frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Abom – Actions Bill of Materials for GitHub Actions Supply Chains

https://github.com/JulietSecurity/abom
2•julietsecurity•1h ago

Comments

julietsecurity•1h ago
We built this after CVE-2026-33634 (Trivy compromise). Every remediation guide says "grep your workflows for trivy-action" — but if you use a composite action that internally calls trivy-action, grep finds nothing.

abom recursively resolves every GitHub Action dependency in your workflows, including composite actions, reusable workflows, and actions that silently embed tools like Trivy as wrappers. It flags known-compromised actions against an advisory database and outputs standard formats (CycloneDX 1.5, SPDX 2.3) so you can treat your CI/CD supply chain like your application dependencies.

We're calling the output an ABOM — an Actions Bill of Materials. SBOMs exist for your app dependencies, ABOMs should exist for your pipelines.

Colibri – chat platform built on the AT Protocol for communities big and small

https://colibri.social/
1•todotask2•34s ago•0 comments

Uncensored: Explicit only playlists on YouTube Music

https://github.com/ttlequals0/uncensored
1•Ttlequals0•2m ago•0 comments

How do you guys handle MFA for AI agents?

1•rayruizhiliao•2m ago•0 comments

The Shape of Jaggedness

https://www.oneusefulthing.org/p/the-shape-of-ai-jaggedness-bottlenecks
1•colonCapitalDee•3m ago•0 comments

Google bumps up Q Day deadline to 2029

https://arstechnica.com/security/2026/03/google-bumps-up-q-day-estimate-to-2029-far-sooner-than-p...
1•rediguanayum•4m ago•1 comments

Want to use the Windows 11 stopwatch? Please update first

https://stopwatch.court.is/
1•jscnz•4m ago•0 comments

We couldn't find an API that understood construction drawings, so we built one

https://www.getanchorgrid.com/developer/docs/changelog/construction-drawings-are-data-prisons
1•wcisco17•6m ago•1 comments

California Regulator Says Tesla's 'Robotaxis' Are More Like a Limo in the Law

https://gizmodo.com/california-regulator-says-teslas-robotaxis-are-more-like-a-limo-in-the-eyes-o...
1•MaysonL•6m ago•0 comments

Cline Kanban

https://cline.bot/kanban
1•Flere-Imsaho•7m ago•0 comments

Base experiment at CERN succeeds in transporting antimatter

https://home.cern/news/press-release/experiments/base-experiment-cern-succeeds-transporting-antim...
1•bko•7m ago•0 comments

EPA approves sale of a higher-ethanol fuel to try to lower gas prices

https://apnews.com/article/gasoline-ethanol-e15-epa-price-pollution-efd15da2b3016cb77fc3cbcf7478be87
1•geox•7m ago•0 comments

The Oxford Comma – Why and Why Not

https://www.deborahcourtbooks.com/post/the-oxford-comma-why-and-why-not
1•taubek•8m ago•0 comments

New study says gnomes are responsible for breaking your electronics

https://lzon.ca/posts/series/duck/gadget-gnomes/
1•jpmitchell•9m ago•0 comments

Reinventing the Pull Request

https://lubeno.dev/blog/reinventing-the-pull-request
1•bkolobara•10m ago•0 comments

How Can America Be So Miserable When It's So Rich?

https://www.nytimes.com/2026/03/26/opinion/economy-attitudes-republicans-democrats.html
3•simonebrunozzi•11m ago•2 comments

Old-Games.com

https://www.old-games.com/
3•helloplanets•11m ago•0 comments

Algorithms, Neo-Brokers, and Political Power Reshaping Who Wins on Wall Street

https://respublica.media/the-rigged-casino/
1•amadeuspagel•11m ago•0 comments

An LLM's not going to tell you no (2024)

https://derekkedziora.com/notes/2024-12-11-an-llms-not-going-to-tell-you-no
1•speckx•12m ago•0 comments

Families are fed up with social media

https://nypost.com/2026/03/25/opinion/legal-double-whammy-is-just-the-start-for-social-media-comp...
1•1vuio0pswjnm7•12m ago•0 comments

Ask HN: Will AI ever be cheap?

2•worldsavior•13m ago•0 comments

The surprising science behind red-light therapy – and how it works

https://www.nature.com/articles/d41586-026-00878-1
1•mikhael•13m ago•0 comments

You shouldn't use ultrathink in Claude Code

https://www.claudecodecamp.com/p/claude-code-extended-thinking
3•aray07•14m ago•0 comments

Building a Blog with Elixir and Phoenix

https://jola.dev/posts/building-a-blog-with-elixir-and-phoenix
5•shintoist•14m ago•0 comments

Unit: A self-replicating Forth mesh agent running in a browser tab

https://davidcanhelp.github.io/unit/
1•DavidCanHelp•14m ago•0 comments

Scientists discover popular diabetic drug's unexpected effect on the brain

https://timesofindia.indiatimes.com/etimes/wellness/scientists-discover-popular-diabetic-drugs-un...
1•01-_-•15m ago•0 comments

CDC plans hiring push to fill gaps from last year's widespread layoffs

https://federalnewsnetwork.com/workforce/2026/03/cdc-plans-hiring-push-to-fill-gaps-from-last-yea...
1•starkparker•15m ago•1 comments

Spotify and Labels Seek $322M Default Judgment Against Anna's Archive

https://torrentfreak.com/spotify-and-labels-seek-322-million-default-judgment-against-annas-archive/
2•Cider9986•17m ago•0 comments

Germany's Merz floats EU-China trade deal as European capitals soften on Beijing

https://www.scmp.com/news/china/diplomacy/article/3348030/germanys-merz-floats-eu-china-trade-dea...
1•vrganj•17m ago•0 comments

Online legal database CanLII and AI startup Caseway settle copyright dispute

https://betakit.com/online-legal-database-canlii-and-ai-startup-caseway-settle-copyright-dispute/
3•ClearwayLaw•18m ago•1 comments

Text Reconstruction via Subtle Vibrations from Videos

https://www.mdpi.com/1424-8220/26/5/1407
1•PaulHoule•18m ago•0 comments