frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

CVE-2026-31900, my 0-click RCE in the psf/black GitHub Action

https://medium.com/securitycertcommunity/cve-2026-31900-50800bafafba
2•ParzivalHack•1h ago

Comments

ParzivalHack•1h ago
Hi HN, I’m Tommy, the researcher who reported this vulnerability.

While looking at the psf/black GitHub Action I noticed that when the action reads the version from pyproject.toml, it accepts values that are not strictly version strings. This makes it possible to reference a remote package and have it executed during the workflow run.

In a PR scenario, this ofc leads to arbitrary code execution on GitHub Actions runners, with no maintainer interaction.

It's my first CVE, so i wrote a writeup, and i would love to get some feedbacks on it, from people who actually work in CI security/DevSecOps :)

Benchmark: TanStack Start is now the fastest full stack React framework

https://blog.platformatic.dev/react-ssr-framework-benchmark-tanstack-start-react-router-nextjs
1•flyaway123•1m ago•0 comments

AI Tools Can Help with Legal History Research

https://reason.com/volokh/2026/03/17/how-ai-tools-can-help-with-legal-history-research/
1•treetalker•4m ago•0 comments

Show HN: Shadcn/UI for Blazor

https://blazor-shadcn.fly.dev
2•Justbeingjustin•4m ago•1 comments

I stopped writing prompts and built an operating system on top of Claude Code

https://medium.com/@assaf_85431/i-stopped-writing-prompts-i-built-an-operating-system-instead-b7a...
1•Assafkip•5m ago•0 comments

JPMorgan Morgan halts $5.3B Qualtrics debt deal as AI fears chill demand

https://www.ft.com/content/ce9a67da-62df-484e-9f50-075d4be7817f
2•petethomas•6m ago•0 comments

Show HN: CodeLedger – deterministic context and guardrails for AI

https://codeledger.dev
1•ashmivante•6m ago•0 comments

Railtracks

1•soulfood5632•6m ago•0 comments

Show HN: ToolGuard – Pytest for AI agent tool calls

1•Heer_J•7m ago•0 comments

Ask HN: What's Your AI Workflow?

1•vixalien•8m ago•0 comments

The Abstraction Ratchet

https://write.as/void-signal/the-abstraction-ratchet
2•void-signal•9m ago•0 comments

Sistemico.net

https://sistemico.net/
1•gdss•9m ago•0 comments

Tree-style invite systems reduce AI slop

https://abyss.fish/tree-style_invite_systems_reduce_AI_slop
1•birdculture•11m ago•0 comments

Eating Ultra-Processed Foods Could Raise Your Heart Risk by 67%

https://scitechdaily.com/eating-ultra-processed-foods-could-raise-your-heart-risk-by-67/
1•Gaishan•13m ago•0 comments

My Son's Roblox Mod Helped Me Find a Bug in Crypto Wallet Software

https://robmulla.substack.com/p/how-my-sons-roblox-mod-helped-me
1•latchkey•13m ago•0 comments

CSLib: The Lean Computer Science Library

https://arxiv.org/abs/2602.04846
2•PaulHoule•13m ago•0 comments

Arizona Becomes First State to Criminally Charge Kalshi

https://newrepublic.com/post/207878/arizona-first-state-criminally-charge-kalshi
1•voxadam•15m ago•0 comments

TPCP – peer-to-peer signed messaging for AI agents across machines

https://github.com/Etriti00/agent-telepathy
1•agenttelepathy•20m ago•0 comments

The New Thelio Mira High Performance Desktop

https://blog.system76.com/post/system76-introduces-new-thelio-mira-high-performance-desktop/
1•shaunpud•21m ago•0 comments

Not-devops.com, a satirical blog about DevOps experiences

https://not-devops.com/
3•weird_trousers•22m ago•0 comments

RSS Gizmos – Tools for Creating, Finding, and Using RSS Feeds

https://rssgizmos.com/
3•ohjeez•22m ago•0 comments

Sparkling Water Helps Gamers Stay Focused for Hours

https://www.sciencealert.com/a-simple-drink-choice-helps-gamers-stay-focused-for-hours-study-finds
2•Gaishan•22m ago•0 comments

Show HN: Devopsiphai – A Claude Code skill to audit DevOps around 5 questions

https://github.com/sanhajio/devopsiphai
1•sanhajio•23m ago•0 comments

Android 15 appends .ogx to downloaded .ogg files – a MIME type mystery

https://file-converter-online.com/why-android-15-downloads-ogg-files-as-ogg-ogx-a-mime-type-analy...
2•iopodx•29m ago•1 comments

Show HN: Lore – Local AI thought capture and recall that runs on your machine

https://github.com/ErezShahaf/Lore
1•ErezShahaf•29m ago•0 comments

Kalshi criminally charged in Arizona for operating illegal gambling business

https://www.reuters.com/world/kalshi-charged-criminally-arizona-operating-illegal-gambling-busine...
3•petethomas•30m ago•0 comments

Roberts says personal hostility aimed at judges has 'got to stop'

https://www.reuters.com/legal/government/us-supreme-courts-roberts-says-personal-hostility-aimed-...
2•petethomas•33m ago•1 comments

GlassWorm malware hits 400 code repos on GitHub, NPM, VSCode, OpenVSX

https://www.bleepingcomputer.com/news/security/glassworm-malware-hits-400-plus-code-repos-on-gith...
1•uyzstvqs•34m ago•0 comments

Conductor – Multi-agent AI workflows in YAML with parallelism and human gate

https://github.com/microsoft/conductor
1•juniorlimaivd•35m ago•1 comments

Introduction to Human Behavioral Biology – Robert Sapolsky [video]

https://www.youtube.com/watch?v=NNnIGh9g6fA&list=PL150326949691B199
1•nomilk•39m ago•0 comments

Tars – A local-first autonomous supervisor powered by Google Gemini

https://tars.saccolabs.com
1•TarsAssistant•40m ago•0 comments