frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

The Contagious Taste of Cancer

https://www.historytoday.com/archive/history-matters/contagious-taste-cancer
1•Thevet•58s ago•0 comments

U.S. Jobs Disappear at Fastest January Pace Since Great Recession

https://www.forbes.com/sites/mikestunson/2026/02/05/us-jobs-disappear-at-fastest-january-pace-sin...
1•alephnerd•1m ago•0 comments

Bithumb mistakenly hands out $195M in Bitcoin to users in 'Random Box' giveaway

https://koreajoongangdaily.joins.com/news/2026-02-07/business/finance/Crypto-exchange-Bithumb-mis...
1•giuliomagnifico•1m ago•0 comments

Beyond Agentic Coding

https://haskellforall.com/2026/02/beyond-agentic-coding
1•todsacerdoti•2m ago•0 comments

OpenClaw ClawHub Broken Windows Theory – If basic sorting isn't working what is?

https://www.loom.com/embed/e26a750c0c754312b032e2290630853d
1•kaicianflone•4m ago•0 comments

OpenBSD Copyright Policy

https://www.openbsd.org/policy.html
1•Panino•5m ago•0 comments

OpenClaw Creator: Why 80% of Apps Will Disappear

https://www.youtube.com/watch?v=4uzGDAoNOZc
1•schwentkerr•9m ago•0 comments

What Happens When Technical Debt Vanishes?

https://ieeexplore.ieee.org/document/11316905
1•blenderob•10m ago•0 comments

AI Is Finally Eating Software's Total Market: Here's What's Next

https://vinvashishta.substack.com/p/ai-is-finally-eating-softwares-total
2•gmays•10m ago•0 comments

Computer Science from the Bottom Up

https://www.bottomupcs.com/
2•gurjeet•11m ago•0 comments

Show HN: I built a toy compiler as a young dev

https://vire-lang.web.app
1•xeouz•13m ago•0 comments

You don't need Mac mini to run OpenClaw

https://runclaw.sh
1•rutagandasalim•13m ago•0 comments

Learning to Reason in 13 Parameters

https://arxiv.org/abs/2602.04118
1•nicholascarolan•15m ago•0 comments

Convergent Discovery of Critical Phenomena Mathematics Across Disciplines

https://arxiv.org/abs/2601.22389
1•energyscholar•15m ago•1 comments

Ask HN: Will GPU and RAM prices ever go down?

1•alentred•16m ago•0 comments

From hunger to luxury: The story behind the most expensive rice (2025)

https://www.cnn.com/travel/japan-expensive-rice-kinmemai-premium-intl-hnk-dst
2•mooreds•17m ago•0 comments

Substack makes money from hosting Nazi newsletters

https://www.theguardian.com/media/2026/feb/07/revealed-how-substack-makes-money-from-hosting-nazi...
5•mindracer•18m ago•2 comments

A New Crypto Winter Is Here and Even the Biggest Bulls Aren't Certain Why

https://www.wsj.com/finance/currencies/a-new-crypto-winter-is-here-and-even-the-biggest-bulls-are...
1•thm•18m ago•0 comments

Moltbook was peak AI theater

https://www.technologyreview.com/2026/02/06/1132448/moltbook-was-peak-ai-theater/
1•Brajeshwar•19m ago•0 comments

Why Claude Cowork is a math problem Indian IT can't solve

https://restofworld.org/2026/indian-it-ai-stock-crash-claude-cowork/
2•Brajeshwar•19m ago•0 comments

Show HN: Built an space travel calculator with vanilla JavaScript v2

https://www.cosmicodometer.space/
2•captainnemo729•19m ago•0 comments

Why a 175-Year-Old Glassmaker Is Suddenly an AI Superstar

https://www.wsj.com/tech/corning-fiber-optics-ai-e045ba3b
1•Brajeshwar•19m ago•0 comments

Micro-Front Ends in 2026: Architecture Win or Enterprise Tax?

https://iocombats.com/blogs/micro-frontends-in-2026
2•ghazikhan205•21m ago•1 comments

These White-Collar Workers Actually Made the Switch to a Trade

https://www.wsj.com/lifestyle/careers/white-collar-mid-career-trades-caca4b5f
1•impish9208•22m ago•1 comments

The Wonder Drug That's Plaguing Sports

https://www.nytimes.com/2026/02/02/us/ostarine-olympics-doping.html
1•mooreds•22m ago•0 comments

Show HN: Which chef knife steels are good? Data from 540 Reddit tread

https://new.knife.day/blog/reddit-steel-sentiment-analysis
1•p-s-v•22m ago•0 comments

Federated Credential Management (FedCM)

https://ciamweekly.substack.com/p/federated-credential-management-fedcm
1•mooreds•22m ago•0 comments

Token-to-Credit Conversion: Avoiding Floating-Point Errors in AI Billing Systems

https://app.writtte.com/read/kZ8Kj6R
1•lasgawe•23m ago•1 comments

The Story of Heroku (2022)

https://leerob.com/heroku
1•tosh•23m ago•0 comments

Obey the Testing Goat

https://www.obeythetestinggoat.com/
1•mkl95•24m ago•0 comments
Open in hackernews

Reducing Dependabot Noise

https://nesbitt.io/2026/01/10/16-best-practices-for-reducing-dependabot-noise.html
64•zdw•3w ago

Comments

anishgupta•3w ago
Had fun reading this, pretty well written. >Consolidate into a monorepo lol this sounds like as if you make a dog tired by playing with it so it sleeps which you're gone :'D

>Contextualize the actual risk This is not as easy as it seems, for example reflection cases where runtime behavior affects a package usage. example: const lib = require(process.env.PARSER) lib.parse(userInput) could use a safe parser in production or a vulnerable one in another environment, but from a code level perspective there's no certainity which package is actually used

doodlesdev•3w ago

   > Modern languages like Zig, Gleam, and Roc offer genuine productivity benefits and attract top talent. As a bonus, their ecosystems are young enough that security tooling has not caught up yet. Dependabot will add support eventually, but until then you get the best of both worlds: a modern stack and a quiet PR queue.
How the hell is that actually a good thing? You might as well just use another language and disable Dependabot security updates if that's what you're looking for. Dependabot security updates aren't a liability, they're an asset in a world where developers use hundreds of dependencies daily, where every few months one of them is going to have a XSS or RCE vulnerability that has to be patched ASAP.

   > And if you are really concerned about a dependency’s security, you can always rewrite it yourself in Rust over a weekend.
That's not how it works. Honestly, this blog post gets me really worried about this developer's projects and clients.

   > Remove lockfiles from version control
What the fuck.
williamjackson•3w ago
Thank you for expressing my thoughts as well. The article seems to be full of contradictory “advice”.

Use a dependency cooldown, okay … but don’t commit your lockfile so you are always running the latest transitive deps? That’s nuts.

Uvix•2w ago
Depends on the package manager. With some you'll get the oldest transitive deps that meet all dependency requirements, not the newest.
equinumerous•3w ago
The "> Remove lockfiles from version control" got me as well.

> Reproducible builds sound nice in theory, but velocity matters more than determinism. Think of it as chaos engineering for your dependency tree.

Reproducible builds are nice in practice, too. :) In the Node.js ecosystem, if you have enough dependencies, even obeying semver your dependencies will break your code. Pinning to specific versions is critical.

wirelesspotat•3w ago
I'm pretty sure the article is joking

> If the vulnerability were critical, someone would have merged it by now.

> GitHub Copilot can automatically suggest fixes for security vulnerabilities. Instead of updating to a patched version, let AI generate a workaround in your own code.

doodlesdev•2w ago

   > I'm pretty sure the article is joking
Went right over my head LOL it actually made me angry reading it earlier hahaha

Well, that makes a lot of sense. I guess I didn't take it as a joke because I've seen some of these things recommended before (including not checking in lockfiles) in other contexts.

lanyard-textile•2w ago
I started to reevaluate the seriousness of this advice with the going to jail prompt. I probably should have caught on sooner :)
doodlesdev•2w ago
I didn't manage to get to that point of the article out of pure anger... He got me all right LOL
yunwal•2w ago
How did you reach "Set open-pull-requests-limit to zero" and not recognize this as satire?
doodlesdev•2w ago
You wouldn't believe how many of these things I've seen seriously recommended before. Also, I do have difficulty detecting sarcasm sometimes (even though I'm very fond of it).

Lovely article :)

torton•3w ago
Excellent troll post. I've had a good chuckle.
williamjackson•3w ago

    At sufficient scale, Dependabot’s analysis will time out before completing, effectively rate-limiting the number of PRs it can generate. This natural throttling prevents notification fatigue while maintaining the appearance of active security tooling.
Am I being trolled?
amitav1•2w ago
I believe so
lanyard-textile•2w ago
Denial: "These dependabot MRs aren't even fixing real security issues, these do not exist in the wild."

Bargaining: "Okay we'll fix them but we'll do it on a schedule, so that it doesn't interrupt sprints."

Anger: "Okay let's just yoink the package lock file how about that?"

Depression: [skip ci]

Acceptance: "So apparently copilot can do this..."

blibble•2w ago
seems the easiest way is to switch from Microslop GitHub to another platform
jbreckmckye•2w ago
I wasn't sure for a while, but this must be satirical - mustn't it?
vlovich123•2w ago
In this thread we get to see which usernames display an inability to detect very obvious satire.
zahlman•2w ago
Presumably there are also people who simply disagree with the message being delivered through the satire... ?

... Or conclude that the message is contradictory such that it's basically just trolling?

wiether•2w ago
I laughed twice: once while reading the article, the second time reading people getting mad at the author in the comments!
odo1242•2w ago
A lot of them, it seems
Tade0•2w ago
I would laugh, but I've met too many people who either adore busywork or worse - seem to think no amount of additional manual stuff that one has to do will ever be a problem.
hypfer•2w ago
Honestly it needed an LLM to tell me that it is satire, because I tuned out at the 20% mark.

The author seems to be so deep in the radioactive weeds that even if it is satire and they're distancing themself from it, they're still likely to already have experienced a near-lethal dose.

Worded differently, I would argue that anyone who sees this and _understands it_ is stuck in something very unhealthy and needs to get out very fast. Using this level of satire as a coping mechanism just prolongs what shouldn't be prolonged (or exist in the first place).

igortg•2w ago
It got me until "Remove lockfiles from version control"
dystopiandevel•2w ago
My favorite was

If it has been mass maintained by some random person in Nebraska since 2003, that is battle-tested infrastructure.

AdrienPoupa•2w ago
I gotta admit you had me thinking this was serious until the `Remove lockfiles` section ;)
doodlesdev•2w ago
I stopped there and had to read the answers to my comment to find out and revisit it. In hindsight, this is absolutely hilarious. Might be one of my new favorite pieces of software satire (because of how realistic, albeit absurd, it is).
coryrc•2w ago
Not "you can always rewrite it yourself in Rust over a weekend"?
gpm•2w ago
"If it has been mass maintained by some random person in Nebraska since 2003, that is battle-tested infrastructure." comes before that.
darkamaul•2w ago
I love all the touches that went into creating the Dependabot configuration:

– Sunday at 3 a.m. for updates

– The prompt injection to skip CI

It was a fun read - I'm looking forward to it being ingested by future LLMs.

bumblehean•2w ago
This is why you shouldn't waste your money on expensive "consultants" like this guy.

We've had 100% success in reducing Dependabot noise by disabling it in our repos. Why should we pay this guy to configure it for us and still end up with Pull Requests being opened?

woodruffw•2w ago
It’s satire.
gpm•2w ago
So is the comment you replied to...
woodruffw•2w ago
Clearly I’m not on the top of my game today!
anematode•2w ago
This is really terrible advice.

> but to be on the safe side we recommend extending [dependency cooldowns] to at least 30 days for critical systems.

I'd say at least a year, no? The xz backdoor took a couple months to find, and that was only because we got lucky -- had it never been found, Jia Tan and his buddies probably would have gotten enough useful data after a year, so it'd be irrelevant at that point anyway.

> Prefer stable, low-activity packages

The authors didn't mention Rust in this section, which is a travesty and would have greatly strengthened their argument. Sooo many "abandoned" projects in cargo are just finished and need no maintenance.

rschiavone•2w ago
I added the suggested dependabot.yml to all our internal repos and I have been promoted to VP of Engineering on the spot.
dystopiandevel•2w ago
Congratulations, well deserved. 100x impact.
lmeyerov•2w ago
Data poisoning at its finest, wow
cluckindan•2w ago
This reads like satire.
chuzz•2w ago
Took me a while to recognize it’s satire because I’ve seen some of these proposed unironically in the wild :,)
swisniewski•2w ago
Take a look at pr-bot:

https://github.com/marqeta/pr-bot

The answer to dependabot, or snyk prs is to automatically merge them once all the status checks pass.

This free your devs from having to worry about patching.

PR-BOT will let you define policy on when it’s ok to automerge prs.

jtbayly•2w ago
I don’t have experience with dependabot at all. I didn’t realize it was satire. I just kept thinking, “This sounds like terrible advice. This can’t be right.”
swisniewski•2w ago
This is not satire.

If you have a large dependency graph, you are going to have a lot of vulnerable stuff.

Letting one computer send you patches and the other computer merge it for you when all your tests pass is a good thing.

istillwritecode•2w ago
try reducing dependencies.