frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

I built an API testing tool that generates tests from a single cURL

https://github.com/LiudasJan/Rentgen
3•liudasjank•53m ago

Comments

liudasjank•53m ago
The idea came from a simple problem: most teams have lots of API endpoints, but almost no one has realistic coverage. Writing and maintaining test collections takes forever, and scripts always fall out of sync.

Rentgen takes one cURL request and generates: • boundary tests (min/max, out-of-range) • enum variation tests • invalid/negative input cases • trimming/whitespace cases • structure/mapping validation • reflection safety checks • missing/incorrect security headers • basic latency/load insights • automatic bug-report templates • and many other.

The goal is to give engineers a rough but honest API health picture in ~2 minutes — without maintaining test files or writing code.

A fun surprise: I pointed Rentgen at ChatGPT’s API and found a few issues we genuinely didn’t expect to see in production. They were fixed immediately after reporting.

I would really appreciate feedback from the community: • What categories of tests are missing? • Which edge cases do you usually find manually? • What would make this useful in your workflow?

GitHub: https://github.com/LiudasJan/Rentgen

Happy to answer anything about the engine design, how the generator works, reflection detection, or upcoming performance modules.

Mintaras•25m ago
This hits a real pain point. I've been on teams with hundreds of endpoints but maybe 10% had any tests beyond "does it return 200?" — and those inevitably rot as the API evolves.

Generating tests from a single cURL is smart because it meets devs where they already are. We're already firing off cURL commands during development; turning that into a test suite with zero extra effort is a nice DX win.

A few edge cases I’d love to see: Rate limit testing (verify proper 429s with Retry-After) Idempotency checks for POST/PUT endpoints Unicode edge cases like : emoji, RTL characters, null bytes in strings

The ChatGPT API finding is a great proof point. Nothing sells a security tool better than “we found something in production at a major company.” Will try this on some internal APIs this week.

liudasjank•18m ago
Thanks for the thoughtful suggestions, those are spot on.

Rate-limit testing and proper 429/Retry-After handling are definitely on the roadmap. Idempotency checks for POST/PUT are a great call too, a lot of APIs behave unpredictably there, and it’s one of those areas people rarely test systematically. Unicode/emoji/RTL input fuzzing is a fun one, Rentgen already generates trimming/whitespace/negative cases, but expanding into more string-weirdness categories makes total sense.

If you end up trying it on any internal APIs this week, I’d genuinely love to hear what it catches. The tool often surprises me in places I didn’t expect.

Paramount makes $108.4B hostile bid for WB

https://www.reuters.com/legal/transactional/paramount-makes-1084-billion-bid-warner-bros-discover...
1•gbil•18s ago•0 comments

Building a magical stock market orb

https://forestdussault.com/building-a-magical-stock-market-orb.html
1•mliezun•42s ago•0 comments

Python Workers redux: fast cold starts, packages, and a uv-first workflow

https://blog.cloudflare.com/python-workers-advancements/
1•dom96•53s ago•0 comments

Show HN: Ogblocks – Ship Your Website 10x Faster with Ready-Made UI Components

https://ogblocks.dev/
1•Karanzk•3m ago•0 comments

Show HN: Outfit Swap Studio – AI clothes changer for your own photos

https://outfitswapstudio.com/
1•xiaoyuan23•7m ago•0 comments

Paramount Makes Hostile Bid for Warner Bros. Discovery

https://www.nytimes.com/2025/12/08/business/paramount-warner-bros-discovery-netflix.html
2•pseudolus•8m ago•1 comments

Show HN: I created a website to scan invoices or bank statements with OCR and AI

https://quickdataconverter.com
1•sithu_khant•8m ago•0 comments

Time might not exist – and we're starting to understand why

https://www.sciencefocus.com/science/the-closer-we-look-at-time-the-stranger-it-gets
2•amichail•9m ago•0 comments

The Reverse Socratic Method in the AI Age

https://smoas.bearblog.dev/reverse-socratic/
1•_nalply•10m ago•0 comments

Paramount launches hostile bid for Warner Bros. Discovery despite Netflix deal

https://www.nbcnews.com/business/media/paramount-hostile-bid-warner-bros-discovery-rcna247993
4•mellosouls•10m ago•0 comments

Dynamic Pong Wars

https://markodenic.tech/dynamic-pong-wars/
1•bookofjoe•11m ago•0 comments

Show HN: NixOS on Fairphone 5

https://github.com/gian-reto/nixos-fairphone-fp5
2•gian-reto•11m ago•0 comments

GeoVista open-source agentic geolocation

https://the-decoder.com/geovista-brings-open-source-ai-geolocation-to-near-parity-with-top-commer...
1•geox•13m ago•0 comments

Notes on building end-to-end encrypted and CRDT-based local-first applications

https://kerkour.com/crdt-end-to-end-encryption-research-notes
4•randomint64•13m ago•0 comments

Dax Martin's Telescreen 2078

https://www.instagram.com/daxmartinart/reel/DR8CbUPDufv/
1•vintagedave•15m ago•0 comments

Show HN: A Wordle helper I made after becoming a little obsessed with the game

https://wordlehelper.co
1•mr_windfrog•17m ago•0 comments

Show HN: WaldenWeek – Weekly challenges for simpler living

https://waldenweek.com
1•calinf•17m ago•0 comments

O'Brien Flops! (1993)

https://archive.nytimes.com/www.nytimes.com/ref/opinion/17opclassic_conan.html
1•TMWNN•19m ago•0 comments

Show HN: LinkedQL – Live Queries over Postgres, MySQL, MariaDB

https://github.com/linked-db/linked-ql
1•phrasecode•19m ago•1 comments

Why your CTO might start coding again

https://davegriffith.substack.com/p/why-your-cto-might-start-coding-again
1•fandorin•19m ago•0 comments

Show HN: A browser-based screen recording / editing tool for fast product demos

https://screentell.com
1•wainguo•23m ago•0 comments

Will LLMs be more or less rational consumers than humans?

https://www.alephic.com/writing/satisficing-for-llms
1•noahbrier•25m ago•0 comments

Paramount launches hostile bid for Warner Bros

https://www.cnbc.com/2025/12/08/paramount-skydance-hostile-bid-wbd-netflix.html
6•gniting•26m ago•1 comments

Mathematician Ernest Ryu on solving a 42-year-old problem in math with GPT-5 Pro

https://excitech.media/p/how-a-mathematician-used-chatgpt
1•ksdk•26m ago•0 comments

Software Applications Face a New Intermediary

https://www.wreflection.com/p/software-gets-a-new-layer
1•nowflux•28m ago•0 comments

How Pokémon cards became a stock market for millennials

https://www.theguardian.com/games/2025/dec/08/how-pokemon-cards-became-a-stock-market-for-millenn...
1•Archelaos•29m ago•0 comments

Israel's biggest defence company suspended by NATO amid corruption probe

https://www.ftm.eu/articles/israel-defence-elbit-systems-suspended-nato-corruption-investigation
5•amarcheschi•30m ago•1 comments

The benefits of standardized architectures for space missions

https://blog.satsearch.co/2025-12-05-spotlight-the-benefits-of-standardized-architectures-for-spa...
1•kartikkumar•31m ago•0 comments

Home Assistant Vibecoding in Cursor, VS Code or Other MCP Enabled IDE

https://medium.com/@eremeev/home-assistant-vibecoding-in-cursor-vs-code-or-other-mcp-enabled-ide-...
1•Vladimir42•32m ago•0 comments

Linguists start compiling first ever complete dictionary of ancient Celtic

https://www.theguardian.com/science/2025/dec/08/linguists-start-compiling-first-ever-complete-dic...
2•Archelaos•32m ago•0 comments