frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Opinion: The era of 'free' excess renewable energy is over

https://www.utilitydive.com/news/the-era-of-free-excess-renewable-energy-is-over/804471/
1•boshomi•2m ago•0 comments

Nicholas Carlini – Are LLMs worth it? [video]

https://www.youtube.com/watch?v=PngHcmMmwWI
1•teddykoker•7m ago•0 comments

SQLite Cache Schema

https://gist.github.com/ewaldbenes/e48b9b4c1d0e1cb7175dfdd868addd58
1•thunderbong•11m ago•0 comments

Palantir tops estimates, boosts fourth-quarter guidance on AI adoption

https://www.cnbc.com/2025/11/03/palantir-pltr-q3-earnings-2025.html
2•mgh2•13m ago•0 comments

Looking for Input

1•tigydavid•15m ago•0 comments

Trump readies US troops for ground invasion in Mexico to go after drug cartels

https://www.independent.co.uk/news/world/americas/us-politics/trump-drug-cartels-mexico-plans-mil...
4•saubeidl•23m ago•1 comments

We Used to Read Things in This Country

https://thebaffler.com/salvos/we-used-to-read-things-in-this-country-mccormack
3•samclemens•25m ago•0 comments

Cost-neutral food tax reforms for healthier and more sustainable diets

https://www.sciencedirect.com/science/article/pii/S0921800925003052
2•PaulHoule•34m ago•0 comments

Visualizee.ai

https://visualizee.ai
1•bellamoon544•34m ago•1 comments

Fusion Energy in 2025: Six Global Trends to Watch

https://www.iaea.org:443/newscenter/news/fusion-energy-in-2025-six-global-trends-to-watch
1•mpweiher•36m ago•0 comments

Claude Code refused to add rainbows and unicorns to my app

7•glamp•37m ago•3 comments

A Friendly Tour of Process Memory on Linux

https://www.0xkato.xyz/linux-process-memory/
5•0xkato•37m ago•2 comments

Bay Area man creates prehistoric Halloween by bringing "Doloresaurus" to life [video]

https://www.youtube.com/watch?v=BXiNtT6cRc4
1•guerrilla•37m ago•0 comments

A confidential manifesto lays out a billionaire's new vision for NASA

https://www.politico.com/news/2025/11/03/jared-isaacman-confidential-manifesto-nasa-00633858
2•c420•38m ago•0 comments

Linkers: A 20 Part Series (2007)

https://www.airs.com/blog/archives/38
2•mattrighetti•40m ago•0 comments

2025 United States federal government shutdown

https://en.wikipedia.org/wiki/2025_United_States_federal_government_shutdown
1•wslh•42m ago•1 comments

KitteHub: Python projects in the cloud in a few clicks

https://github.com/autokitteh/kittehub
1•itayd•43m ago•0 comments

OneBusAway: Open-source transit app for real-time information

https://github.com/OneBusAway
1•thunderbong•45m ago•0 comments

Guideline has been acquired by Gusto

https://help.guideline.com/en/articles/12694322-guideline-has-joined-gusto-faqs-about-our-recent-...
25•surprisetalk•47m ago•7 comments

Physical activity as a modifiable risk factor in preclinical Alzheimer's disease

https://www.nature.com/articles/s41591-025-03955-6
2•bookofjoe•48m ago•0 comments

No space, no time, no particles: a vision of quantum reality

https://www.newscientist.com/article/2500081-no-space-no-time-no-particles-a-radical-vision-of-qu...
3•fnord77•49m ago•0 comments

DJI's Drones, Both Branded and Disguised, Are Even Closer to a US Ban

https://petapixel.com/2025/11/03/djis-drones-both-branded-and-disguised-are-even-closer-to-a-us-ban/
4•bookofjoe•53m ago•2 comments

What's Next in Customer Identity and Access Management

https://www.kuppingercole.com/blog/tolbert/whats-next-in-customer-identity-and-access-management
1•mooreds•55m ago•0 comments

Norway's Public Buses Can Be Shut Down Remotely from China

https://www.carscoops.com/2025/11/norways-public-buses-can-be-shut-down-remotely-from-china/
5•josephcsible•56m ago•0 comments

Ask HN: What Is the State of Mobile Development in 2025?

1•sarimkx•57m ago•0 comments

PocketBook – DIY pocket-sized Project Gutenberg books

https://github.com/sieste/pocketbook
2•sieste•1h ago•0 comments

LLM Security Guide – 100 tools and real-world attacks from 370 experts

https://github.com/requie/LLMSecurityGuide
2•tarique192•1h ago•1 comments

Why Does the Universe Exist? (1991) [pdf]

https://philosophy.fas.harvard.edu/sites/g/files/omnuum4436/files/phildept/files/parfit_-_why_doe...
3•measurablefunc•1h ago•1 comments

Scaling up Prime Video monitoring service reduced costs 90% (archive) (2023)

https://web.archive.org/web/20240325042615/https://www.primevideotech.com/video-streaming/scaling...
1•Ellipsis753•1h ago•2 comments

Do I want Coders to Code?

https://yeikoff.xyz/blog/11-02-2025-do-i-want-coders-to-code/
1•iglesiastj•1h ago•0 comments
Open in hackernews

Your Infra Isn't Special: Why Open Source Infrastructure as Code (IaC) Wins

https://masterpoint.io/blog/why-open-source-iac-wins/
5•mooreds•6h ago

Comments

sshine•4h ago
> The IaC ecosystem is not the Javascript ecosystem; If you use good modules, pin them to a specific version, and update when you need to then you won’t run into the dependency issues that you may have elsewhere.

That’s a half-truth. The IaC consulting I take part of is overwhelmed equally by npm and docker/helm dependency hell.

Sure, worms in npm. But just as many things breaking and getting deprecated in IaC land. Bitnami deprecating their charts. Zookeeper operator breaking on newer Linux kernels. Lagoon not respecting resource requests.

“But if you stick to the good packages!” works for any package ecosystem. It’s just that sometimes you don’t choose the packages.

My only counter-argument: sometimes it is cheaper to maintain your own fork of something. Sometimes it is cheaper to make your own thing.

Gowiem•3h ago
That's a reasonable take! Yes, there are tradeoffs and there are bad OSS actors (like Bitnami) that make it hard to state anything in this realm as a hard truth.

In this article, I'm fairly focused on the Terraform + OpenTofu IaC child module ecosystem in which I'm not aware of anyone who has done that sort of rug pull. I get your point though and that is why I included the "How you should evaluate good OSS" steps towards the end of the article. Hopefully that helps folks pick good packages...

sshine•2h ago
In Terraform/OpenTofu you just run into unreliable providers, 3rd party providers that make your supply chain a little questionable, or providers with half-broken APIs that weren’t ever intended to be called via terraform. (How many hashpin their binary third party providers? https://github.com/nix-community/nixpkgs-terraform-providers... is still open after 2 years.)

Not just bad FOSS actors, things just fall apart in every ecosystem over time as actors stop contributing.

More dependencies = more problems. Long dependency chains means more dependencies. IaC generally doesn’t have long chains. But you can still depend on a ton of dockerfiles, images, charts, and the same software that gets packaged ends up with CVEs in images rather than at the library import level.