frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Pompelmi – Privacy-first file upload scanning for Node.js

https://github.com/pompelmi/pompelmi
1•alrjoe•2h ago
Hi HN — I’m the author of pompelmi, an open-source, in-process scanner for untrusted file uploads in Node.js.

Motivation: I wanted a practical “upload guard” that reduces common upload risks (ZIP bombs, traversal in archives, MIME spoofing, polyglots/macro hints) without sending files to a cloud AV service (privacy + latency + GDPR concerns).

Key points: - Runs in-process (no cloud calls); files never leave your infrastructure - Deep ZIP inspection with configurable limits (depth/entries/ratio) + nested archive scanning - Composable scanners (heuristics + optional signature engines like YARA), fail-closed policies - Drop-in adapters for popular frameworks (Express/Koa/Fastify/Next/Nuxt/Nest)

Try it in 2 minutes (Express example): 1) npm i pompelmi @pompelmi/express-middleware 2) Add createUploadGuard middleware (docs + examples in the repo)

It was recently covered by Help Net Security and previously mentioned in Risky Bulletin; also featured in Node Weekly / Detection Engineering Weekly / Bytes and daily.dev (links in the README).

I’d love feedback on: 1) What’s missing for production use in your upload pipeline? 2) Which integrations/templates would be most valuable next (e.g., SvelteKit/Remix/hapi)?

How to elevate visual storytelling with Nano Banana Pro

https://www.theaithinker.com/p/how-to-elevate-visual-storytelling
1•faikadam•2m ago•0 comments

Show HN: DayTape – record thoughts, get transcripts, takeaways, and patterns

https://apps.apple.com/us/app/daytape/id6757109811
1•holaduder•2m ago•0 comments

Show HN: Orange Juice Hacker News browser extension

https://oj-hn.com
1•oj-hn-dot-com•3m ago•0 comments

Expectation and Copysets

https://buttondown.com/jaffray/archive/expectation-and-copysets/
1•shachaf•4m ago•0 comments

Show HN: PaperPod – Fast, no-setup sandboxes for AI agents

https://www.paperpod.dev
1•shassingh09•6m ago•1 comments

Likely You Understand Cycle Time Wrong

https://ksaweryskowron.substack.com/p/cycle-time-is-not-a-number
1•ksaweryskowron•7m ago•0 comments

Data Exfil from Agents in Messaging Apps

https://www.promptarmor.com/resources/llm-data-exfiltration-via-url-previews-(with-openclaw-examp...
2•sarelta•8m ago•0 comments

Remote Access Security Act Closes the Cloud Loophole in the US Export

https://exportcompliancemanager.com/articles/will-the-remote-access-security-act-close-the-cloud-...
1•sharpshadow•9m ago•0 comments

Global biodiversity loss, ecosystem collapse and national security [pdf]

https://assets.publishing.service.gov.uk/media/696e0eae719d837d69afc7de/National_security_assessm...
2•andyjohnson0•9m ago•0 comments

Asteroid Bennu Just Changed the Origin Story of Life

https://scitechdaily.com/asteroid-bennu-just-changed-the-origin-story-of-life/
3•geox•10m ago•0 comments

Dutch parties strike minority coalition after D66 election upset

https://www.theguardian.com/world/2026/jan/28/dutch-minority-coalition-after-d66-election-upset
1•PaulHoule•11m ago•0 comments

The dazzling discovery of Tutankhamun's tomb

https://www.bbc.com/culture/article/20260205-the-discovery-of-tutankhamuns-tomb
1•rolph•13m ago•0 comments

The Diary of Mary Cooper [pdf]

https://nationalhumanitiescenter.org/pds/becomingamer/peoples/text5/marycooper.pdf
1•whatisabcdefgh•13m ago•0 comments

Show HN: Distill – AI summaries and Worth It scores for YouTube videos

https://chromewebstore.google.com/detail/distill-youtube-video-sum/plllepklppgopiobiecalocnfcdoekjg
1•flashdoc•14m ago•0 comments

GPT-5.3-Codex is now generally available for GitHub Copilot

https://github.blog/changelog/2026-02-09-gpt-5-3-codex-is-now-generally-available-for-github-copi...
3•vyrotek•14m ago•0 comments

The Consequences of Outsourced Thinking

https://www.neilwithdata.com/outsourced-thinking
2•FeteCommuniste•16m ago•0 comments

In Memoriam – Robert Tinney Illustrations

https://tinney.net/in-memoriam
1•rbanffy•18m ago•0 comments

How do you use AI to program Three.js 3D games?

1•roschdal•19m ago•0 comments

Silicon Photonics in the Data Center: What a CMOS Exec Needs to Know

https://semiengineering.com/silicon-photonics-in-the-data-center-what-a-cmos-exec-needs-to-know/
2•matt_d•19m ago•0 comments

Postgres Backend Platform with full stack, instant cloning, branching and

https://github.com/simplyblock/vela
2•noctarius•20m ago•0 comments

Metaprogramming in Jai [video]

https://www.youtube.com/watch?v=0lGSTBqJ2nM
1•eudamoniac•21m ago•1 comments

What Is Claude? Anthropic Doesn't Know, Either

https://www.newyorker.com/magazine/2026/02/16/what-is-claude-anthropic-doesnt-know-either
2•littlexsparkee•22m ago•1 comments

Digital Sovereignty Initiatives and the U.S. Assault on Research

https://www.hpcwire.com/2026/02/09/digital-sovereignty-initiatives-and-the-u-s-assault-on-research/
2•rbanffy•23m ago•0 comments

Best Note-Taking App for Personal and AI Prompts

https://www.viewert.com
1•Sunrostern•23m ago•0 comments

Anthropic Closes in on $20B Round

https://techcrunch.com/2026/02/09/anthropic-closes-in-on-20b-round/
1•tosh•24m ago•0 comments

Letting Gemini Drive My Rover

http://martin.drashkov.com/2026/02/letting-gemini-drive-my-rover.html
1•martythemaniak•24m ago•0 comments

Show HN: GithubDownfall – Track GitHub incidents and downtime

https://githubdownfall.com
2•danscan•24m ago•0 comments

"Building a Self-Sustaining Trading and Learning Ecosystem"

1•MIKAxGSF•26m ago•0 comments

Modernizing my "150-line" Python search engine

https://bart.degoe.de/modernizing-python-search-engine/
3•bartdegoede•26m ago•1 comments

A New Chapter for Gather

https://www.gather.town/blog/new-chapter
1•zodo123•27m ago•0 comments