frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Supply Chain Attack on Trivy

https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack
10•tiri•1h ago

Comments

wilkystyle•1h ago
I have generally preferred to avoid using community-maintained actions as far as possible, instead installing and configuring the runners as though I would a normal machine.

This started from a desire to avoid an unknown amount of bloat and untrusted code, but also because I'm pretty tired of getting Node deprecation warnings for installing/using something that has nothing to do with JavaScript at all.

I've always installed a pinned version of Trivy of my choosing, and installed by curl | sh.

Looks like curl | sh may have saved my skin, whereas even older versions of the github action were force-pushed to install the vulnerable binary.

SahAssar•50m ago
> avoid using community-maintained actions as far as possible, instead installing and configuring the runners as though I would a normal machine.

A runner and a action are two very different things.

You could run on the default runners with no community actions, and you can run on self-hosted runners with a lot of community actions.

wilkystyle•13m ago
If you're getting hung up on "normal machine", what I meant is a computer in general that is not related to GitHub Actions at all.

If that's not the part of my message you're referring to, then your message seems completely orthogonal to what I posted.

Understanding kubectl top Output Columns

https://randomwrites.com/operations/09-Resource-Troubleshooting
1•mutahirs•3m ago•0 comments

Agentic AI requires compute that can't be measured in tokens alone

https://www.revenuemodel.ai/agentic-ai-requires-more-compute-that-is-not-measured-in-tokens/
1•alanjacobson•4m ago•0 comments

Thermal Grizzly hit by China metal scam

https://www.pcgamer.com/hardware/a-simple-check-with-a-magnet-was-the-final-clue-that-made-therma...
1•libpcap•6m ago•0 comments

Activist Elliott Builds Big Stake in EDA Chip-Design Software Maker Synopsys

https://www.wsj.com/business/deals/activist-elliott-builds-big-stake-in-chip-design-software-make...
1•walterbell•11m ago•0 comments

The first modern rocket launched 100 years ago

https://theconversation.com/the-first-modern-rocket-launched-100-years-ago-beginning-a-century-of...
1•geox•13m ago•0 comments

Calm: LLMs That Predict Vectors Instead of Tokens

https://shaochenze.github.io/blog/2025/CALM/
1•IndignantTyrant•15m ago•0 comments

Show HN: Quillium, Git for Writers

https://quillium.bryanhu.com/
1•thatxliner•16m ago•0 comments

Crunchyroll's customer analytics data breached via outsourcing partner Telus

https://twitter.com/IntCyberDigest/status/2035864555805413448
1•badcryptobitch•19m ago•0 comments

Show HN: ClauseGuard – AI contract review in 90s, finds risks, writes redlines

https://www.theclauseguard.com
1•ebuyan•20m ago•0 comments

Show HN: Plot-Hole.com a daily movie puzzle I made

https://www.plot-hole.com/
1•captaincrunch•23m ago•1 comments

Migrating the American Express Payment Network, Twice

https://americanexpress.io/migrating-the-payments-network-twice/
2•madflojo•23m ago•0 comments

PewPew – real-time SSH attack visualizer, single Go binary

https://github.com/awakeelectronik/pewpew
2•awakeelectronik•33m ago•0 comments

How do we build production-ready AI systems?

https://docs.struere.dev
2•MarcoKueks•34m ago•6 comments

Men are losing a key chromosome with age and it may be deadly

https://www.sciencedaily.com/releases/2026/03/260319044711.htm
2•bookofjoe•34m ago•0 comments

Obesity may come in 11 different types, each with their own cause

https://www.newscientist.com/article/2488744-obesity-may-come-in-11-different-types-each-with-the...
1•paulpauper•36m ago•0 comments

Iconic Australian-made pinball machines preserved for generations to come

https://www.abc.net.au/news/2026-03-12/pinball-machines-collected-nfsa-hankin/105971386
3•gnabgib•44m ago•0 comments

What if Elon built a decentralized AI network?

http://heatmine.ai/
1•scharf•46m ago•0 comments

Plexus – Unified API gateway for multiple AI providers

https://github.com/mcowger/plexus
1•indigodaddy•47m ago•0 comments

How HN: A geometric framework for NP-Intermediate classes (OM Theory)

https://github.com/jumapama/OM-Theory-A-Geometric-Framework-for-NP-Intermediate-Classes
1•jumapama•49m ago•0 comments

AskAlf – Self-hosted AI workforce that runs 24/7

https://github.com/askalf/askalf
1•jsprayberry87•52m ago•1 comments

The deep cave bacteria resistant to modern medicine

https://www.bbc.com/future/article/20260318-the-deep-cave-bacteria-resistant-to-modern-medicine
1•Teever•52m ago•1 comments

Unlocking 25 Gigabit/S on 10 GbE Direct Attach Copper

https://kohlschuetter.github.io/blog/posts/2026/03/22/unlock25/
3•kohlschuetter•54m ago•0 comments

Privacy Respecting Age Controls

https://gist.github.com/devinvs/e334f7fb92f8d9b41b821a1dc8a46fde
1•devinvs•59m ago•1 comments

Health: Science Outran the System

https://juliahawkins.substack.com/p/health-how-science-outran-the-system
1•brandonb•59m ago•1 comments

The solar-powered compact car driving Tunisia's electric vehicle revolution

https://www.cnn.com/world/africa/electric-vehicle-solar-tunisia-spc
9•mooreds•1h ago•0 comments

Apply video compression on KV cache to 10,000x less error at Q4 quant

https://github.com/cenconq25/delta-compress-llm
4•polymorph1sm•1h ago•0 comments

The Onion's Exclusive Interview with Sam Altman

https://theonion.com/the-onions-exclusive-interview-with-sam-altman/
1•mooreds•1h ago•0 comments

Zprof – a comptime-configurable and minimal memory profiler for Zig allocators

https://github.com/ANDRVV/zprof
2•andrvv•1h ago•0 comments

VercelNet: The internet but only Vercel apps

https://vercelnet.vercel.app
1•aquajet•1h ago•0 comments

ForgeKV – Redis-compatible KV server in Rust that scales with cores

https://github.com/ForgeKV/forgekv
1•forgekv•1h ago•0 comments