frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Why software supply-chain review shouldn't be split across five tools

https://github.com/ferxalbs/rainy-updates
1•ferxalb•1h ago

Comments

ferxalb•1h ago
Over time I started feeling that modern software change review is too fragmented.

Dependency updates live in one place. Security findings in another. Supply-chain checks somewhere else. Attestation exists as metadata, but often not as an actual decision surface. And CI ends up stitching all of this together inconsistently.

The result is that teams get more signals, but not necessarily better decisions.

That pushed me toward a different idea: treat dependency review, supply-chain scanning, and attestation checks as one deterministic review problem instead of separate tool categories.

The core thing I’m interested in is not just generating more scans or more PR noise, but creating a clearer review layer: - normalized findings - explicit policy signals - deterministic allow/review/block outcomes - local + CI workflows - agent-readable surfaces without making mutation the default

I’ve been exploring this through Rainy Updates and the broader Rainy MaTE direction, but I’m more interested in the underlying question:

Should software change review be treated as one operator layer instead of a collection of fragmented checks?

Curious how others think about this, especially people dealing with CI policy, supply-chain tooling, dependency automation, or release workflows.

Mockdown

https://www.mockdown.design
1•handfuloflight•20s ago•0 comments

Sony is testing dynamic pricing in the PlayStation Store

https://psprices.com/news/sony-ab-testing-prices/
1•xoxxala•54s ago•0 comments

Amazon tells FCC to bin SpaceX's million-satellite datacenter dream

https://www.theregister.com/2026/03/09/amazon_petitions_to_block_spacexs/
1•johnbarron•5m ago•0 comments

Lazy iteration vs. array chaining on 500k rows – benchmark results

1•gvsh_maths•8m ago•0 comments

I built a tool to export Gemini chat to PDF, Word, Docs, and Notion

1•backrun•8m ago•0 comments

Baochip-1x: What It Is, Why I'm Doing It Now, and How It Came About

https://www.crowdsupply.com/baochip/dabao/updates/what-it-is-why-im-doing-it-now-and-how-it-came-...
1•brewcrew•8m ago•0 comments

Sen Sheldon Whitehouse: Connections Between Trump, Russia, and Epstein

https://www.youtube.com/watch?v=ylvTFvJvB84
1•johnbarron•10m ago•0 comments

I just launched my first Roblox game "Drone Wars"

https://www.roblox.com/games/136100514232797/Drone-Wars
1•mmmmkay•11m ago•1 comments

Scotland becomes first UK country to legalise water cremations

https://www.theguardian.com/society/2026/mar/02/scotland-becomes-first-uk-country-to-legalise-wat...
1•gscott•14m ago•0 comments

Loom vs. Linear: A tale of two AI-cities

https://jamespember.substack.com/p/loom-vs-linear-a-tale-of-two-ai-cities
1•jep888•16m ago•0 comments

Reese's changed its chocolate because of climate change

https://www.fooddive.com/news/hershey-reeses-ingredients-chocolate-climate-change-oped/813903/
1•del82•16m ago•1 comments

Financial group probed by congressional committee over Chinese stock scams

https://www.ft.com/content/49f541f8-c73d-4268-9621-f8604f1a8141
1•petethomas•17m ago•0 comments

Boredom Is the Price We Pay for Meaning

https://www.theatlantic.com/ideas/2026/02/boredom-parenthood-father/686158/
1•myth_drannon•17m ago•0 comments

Something feels weird about this economy

https://www.noahpinion.blog/p/something-feels-weird-about-this
1•paulpauper•18m ago•0 comments

Phonyhuman

https://github.com/manav03panchal/phonyhuman
1•manavpanchal•20m ago•0 comments

Ask HN: What game engine would you recommend for vibe coding?

3•general_reveal•21m ago•2 comments

American Prairie Grows Again with 2k+ Acres of Critical Wetland Habitat

https://americanprairie.org/the-latest/american-prairie-grow-again-with-2k-acres-of-critical-wetl...
2•gametorch•23m ago•0 comments

Emergent Quantization from a Dynamic Vacuum

https://journals.aps.org/prresearch/abstract/10.1103/l8y7-r3rm
1•Rover222•33m ago•2 comments

High-throughput phenomics of global ant biodiversity

https://www.nature.com/articles/s41592-026-03005-0
1•bookofjoe•34m ago•0 comments

The Deadliest Animals

https://ourworldindata.org/deadliest-animals
1•gmays•35m ago•0 comments

Fast and Powerful Code Editor

https://lap.dev/lapce/
3•arthurz•37m ago•1 comments

The greatest unsolved problem in computer science

https://www.youtube.com/watch?v=x36UmiSiEzc
1•ArturoNereu•39m ago•0 comments

China Deploys 30k-Ton Liaowang-1 "Floating Supercomputer" to Gulf of Oman

https://defencesecurityasia.com/en/china-liaowang-1-spy-ship-gulf-of-oman-us-israel-iran-war-surv...
4•swed420•40m ago•1 comments

Family of Tumbler Ridge shooting victim suing OpenAI

https://www.cbc.ca/news/canada/british-columbia/openai-sued-tumbler-ridge-victim-9.7121635
3•stygiansonic•42m ago•0 comments

Show HN: Open-source, model-agnostic alternative to Claude Code Review

https://github.com/kodustech/kodus-ai
3•edvaldodfreitas•44m ago•0 comments

Trump cancels sanctions against countries buying Russian oil

https://unn.ua/en/news/trump-cancels-sanctions-against-countries-buying-russian-oil
3•testing22321•45m ago•0 comments

Show HN: CLI for Atlassian

https://github.com/chinmaymk/acli
3•_chinmaymk•46m ago•0 comments

The Custodian Shift

https://igorschwarzmann.com/strategyasprotocol/custodian-shift/
2•doener•47m ago•0 comments

How to Get Free Email for Your Custom Domain

https://timleland.com/how-to-get-free-email-for-your-custom-domain/
2•TimLeland•48m ago•0 comments

Corporateapology.com – Accountability at Scale

https://corporateapology.com
1•drawbars•51m ago•1 comments