frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Suno, AI Music, and the Bad Future [video]

https://www.youtube.com/watch?v=U8dcFhF0Dlk
1•askl•27s ago•0 comments

Ask HN: How are researchers using AlphaFold in 2026?

1•jocho12•3m ago•0 comments

Running the "Reflections on Trusting Trust" Compiler

https://spawn-queue.acm.org/doi/10.1145/3786614
1•devooops•8m ago•0 comments

Watermark API – $0.01/image, 10x cheaper than Cloudinary

https://api-production-caa8.up.railway.app/docs
1•lembergs•9m ago•1 comments

Now send your marketing campaigns directly from ChatGPT

https://www.mail-o-mail.com/
1•avallark•13m ago•1 comments

Queueing Theory v2: DORA metrics, queue-of-queues, chi-alpha-beta-sigma notation

https://github.com/joelparkerhenderson/queueing-theory
1•jph•25m ago•0 comments

Show HN: Hibana – choreography-first protocol safety for Rust

https://hibanaworks.dev/
5•o8vm•27m ago•0 comments

Haniri: A live autonomous world where AI agents survive or collapse

https://www.haniri.com
1•donangrey•27m ago•1 comments

GPT-5.3-Codex System Card [pdf]

https://cdn.openai.com/pdf/23eca107-a9b1-4d2c-b156-7deb4fbc697c/GPT-5-3-Codex-System-Card-02.pdf
1•tosh•40m ago•0 comments

Atlas: Manage your database schema as code

https://github.com/ariga/atlas
1•quectophoton•43m ago•0 comments

Geist Pixel

https://vercel.com/blog/introducing-geist-pixel
2•helloplanets•46m ago•0 comments

Show HN: MCP to get latest dependency package and tool versions

https://github.com/MShekow/package-version-check-mcp
1•mshekow•54m ago•0 comments

The better you get at something, the harder it becomes to do

https://seekingtrust.substack.com/p/improving-at-writing-made-me-almost
2•FinnLobsien•55m ago•0 comments

Show HN: WP Float – Archive WordPress blogs to free static hosting

https://wpfloat.netlify.app/
1•zizoulegrande•57m ago•0 comments

Show HN: I Hacked My Family's Meal Planning with an App

https://mealjar.app
1•melvinzammit•57m ago•0 comments

Sony BMG copy protection rootkit scandal

https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal
2•basilikum•1h ago•0 comments

The Future of Systems

https://novlabs.ai/mission/
2•tekbog•1h ago•1 comments

NASA now allowing astronauts to bring their smartphones on space missions

https://twitter.com/NASAAdmin/status/2019259382962307393
2•gbugniot•1h ago•0 comments

Claude Code Is the Inflection Point

https://newsletter.semianalysis.com/p/claude-code-is-the-inflection-point
3•throwaw12•1h ago•1 comments

Show HN: MicroClaw – Agentic AI Assistant for Telegram, Built in Rust

https://github.com/microclaw/microclaw
1•everettjf•1h ago•2 comments

Show HN: Omni-BLAS – 4x faster matrix multiplication via Monte Carlo sampling

https://github.com/AleatorAI/OMNI-BLAS
1•LowSpecEng•1h ago•1 comments

The AI-Ready Software Developer: Conclusion – Same Game, Different Dice

https://codemanship.wordpress.com/2026/01/05/the-ai-ready-software-developer-conclusion-same-game...
1•lifeisstillgood•1h ago•0 comments

AI Agent Automates Google Stock Analysis from Financial Reports

https://pardusai.org/view/54c6646b9e273bbe103b76256a91a7f30da624062a8a6eeb16febfe403efd078
1•JasonHEIN•1h ago•0 comments

Voxtral Realtime 4B Pure C Implementation

https://github.com/antirez/voxtral.c
2•andreabat•1h ago•1 comments

I Was Trapped in Chinese Mafia Crypto Slavery [video]

https://www.youtube.com/watch?v=zOcNaWmmn0A
2•mgh2•1h ago•1 comments

U.S. CBP Reported Employee Arrests (FY2020 – FYTD)

https://www.cbp.gov/newsroom/stats/reported-employee-arrests
1•ludicrousdispla•1h ago•0 comments

Show HN: I built a free UCP checker – see if AI agents can find your store

https://ucphub.ai/ucp-store-check/
2•vladeta•1h ago•1 comments

Show HN: SVGV – A Real-Time Vector Video Format for Budget Hardware

https://github.com/thealidev/VectorVision-SVGV
1•thealidev•1h ago•0 comments

Study of 150 developers shows AI generated code no harder to maintain long term

https://www.youtube.com/watch?v=b9EbCb5A408
2•lifeisstillgood•1h ago•0 comments

Spotify now requires premium accounts for developer mode API access

https://www.neowin.net/news/spotify-now-requires-premium-accounts-for-developer-mode-api-access/
2•bundie•1h ago•0 comments
Open in hackernews

Show HN: I built an OSHA compliance SaaS for oilfields using only LLMs

https://basincheck.com
2•jaycobski•3w ago
I’m a marketer (6 years in SaaS) who spent the last year learning to build software using purely AI assistance ("vibe coding"). I just shipped my first production app for the Oil & Gas industry.

The Product BasinCheck (https://basincheck.com) replaces the clipboard/Excel workflow for Safety Managers in the Permian Basin. It handles offline audits, hot work permits, and automates OSHA 300 logs.

The Stack

Next.js (App Router): Monorepo setup lets me spin out features as standalone free tools for SEO/lead gen.

Supabase: The path of least resistance for backend/auth.

Resend: For all transactional/marketing emails.

Stripe: Stuck with the standard despite the Polar/Lemon Squeezy hype. The SDK coverage made it easier for LLMs to generate reliable integration code.

AI: Used for parsing incident descriptions to suggest OSHA codes. Hard rule: AI is read-only/suggestion mode. A human (Safety/HSE manager) must approve every classification.

The "Vibe Coding" Reality Check

The biggest lesson so far: AI leaves logic gaps. I asked the AI to "alert me on new signups," which it did—for email/password forms. I missed my first real user for 5 days because the AI didn't intuitively know to hook those same alerts into the Google OAuth callback.

Fix: Moved logic from client-side to Postgres triggers on auth.users to catch everything at the DB level.

Happy to answer questions on the prompting workflow or the "boring" industrial tech stack.

Comments

tomaslau•3w ago
Congrats on the launch! How are you handling security?
jaycobski•3w ago
Thanks! This is definitely the part that kept me up at night as a non-traditional dev.

My philosophy was to write as little security code as possible myself and rely on battle-tested infrastructure:

Auth & User Data: I rely entirely on Supabase Auth (which is based on the GoTrue API). I don't touch password hashing or session management logic directly.

Data Access: I use PostgreSQL Row Level Security (RLS) policies extensively. Every request to the DB has to pass a policy like auth.uid() = company_id. This ensures that even if there’s a bug in my frontend code, the database layer rejects unauthorized access.

Inputs: I use Zod for strict schema validation on all API routes to prevent weird injections before they even hit the DB.

Since this is for Oil & Gas (sensitive compliance data), I also made a hard rule: No AI agents have write-access to the database. The AI only suggests text/codes in the UI, and a logged-in human must click "Save."