frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: PACO A tool to find Dependency Confusion vulnerabilities

https://github.com/r00tSid/PACO-Package-Confuser
1•r00tSid•8h ago

Comments

r00tSid•8h ago
Author here.

One interesting challenge while building PACO was avoiding false positives.

For example, some repositories use workspaces (like npm workspaces or monorepos) where dependencies may resolve locally instead of from public registries.

PACO currently checks the official registries (NPM, PyPI, RubyGems) and flags dependencies that appear unpublished or removed, but I'm still improving detection for monorepos and internal workspace dependencies.

If anyone has ideas or feedback on improving detection accuracy, I'd love to hear them.

r00tSid•5h ago
Another improvement I'm exploring is adding support for additional ecosystems like Go modules and Maven.

Supply chain attacks aren't limited to JavaScript ecosystems, so expanding PACO's coverage is something I'm actively working on.

Htmx Infinite Scroll

https://alchemists.io/articles/htmx_infinite_scroll
1•speckx•1m ago•0 comments

Show HN: Tri·TFM Lens – 5-axis quality evaluation for ChatGPT/Gemini responses

1•siris950•1m ago•1 comments

Let's build a tool-using agent

https://educatedguesswork.org/posts/tool-calling/
2•ibobev•1m ago•0 comments

AI bubble probably going to be blown? [video]

https://www.youtube.com/watch?v=4Ql24Z8SIeE
1•kar37•2m ago•0 comments

BYD's Second-Generation Blade Battery Makes Western EV Tech Look Ancient

https://insideevs.com/news/789094/byd-second-generation-blade-battery/
1•mooreds•2m ago•0 comments

Should newbies use IDE autocomplete (Intellisense)? (2011)

https://softwareengineering.stackexchange.com/questions/40172/should-newbies-use-ide-autocomplete...
1•mooreds•3m ago•0 comments

Geoffrey Hinton Explains AI Dangers to Neil DeGrassi Tyson [video]

https://www.youtube.com/watch?v=l6ZcFa8pybE
1•keernan•4m ago•0 comments

I Still Blog – and Why the Future of Blogging Is Connected

https://www.ssp.sh/blog/why-i-still-blog/
2•articsputnik•4m ago•0 comments

Show HN: Claudine – A Kanban board for your Claude Code and Codex conversations

https://claudine.pro
1•ycmatt•5m ago•0 comments

Show HN: I built the first scripting language for multiplayer game dev

https://docs.allout.game/scripting/syntax
2•joshuamanton•5m ago•1 comments

Cognitive and Physical Improvement with Positive Age Beliefs

https://www.mdpi.com/2308-3417/11/2/28
1•wjb3•6m ago•0 comments

Manual to Phil Zimmermans PGPfone Circa 1996 [pdf]

https://philzimmermann.com/docs/pgpfone10b7.pdf
2•smalltorch•6m ago•1 comments

Self taught gen-xers with senior dev/pm exp. Where's my imposter syndrome team?

1•_hugerobots_•6m ago•0 comments

Lotus 1-2-3 on the PC with DOS

https://stonetools.ghost.io/lotus123-dos/
1•TMWNN•7m ago•0 comments

Knightian Uncertainty

https://en.wikipedia.org/wiki/Knightian_uncertainty
1•jerlendds•7m ago•0 comments

Generate cell-type specific mRNAs for better vaccines autoregressively

https://tsone.notion.site/Generate-cell-type-specific-mRNAs-for-better-vaccines-autoregressively-...
1•tdsone3•8m ago•0 comments

Withheld Epstein files with accusations against Trump released by justice dept

https://www.bbc.com/news/articles/c4g0dzg6e4mo
1•tartoran•9m ago•0 comments

Three Quiet Brothers on Long Island, All of Them Related to Hitler

https://www.nytimes.com/2006/04/24/nyregion/three-quiet-brothers-on-long-island-all-of-them-relat...
1•Anon84•11m ago•0 comments

Time to teach our children about finance

https://cointales.ai/en
1•mhalifax•11m ago•1 comments

A Plea for Lean Software (1995) [pdf]

https://berthub.eu/articles/LeanSoftware_text.pdf
1•tosh•13m ago•0 comments

Show HN: CloakPipe – Rust privacy proxy for LLM APIs with pseudonymization

1•rohansx•14m ago•0 comments

An approach to provably safe AI engineering for legacy codebases

https://evok.dev
1•devconcierge•16m ago•1 comments

M6 MacBook Pro could have four innovations new to the Mac

https://9to5mac.com/2026/03/06/m6-macbook-pro-could-have-four-innovations-new-to-the-mac/
2•blacktulip•16m ago•1 comments

We fixed Postgres connection pooling on serverless with PgDog

https://circleback.ai/blog/how-we-fixed-postgres-connection-pooling-on-serverless-with-pgdog
1•levkk•16m ago•0 comments

Interpreting Pull Request Changes Before CI Enforcement

https://github.com/signalprism/execution-boundary-interpretation
1•mattgallant001•17m ago•1 comments

Colorado SB26-051 Age Attestation

https://aphyr.com/posts/408-colorado-sb26-051-age-attestation
1•speckx•18m ago•0 comments

When Using AI Leads to "Brain Fry"

https://hbr.org/2026/03/when-using-ai-leads-to-brain-fry
2•dracula_x•19m ago•0 comments

Artificial Intelligence: friend or foe for hiring in Europe today?

https://www.ecb.europa.eu/press/blog/date/2026/html/ecb.blog20260304~d9e34fc95f.en.html
1•akyuu•21m ago•0 comments

Making Hybrid Bonding Better

https://semiengineering.com/making-hybrid-bonding-better/
1•PaulHoule•21m ago•0 comments

Building a High-Performance Postgres Time Series Stack with Iceberg

https://www.snowflake.com/en/engineering-blog/postgres-time-series-iceberg/
2•craigkerstiens•23m ago•0 comments