frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Bulwark – zero-dependency supply chain security gateway

https://github.com/Bluewaves54/Bulwark
1•Bluewaves54•1h ago

Comments

Bluewaves54•1h ago
Software supply chain attacks are the fastest-growing threat vector in the industry (event-stream, ua-parser-js, PyPI malware campaigns, Shai-Hulud worm). As AI agents lower the barrier to development, more and more code is getting shipped by people who are unaware of where their dependencies are coming from. The existing solutions are either “trust everything” or “buy an enterprise platform.” There wasn't a simple, self-hosted, open-source middle ground until now.

It's a transparent, locally-hosted proxy that sits between your package managers (pip, npm, maven) and the public registries. Every package request is evaluated against policy rules before it ever reaches your machine or CI pipeline. Out of the box it blocks: Packages published less than 7 days ago (the primary attack window) Typosquatted packages via Levenshtein distance detection Packages with install scripts (postinstall, binding.gyp) Pre-release and SNAPSHOT versions in production Explicitly denied packages (customize your own deny list) Velocity anomalies and suspicious version patterns No database, UI, or vendor lock-in — simply one Go binary and a configurable YAML file. The rule engine is readable, auditable, and fully customizable. It ships with best-practices configs for npm, PyPI, and Maven, Docker images, Kubernetes manifests, and a 90-test Docker E2E suite.

Bulwark is meant for real-world use in development environments and CI pipelines, especially for teams that want supply chain protections without adopting a full enterprise platform. It can be deployed independently or integrated into existing supply chain security systems.

More package support (cargo, cocoapods, rubygems) is coming soon. I’ll be actively maintaining the project, so contributions and feedback are welcome — give it a star if you find it useful!

Agentfile generate AI agent instruction files from a single contract.yaml

https://github.com/dennishavermans/agentfile
1•bychanzey•23s ago•0 comments

Show HN: Union-find for chatbot memory instead of flat compaction

https://www.june.kim/union-find-compaction
1•kimjune01•3m ago•0 comments

Afrinic accuses litigant of trying to 'paralyse' it

https://www.theregister.com/2026/03/13/afrinic_strikes_back_at_litigant/
1•t-3•3m ago•0 comments

64% of unmarried young women in Japan don't want children, exceeding men

https://mainichi.jp/english/articles/20260312/p2a/00m/0li/006000c
1•rawgabbit•3m ago•0 comments

Mass-Produced Software Components

https://www.cs.dartmouth.edu/~doug/components.txt
1•birdculture•4m ago•1 comments

Chatbots encouraged 'teens' to plan shootings in study

https://www.theverge.com/ai-artificial-intelligence/892978/ai-chatbots-investigation-help-teens-p...
3•01-_-•4m ago•0 comments

How A Deep Learning Library Enables Learning

https://www.henrypan.com/blog/2026-03-14-how-deep-learning-library-enables-learning/
1•megadragon9•7m ago•0 comments

Europe takes first step to banning AI-generated child sexual abuse images

https://www.reuters.com/business/europe-takes-first-step-banning-ai-generated-child-sexual-abuse-...
3•01-_-•10m ago•0 comments

Tech companies defeat bill as AI drains local water supplies

https://www.theolympus.net/13531/
11•laurex•10m ago•1 comments

Groundsource

https://research.google/blog/introducing-groundsource-turning-news-reports-into-data-with-gemini/
1•bookofjoe•14m ago•0 comments

KatBook – Pythonic Social Network for Knostic Agentic Trading (Kat)

https://github.com/claytantor/katbook-api-py
2•claydronze•17m ago•1 comments

Grandparents are glued to their phones, families are worried [video]

https://www.bbc.com/reel/video/p0n61dg3/grandparents-are-glued-to-their-phones-families-are-worried
20•tartoran•17m ago•2 comments

Understanding SMF Properties

https://www.davepacheco.net/blog/2026/smf-properties/
1•naves•17m ago•0 comments

Notes for March 9–15

https://taoofmac.com/space/notes/2026/03/15/1900
1•rcarmo•17m ago•0 comments

Sculpting jaws, giving scores: Inside the world of looksmaxxing

https://www.bbc.com/news/articles/cx28z4zypkno
3•tartoran•18m ago•1 comments

Boom: Senate Votes to Block Private Equity from Buying Homes

https://www.thebignewsletter.com/p/boom-senate-votes-to-block-private
2•randycupertino•20m ago•1 comments

Processes Are All You Need for AI Sandboxing

https://multikernel.io/2026/03/14/introducing-sandlock/
1•wang_cong•20m ago•0 comments

Show HN: Detach – Mobile UI for managing AI coding agents from your phone

https://github.com/salvozappa/detach
2•salvozappa•20m ago•0 comments

Built to Forget: Importance of Consent Infrastructure for the Post-Keyboard Era

https://zenodo.org/records/18842578
1•zedlasso•22m ago•0 comments

An analysis of how scientists use Claude Code

https://republicofscience.substack.com/p/how-do-scientists-use-claude-code
1•charlesxjyang•23m ago•0 comments

Write up of my homebrew CPU build

https://willwarren.com/2026/03/12/building-my-own-cpu-part-3-from-simulation-to-hardware/
2•wwarren•23m ago•0 comments

The Foilies 2026

https://www.eff.org/deeplinks/2026/03/foilies-2026
2•hn_acker•24m ago•0 comments

We Know How Bumblebee Queens Can Survive Underwater for Days

https://www.sciencealert.com/we-finally-know-how-bumblebee-queens-can-survive-underwater-for-days
1•gscott•25m ago•1 comments

Show HN: Flint – A compiled, pipeline-oriented language for CLI tooling

https://codeberg.org/lucaas-d3v/flint
1•lucaas-d3v•27m ago•0 comments

My GPS app makes zero HTTP requests

https://redgridtactical.github.io/RedGridMGRS/blog/zero-network-architecture.html
1•redgridtactical•28m ago•2 comments

Show HN: DocuDesign – describe a design, edit text inline, get print-ready file

https://docudesign.app/
1•noahSchenk_•28m ago•0 comments

Risk Beneath the Waves: Safeguarding Subsea Cables for a Secure Global Network

https://features.csis.org/safeguarding-subsea-cables/
3•gmays•30m ago•0 comments

Don't be a Process Zealot [video]

https://www.youtube.com/watch?v=_wbLChnXz9Q
1•lopespm•31m ago•0 comments

Kintsu.ai – Vibe code your existing WordPress site

https://kintsu.ai
3•david1616•33m ago•1 comments

Unseen details of human brain structure revealed

https://www.nih.gov/news-events/nih-research-matters/study-reveals-unseen-details-human-brain-str...
3•firefoxd•34m ago•0 comments