frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Sandboxed Trivy GitHub Action

https://github.com/lhotari/sandboxed-trivy-action
1•flarecoder•1h ago

Comments

flarecoder•1h ago
Scans container images for vulnerabilities with Trivy running inside a sandboxed Docker container.

This action is forked from aquasecurity/trivy-action with security hardened by running Trivy inside a sandboxed Docker container. Credits to Aqua Security for the original action.

This action runs Trivy inside a Docker container with strict security settings to prevent container escape: * --read-only filesystem — the container's root filesystem is read-only * --cap-drop ALL — all Linux capabilities are dropped * --security-opt no-new-privileges:true — prevents privilege escalation inside the container * All scan targets are mounted read-only * Only the output and cache directories are mounted writable * A tmpfs is mounted at /tmp for Trivy's temporary files * No direct Docker socket access — image scans use docker save to export a tar file which is mounted read-only into the container

Contributions are welcome to improve this!

Writing Was the First Data Platform: A Framework for Understanding AI

https://pattersonconsultingtn.com/content/hitchhikers_guide_kw/information_as_infrastructure.html
1•jpattanooga•37s ago•0 comments

Show HN: Visualizing Apple Health workout data (stats, trends, insights)

https://apps.apple.com/us/app/streakout-workout-stats/id6758457318
1•toni88x•46s ago•0 comments

Show HN: Claude Code Bible (notes on making LLM agents more consistent)

https://github.com/4riel/cc-bible
1•4riel•3m ago•0 comments

The Intelligence Curse

https://intelligence-curse.ai/
1•rzk•3m ago•0 comments

Jax-LM: Guide to Language Modelling and Distributed Training in Jax

http://www.chuyishang.com/blog/2026/jax-lm/
1•chuyishang•3m ago•1 comments

Coding Agents Are "Fixing" Correct Code

https://www.sri.inf.ethz.ch/blog/fixedcode
1•nielstron•4m ago•0 comments

Mining the commons: AI extraction, Wikipedia, and

https://policyreview.info/articles/news/commons-ai-extraction-wikipedia/2089
1•edsu•4m ago•0 comments

Enabling MTE for the LLDB Test Suite

https://jonasdevlieghere.com/post/lldb-mte-test-suite/
2•JDevlieghere•4m ago•0 comments

Apple to bring paid ads to maps to US, Canada this summer

https://www.reuters.com/business/media-telecom/apple-bring-paid-ads-maps-us-canada-this-summer-20...
2•gostsamo•5m ago•0 comments

WolfGuard: WireGuard with FIPS 140-3 cryptography

https://github.com/wolfssl/wolfguard
1•789c789c789c•5m ago•0 comments

Executable Specs for Reliable Systems

https://quint-lang.org/
1•perpetua•5m ago•1 comments

What's New in Mellea 0.4.0 and Granite Libraries Release

https://huggingface.co/blog/ibm-granite/granite-libraries
1•ibobev•6m ago•0 comments

When "One in a Billion" Happens Every Day: Scaling Redis at Report URI

https://scotthelme.co.uk/when-one-in-a-billion-happens-every-day-scaling-redis-at-report-uri/
1•speckx•6m ago•0 comments

Build a Domain-Specific Embedding Model in Under a Day

https://huggingface.co/blog/nvidia/domain-specific-embedding-finetune
1•ibobev•6m ago•0 comments

A New Framework for Evaluating Voice Agents (Eva)

https://huggingface.co/blog/ServiceNow-AI/eva
1•ibobev•6m ago•0 comments

OnlyFans owner Leonid Radvinsky dies at 43

https://thehill.com/policy/technology/5796380-leonid-radvinsky-onlyfans-founder/amp/
1•gscott•7m ago•0 comments

Ares and Apollo cap private credit fund withdrawals as exodus grows

https://www.bloomberg.com/news/articles/2026-03-24/ares-limits-private-credit-fund-withdrawals-as...
1•pera•7m ago•1 comments

Luddite

https://en.wikipedia.org/wiki/Luddite
2•thunderbong•8m ago•0 comments

BFChess: A Chess Engine in Brainfuck

https://blog.mathieuacher.com/BFChessChessEngineBrainfuck/
2•sebg•8m ago•0 comments

TournO: Tournament Optimization for Non-Verifiable RL

https://github.com/haizelabs/tourno/
1•leonardtang•8m ago•0 comments

Why Tech Giants Are Ditching the Power Grid

https://www.nytimes.com/interactive/2026/03/18/business/energy-environment/data-center-energy-gas...
2•bookofjoe•9m ago•1 comments

CVE-2026-33413 found in ETCD by open source AI agent (strix.ai), 8.8 CVSS

https://www.wiz.io/vulnerability-database/cve/cve-2026-33413
1•bearsyankees•9m ago•0 comments

Galway astronomer leads team on discovery of new planet

https://www.rte.ie/news/ireland/2026/0324/1564950-galway-astronomer-planet/
3•austinallegro•10m ago•0 comments

LM Studio may possibly be infected with sophisticated malware

https://old.reddit.com/r/LocalLLaMA/comments/1s2clw6/lm_studio_may_possibly_be_infected_with/
2•kburman•10m ago•0 comments

Phase Transitions and Attractor States in the Evolution of Informational Media

https://theinterposer.substack.com/p/approaching-a-crab-problem
2•headspreader•10m ago•0 comments

Show HN: Grove – Homemade version control, one binary, 1mb, written in Rust

https://avatardeejay.github.io/grove/
1•avatardeejay•12m ago•1 comments

The Phantoms of the Fraudpera: an overview of anti-detection tooling

https://digitalseams.com/blog/phantoms-of-the-fraudpera-an-overview-of-anti-detection-tooling
1•Brajeshwar•12m ago•0 comments

EPForecast 7-day Spanish electricity price forecasting with XGBoost and LSTM

https://epforecast.vercel.app/blog/predicting-electricity-prices
1•REControversy•14m ago•0 comments

DeepBlue Marine joins EquityPilot to build Africa's premium ocean experiences

https://deep-blue-marine-5f14a6b1.base44.app
1•DeepBlue_Marine•14m ago•0 comments

/r/ATC

https://old.reddit.com/r/ATC
2•throw_a_grenade•14m ago•0 comments