frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Could lockfiles just be SBOMs?

https://nesbitt.io/2025/12/23/could-lockfiles-just-be-sboms.html
14•zdw•2h ago

Comments

firloop•1h ago
Another drawback could be that package manager lockfile schemas are optimized for performance[0]. I wouldn't appreciate seeing slower install times by default - especially if the lockfile could be converted with other tooling.

[0]: https://bun.com/blog/behind-the-scenes-of-bun-install#optimi...

zingar•59m ago
In hearing the SBOM term for the first time from that article and the linked Wikipedia page. For the ignorant like me: what is it that SBOM is used for that lockfiles aren’t? Everything in the article is something that I’m used to seeing automated scanners using lockfiles for.

Is it just that the two are used by different communities? What is the SBOM community?

edoceo•51m ago
In many cases the lock files are for one part of the stack. Like npm and composer and $other_lang thing. sBOM is when all are together and version-pinned. (I've over simplified).

Edit: for my domain we have Alpine, Debian, PHP, JS, Go in the stack. So our BOM has all that (and dependencies). It's a big list. Some is just necessary base (Alpine, Debian) but some are core stack and other are edge (dependency on python lib when we're mostly Rust (or something)).

Mirror/Vendor all these things for supply-chain integrity (it's what they tell me)

LoganDark•45m ago
> what is it that SBOM is used for that lockfiles aren’t?

Compliance. The article mentions "the EU’s Cyber Resilience Act will push vendors toward providing SBOMs", and having package managers generate SBOMs directly would certainly be convenient for that.

woodruffw•39m ago
This is a great summary, although I think I'm more bearish on SBOMs than Andrew is: my experience integrating them so far (in both pip-audit and uv) has been that there's much more malleability at the representation level than the presence of a standard might imply, and that consumers have adapted (a la Postel) to this reality by being very permissive with the kinds of broken stuff they permit when ingesting third-party SBOMs.

(Case in point: pip-audit's CycloneDX emission was subtly incorrect for years, and nobody noticed[1].)

[1]: https://github.com/pypa/pip-audit/pull/981

Old English Computer Glossary

https://web.archive.org/web/20231120210517/http://www.u.arizona.edu/~ctb/wordhord.html
1•LAC-Tech•4m ago•0 comments

Claude Code with API Key?

https://old.reddit.com/r/ClaudeAI/comments/1jwvssa/comment/mtt0urz/
1•behnamoh•4m ago•0 comments

Microsoft wants to replace its C and C++ codebase, perhaps by 2030

https://www.theregister.com/2025/12/24/microsoft_rust_codebase_migration/
1•0in•10m ago•1 comments

Pennsylvania High Court Rules Police Can Access Google Searches Without Warrant

https://reclaimthenet.org/pennsylvania-court-rules-no-privacy-in-google-searches
1•imglorp•14m ago•0 comments

A new immunotherapy approach could work for many types of cancer

https://news.mit.edu/2025/new-immunotherapy-approach-could-work-many-types-cancer-1216
2•0in•17m ago•0 comments

QWED – Deterministic Verification for AI

https://docs.qwedai.com/
1•handfuloflight•19m ago•0 comments

Gave My RGB Fans a Job: 38-Pixel Screen Mirror

https://seg6.space/posts/rgb-sync/
1•seg6•21m ago•0 comments

Ask HN: Will SLMs be what bursts the LLM bubble cos you can run them on a phone?

1•aniijbod•26m ago•0 comments

They graduated from Stanford. Due to AI, they can't find a job

https://www.latimes.com/business/story/2025-12-19/they-graduated-from-stanford-due-to-ai-they-can...
2•osnium123•26m ago•0 comments

We interfaced single-threaded C++ with multi-threaded Rust and lived

https://antithesis.com/blog/2025/rust_cpp/
1•wwilson•27m ago•0 comments

Evaluating Context Compression for AI Agents

https://factory.ai/news/evaluating-compression
1•gmays•30m ago•0 comments

Zodiac Z13 Decryption

https://colab.research.google.com/drive/19p4n1aMyeYte1jC4P3GKflMgD6xuZAvV
3•sgustard•30m ago•0 comments

Manufactured Inevitability and the Need for Courage

https://theconvivialsociety.substack.com/p/manufactured-inevitability-and-the
1•danielam•31m ago•0 comments

Physicists found a way to make thermodynamics work in the quantum world

https://www.sciencedaily.com/releases/2025/12/251223084615.htm
3•ashishgupta2209•45m ago•0 comments

Don't Become the Machine

https://armeet.bearblog.dev/becoming-the-machine/
4•armeet•50m ago•1 comments

You Can Get Every AI Model for Free

https://infiniax.ai
2•ZacharyGolinger•1h ago•1 comments

Ask HN: Critique wanted — granular-physics pyramid preprint

https://zenodo.org/records/18036910
1•Sherlock_Blight•1h ago•1 comments

The semantic layer is dead. Long live the wiki

https://promptql.io/blog/semantic-layer-dead-long-live-wiki
4•tirumaraiselvan•1h ago•0 comments

Big Space Sandwich Broke a Record

https://nautil.us/this-big-space-sandwich-broke-a-record-1256821/
2•fleahunter•1h ago•0 comments

China bans sharing 'obscene' material – potentially including sexting

https://www.washingtonpost.com/world/2025/12/23/china-porn-ban-online-censorship/
3•0in•1h ago•0 comments

Yendor: A Zach-like, rogue-like game and language made in 7 days

https://github.com/olifog/YENDOR
2•azhenley•1h ago•0 comments

China Delays Plans for Mass Production of Self-Driving Cars After Accident

https://www.nytimes.com/2025/12/23/business/china-autonomous-cars-driving.html
2•bookofjoe•1h ago•1 comments

Poetiq achieves 75% at under $8 / problem using GPT-5.2 X-High on ARC-AGI-2

https://poetiq.ai/posts/arcagi_announcement/
3•mromanuk•1h ago•0 comments

A semantic POP-style framework for structuring AI-assisted programs

https://github.com/dohuyhoang93/theus/blob/main/README.md
3•dohuyhoangvn93•1h ago•1 comments

How to Become AGI: From Capitalism to Compute-Ism

https://medium.com/@zichengxu/how-to-become-agi-a5b2d7d74bda
2•lossy_compress•1h ago•0 comments

Casuistic Alignment

https://fi-le.net/casuism/
3•fi-le•1h ago•0 comments

Show HN: Depsy – normalized SaaS dependency health in one API call (cached,fast)

https://depsy.io/
2•malik_naji•1h ago•0 comments

Show HN: Send free letters to your future self or others

https://lettertolater.com
1•sankar_builds•1h ago•0 comments

DownDownDown Come and challenge the 100th floor game

https://downdowndown.live/
2•bitvvip•1h ago•0 comments

Peter Thiel's $74M Shake-Up: Slashes Tesla, Bets Big on Microsoft and Apple

https://www.13radar.com/guru/peter-thiel
3•EvansWilson•1h ago•3 comments