frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

SBoM – treating dependencies like code, not artifacts

https://mz.attahri.com/posts/software-bill-of-materials-as-code/
3•mohamedattahri•1d ago

Comments

mohamedattahri•1d ago
OP here. Sharing this early because I'm trying to gauge if this specific pain point is widespread, or if I'm just scratching a niche itch.

Context: I’ve been working in a regulated monorepo and realized that almost all existing supply chain tools assume you are a large enterprise with dedicated infrastructure.

The gap I found:

Scanners are reactive (they yell at you after the fact).

Artifactory/Nix are heavy (they require rebuilding your workflow or hosting servers).

I wanted something in the middle. The idea is a lightweight CLI that acts as a local proxy to gate npm/cargo/go requests against policies stored directly in git. It forces "lockfile intent" (what the dev wants) to match "security policy" (what the repo allows) before the package hits the host.

The mechanism I'm most interested in feedback on is the enforcement logic: sbom check --policy-from=origin/main

This allows the CLI to judge the "crimes" on your feature branch against the "laws" defined in main. It effectively prevents a developer from un-banning a vulnerable package in the same PR that introduces it.

Does this "local proxy" approach feel like the right middle ground to you, or is the overhead of a proxy too much for a daily driver?

National Design Studio

https://ndstudio.gov/
1•handfuloflight•26s ago•0 comments

Breakthrough lets scientists watch plants breathe in real time

https://www.sciencedaily.com/releases/2026/01/260106224625.htm
1•amrrs•28s ago•0 comments

Trump warns Iran over protest crackdown amid internet blackout

https://www.iranintl.com/en/liveblog/202601054803
1•ukblewis•31s ago•0 comments

Is AI solving open Erdős problems?

https://zeyu-zheng.github.io/blog/erd%C5%91sConjectures.html
1•fahrbach•47s ago•0 comments

TxtNet-Browser: An app that lets you browse the web over SMS

https://github.com/lukeaschenbrenner/TxtNet-Browser
1•gurjeet•1m ago•0 comments

Jujutsu v0.37.0 Released

https://github.com/jj-vcs/jj/releases/tag/v0.37.0
1•todsacerdoti•1m ago•0 comments

Toyota uses retro-style games and prizes to urge US workers to lobby politicians

https://www.theguardian.com/us-news/2025/dec/19/toyota-employee-lobbying
1•PaulHoule•3m ago•0 comments

Show HN: I built a small tool to sanity-check ad revenue assumptions

https://tatrezvalthazarsite.blogspot.com/p/tatrez-ad-revenue-estimator_8.html
1•Traumen•5m ago•1 comments

Rust Is Perfectly Imperfect

http://0x80.pl/notesen/2026-01-08-imperfect-rust.html
2•mfiguiere•6m ago•0 comments

An Underappreciated Variable in Sports Success

https://www.theatlantic.com/health/2026/01/athletic-success-luck/685533/
2•breve•6m ago•0 comments

Consumer electronics, the "Modular Middle", and production models of the future

https://www.a16z.news/p/everything-is-computer
1•walterbell•6m ago•0 comments

Solar hydrogen can now be produced efficiently without the scarce metal platinum

https://www.eurekalert.org/news-releases/1111199
1•westurner•7m ago•0 comments

BirdBot, an energy-efficient robot leg inspired by birds' legs (2022) [video]

https://www.youtube.com/watch?v=PXXdaqseHis
1•Luc•7m ago•0 comments

Multi-platform WhatsApp client written in Rust

https://github.com/jlucaso1/whatsapp-rust
1•justmarc•7m ago•0 comments

OAuth 2.0 Security Best Practices for Developers

https://maida.kim/oauth2-best-practices-for-developers/
1•mooreds•8m ago•0 comments

Code Coverage for GoAWK (2022)

https://maximullaris.com/goawk_cover.html
1•benhoyt•10m ago•0 comments

We Keep Making the Same Software Mistakes

https://spectrum.ieee.org/avoidable-software-failures-cost-trillions
1•Growtika•11m ago•0 comments

Gut Microbes Played Role in Evolution of Human Brain, New Study Suggests

https://www.sci.news/biology/gut-microbes-human-brain-evolution-14461.html
1•gmays•12m ago•0 comments

Reusable "skills" for coding agents: how to design them so they do not drift

https://clipnotebook.com/blog/reusable-skills-for-coding-agents
3•amandapoDEV•13m ago•1 comments

How to Fool a Neural Network

https://briefer.cloud/blog/posts/fooling-neural-networks/
1•rafaepta•14m ago•0 comments

AG Pax­ton Secures Win Stop­ping Sam­sung from Using Smart TVs to Spy on Texans

https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-major-win-...
2•voxadam•14m ago•1 comments

Decoding the Astonishing Secret Languages of Animals

https://atmos.earth/science-and-nature/decoding-the-astonishing-secret-languages-of-animals/
1•bikeshaving•14m ago•0 comments

Detecting "AI Slop" with Shannon Entropy (Python)

https://steerlabs.substack.com/p/detecting-ai-slop-with-shannon-entropy
2•steer_dev•15m ago•1 comments

OpenAPI Isn't Enough

https://alexstephen.me/writing/openapi-isnt-enough/
2•rambleraptor•15m ago•0 comments

GLM-4.7: Advancing the Coding Capability

https://z.ai/blog/glm-4.7?_hsenc=p2ANqtz-_A0g1a_qMPKlnITH_2MrETt56Egtpn06pe9CyarPb7l_DhltBP9TmtFS...
1•rbanffy•16m ago•0 comments

The work of sleep doesn't depend on time

https://blog.affectablesleep.com/p/the-hidden-work-of-sleep-doesnt-depend
1•pedalpete•17m ago•0 comments

Show HN: Semi-private chat with Gemini from your computer

https://github.com/deepanwadhwa/semi_private_chat
1•dwa3592•19m ago•0 comments

Show HN: Ralph2Ralph

https://github.com/eqtylab/real-a2a
2•ramoz•19m ago•0 comments

Richard D. James interviews ex Korg engineer Tatsuya Takahashi (2017)

https://web.archive.org/web/20180719052026/http://item.warp.net/interview/aphex-twin-speaks-to-ta...
1•lelandfe•20m ago•4 comments

Our take on the best Firefox-based browsers for top privacy and customization

https://alternativeto.net/news/2026/1/our-honest-take-on-the-best-firefox-based-web-browsers-for-...
1•elliot_a•22m ago•0 comments