly-for-french-economy-sa...
2•PaulHoule•11m ago•0 comments

Noble's Coding Principles – Updated for the AI Era

https://derive.io/nobles-coding-principles/
1•vishal-derive•13m ago•0 comments

I Turned the Lego Game Boy into a Working Game Boy

https://blog.nataliethenerd.com/i-turned-the-lego-game-boy-into-a-working-game-boy-part-1/
2•todsacerdoti•14m ago•0 comments

In a Sea of Tech Talent, Companies Can't Find the Workers They Want

https://www.wsj.com/lifestyle/careers/in-a-sea-of-tech-talent-companies-cant-find-the-workers-the...
1•Bostonian•15m ago•3 comments

Autism should not be seen as single condition with one cause, say scientists

https://www.theguardian.com/society/2025/oct/01/autism-should-not-be-seen-as-single-condition-wit...
3•01-_-•16m ago•0 comments

Show HN: Visual EE Builder – Build Ansible Execution Environments in One Click

https://visualeebuilder.com/
1•tolarewaju3•16m ago•0 comments

LLM Security Scanners for Penetration Testers and Security Teams

https://joshua.hu/llm-engineer-review-sast-security-ai-tools-pentesters
1•charlieirish•17m ago•0 comments

The power of reusing and adapting viral posts

https://comuniq.xyz/post?t=393
1•01-_-•17m ago•0 comments

Airports are incredibly reliant on oil refineries

https://twitter.com/Object_Zero_/status/1973644703275876495
1•Michelangelo11•17m ago•0 comments

Geist Sans from Vercel

https://vercel.com/font
1•kblissett•18m ago•1 comments

US memo to colleges proposes terms on ideology, foreign enrollment for fed funds

https://www.reuters.com/world/us/white-house-sets-hiring-foreign-enrolment-terms-colleges-get-fun...
2•c420•18m ago•0 comments

Waku – A Family of Robust, Censorship-Resistant Protocols to Preserve Privacy

https://waku.org/
1•TheWiggles•19m ago•0 comments

If you delete your Sora acct you lose ChatGPT acct and banned from re-signing up

https://twitter.com/PaulYacoubian/status/1973401982888022277
1•CGMthrowaway•21m ago•0 comments

Delusions of a Protocol

https://azhdarchid.com/delusions-of-a-protocol/
1•speckx•21m ago•0 comments

Glaciers in California's Sierra Nevada disappearing for first time the Holocene

https://phys.org/news/2025-10-california-glaciers-people-ice-free.html
2•bikenaga•21m ago•1 comments

Fluid forms, vibrant colors – subtle refresh of Microsoft 365 icons

https://microsoft.design/articles/fluid-forms-vibrant-colors/
1•ChrisArchitect•21m ago•0 comments

Claude Code 2.0 Is Promising but Flawed

https://www.aiengineering.report/p/claude-code-20-great-model-but-flawed
2•waprin•23m ago•2 comments

Linus Torvalds Lashes Out at RISC-V Big Endian Plans

https://www.phoronix.com/news/Torvalds-No-RISC-V-BE
4•jackdoe•25m ago•2 comments

Show HN: I built a SOC2 policy generator after auditors hated the existing ones

https://nextcomply.ai/tools/soc2-policy-generator
1•adam_ftt•25m ago•0 comments

America fell behind China in the lunar space race

https://arstechnica.com/space/2025/10/how-america-fell-behind-china-in-the-lunar-space-race-and-h...
6•perihelions•27m ago•2 comments