frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Vex8s: Suppress container CVEs that your Kubernetes settings mitigates

https://github.com/alegrey91/vex8s
1•alegrey91•1h ago

Comments

alegrey91•1h ago
If you run hardened containers (readOnlyRootFilesystem, runAsNonRoot, resource limits, etc.), you've probably noticed that trivy/grype still flag CVEs that aren't actually exploitable in your environment. There's no standard way to say "this CVE doesn't apply to my deployment." vex8s bridges that gap. It uses an embedded ML model to classify each CVE by exploitation type (arbitrary file write, privilege escalation, resource exhaustion, etc.), then checks your Kubernetes manifest to determine if the settings already mitigate it. The output is an OpenVEX document that scanners like trivy can consume to suppress those CVEs. Example: a CVE classified as arbitrary_file_write gets suppressed if your container has readOnlyRootFilesystem: true with all volume mounts set to read-only.

Paper with the full research: https://github.com/alegrey91/vex8s/blob/main/docs/environmet...

Would love feedback :)

From latent spaces to JWTs: how agents taught me backend

https://blog.cobanov.dev/blog/agents
1•cobanov•1m ago•0 comments

When Brands Wear an Insult as a Badge of Honor

https://sloanreview.mit.edu/article/when-brands-wear-an-insult-as-a-badge-of-honor/
2•gnabgib•3m ago•0 comments

Lifetime subscriptions don't mean what you think they mean

https://productimpossible.com/review/lifetime-subscriptions-trap/
2•lest•9m ago•1 comments

Camden, N.J., Cut Its Murder Rate to a 40-Year Low

https://www.nytimes.com/interactive/2026/03/27/headway/camden-nj-murder-rate-gun-violence.html
1•JumpCrisscross•9m ago•0 comments

Gaza toddler released from Israeli custody with 'cigarette burn' wounds

https://web.archive.org/web/20260000000000*/https://www.middleeasteye.net/news/gaza-toddler-relea...
5•Imustaskforhelp•13m ago•3 comments

Off Grid Fteepee

https://klumpen.eu/
1•worik•13m ago•0 comments

Rivian Made Car Dealers Back Down in Washington. More States May Be Next

https://www.wsj.com/business/autos/rivian-made-car-dealers-back-down-in-washington-more-states-ma...
1•JumpCrisscross•14m ago•0 comments

Please Stop Talking about "Zoomers" and "Gen Alpha"

https://www.richardhanania.com/p/please-stop-talking-about-zoomers
2•paulpauper•16m ago•0 comments

Did Paul Conyngham use AI to develop a cancer treatment for his dog?

https://hedonicescalator.substack.com/p/did-paul-conyngham-really-use-ai
1•paulpauper•17m ago•0 comments

Sylve – Proxmox Alternative by FreeBSD

https://sylve.io/
2•imbobbytables•19m ago•0 comments

The Revenge of the Data Scientist

https://hamel.dev/blog/posts/revenge/
1•hamelsmu•20m ago•0 comments

Nothing new to see here

https://feld.com/archives/2026/03/nothing-new-to-see-here/
2•guiambros•26m ago•0 comments

The Nap Room Didn't Love Me Back

https://www.thenation.com/article/society/the-nap-room-didnt-love-me-back/
1•mitchbob•26m ago•1 comments

Show HN: testing Ansible playbooks *fast*

https://github.com/lucasluitjes/ansible-lxd-boilerplate
2•lucasluitjes•27m ago•0 comments

Make Space for Every Voice: Reflect, Headline, Discussion

https://pointc.co/make-space-for-every-voice/
1•walterbell•30m ago•0 comments

A silly little trivia game I made

https://veritas.axiomatik.net/
1•stealth_dev•32m ago•0 comments

The American Soldier [pdf]

https://gwern.net/doc/psychology/1949-stouffer-theamericansoldier-v1-adjustmentduringarmylife.pdf
1•hbarka•32m ago•0 comments

Hardware Image Compression

https://www.ludicon.com/castano/blog/2026/03/hardware-image-compression/
1•luu•34m ago•0 comments

Humans Are Amazing

https://v5.chriskrycho.com/journal/humans-are-amazing/
3•walterbell•38m ago•1 comments

Usability – Catch common usability problems before user testing

https://www.userium.com/
1•calmnordic•39m ago•0 comments

Anthropic's 'Claude Mythos' Leak

https://www.coindesk.com/markets/2026/03/27/anthropic-s-massive-claude-mythos-leak-reveals-a-new-...
2•geoffbp•40m ago•0 comments

Basic Physics Engine in about 100 lines of pure JavaScript

https://slicker.me/javascript/physics/physics_engine.htm
2•thunderbong•42m ago•1 comments

Show HN: Canary – Monitor any URL for changes, get AI-powered intelligence

2•iambel0ved•43m ago•1 comments

First all-solid-state battery in production vehicles

https://www.donutlab.com/battery/
2•erickhill•44m ago•1 comments

Show HN: Free.ai

https://free.ai/
3•nadermx•45m ago•2 comments

MyHousingWiki: Crowdsourced Insights on Indian Apartments

https://www.myhousingwiki.com/
1•sawyerbilt•46m ago•0 comments

How Kimi, Cursor, and Chroma Train Agentic Models with RL

https://www.philschmid.de/kimi-composer-context
1•criscros•48m ago•0 comments

How a Mechanical Watch Works

https://ciechanow.ski/mechanical-watch/
3•josh-sematic•49m ago•1 comments

The first 40 months of the AI era

https://lzon.ca/posts/other/thoughts-ai-era/
2•jpmitchell•50m ago•0 comments

An investigation of the forces behind the age-verification bills

https://lwn.net/Articles/1062779/
3•greggyb•51m ago•0 comments