frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: CargoWall – eBPF Firewall for GitHub Actions

https://github.com/code-cargo/cargowall-action
10•caleblloyd•1h ago
We just open-sourced CargoWall - a lightweight eBPF firewall for GitHub Actions.

We originally built it to stop LLM agents from connecting to untrusted domains. After recent GitHub Actions supply chain compromises like the Trivy attack, we realized it'd work well for blocking untrusted connections from CI runners too.

It uses iptables DNAT to redirect all outbound port 53 traffic to a local DNS proxy, which checks each query against a hostname allowlist before forwarding. Resolved IPs from allowed responses are inserted into eBPF LPM trie maps, and a TC egress classifier attached to the network interface drops any packet whose destination IP/protocol/port isn't in the trie.

Cgroup hooks capture every socket connect/sendmsg call system-wide, mapping the socket cookie to the process to correlate where connections are coming from. It then correlates the connection times with steps to provide a summary of which connections originated from which steps.

ubuntu-latest and ubuntu-24.04 runners are supported. Simple one-step setup example:

  uses: code-cargo/cargowall-action@v1   # or v1.0.0 for immutable tag
  with:
    mode: enforce
    allowed-hosts: |
      registry.npmjs.org
eBPF Program: https://github.com/code-cargo/cargowall

GitHub Action: https://github.com/code-cargo/cargowall-action

We'd love for you to give it a try! Happy to answer questions or take feedback.

Comments

wkd415•1h ago
Feels like CI/CD is still operating on a pretty optimistic threat model.
matthewdevenny•1h ago
Yes - especially when you are building on GitHub hosted runners.

Enterprises who build within their own network typically have numerous safeguards on network egress. There is cost associated with that effort though and more friction to getting reliable, fast and repeatable build environments.

This eBPF firewall helps you lockdown that network egress on GitHub's cloud and gives you observability on what each build is reaching out to.

Reusable custom syntax for any programming language (Language Workbenches) [video]

https://www.youtube.com/watch?v=XGm_khXZl44
1•gima•42s ago•1 comments

Show HN: Modolap – Machine-First Analytical Infrastructure

https://modolap.com/
1•ronfriedhaber•1m ago•0 comments

Broker for Pete Hegseth made multi-million defense investments before Iran War

https://www.reuters.com/business/finance/us-defense-secretary-hegseths-broker-looked-buy-defense-...
1•ck2•2m ago•0 comments

Show HN: Avoid AI Writing– a skill that audits text for 34 AI pattern categories

https://github.com/conorbronsdon/avoid-ai-writing
1•cliffclimber•3m ago•0 comments

Claude Code Auto Mode: A Comprehensive Technical Summary

https://gist.github.com/sc0tfree/11c86116df4c2281a976d796f9493cd7
1•sc0tfree•4m ago•0 comments

Vibe Coding a (basic) Wispr Clone in 20 minutes

https://zach.codes/p/vibe-coding-a-wispr-clone-in-20-minutes
1•zackify•5m ago•0 comments

You Can't Escape the AI Tax

https://www.theatlantic.com/technology/2026/03/laptop-electronics-ram-ai-tax/686628/
1•samizdis•5m ago•0 comments

Rejected by iloveimg so created ihateimg

https://ihateimg.com/
1•ajdeez•5m ago•0 comments

Ollama Now Runs Faster on Macs Thanks to Apple's MLX Framework

https://www.macrumors.com/2026/03/31/ollama-now-runs-faster-apple-silicon-macs/
1•alwillis•5m ago•0 comments

Google lets you ditch that embarrassing old Gmail username

https://www.androidauthority.com/change-google-account-gmail-username-usa-rollout-3653478/
2•speckx•9m ago•0 comments

Show HN: Lazy-tool: reducing prompt bloat in MCP-based agent workflows

https://github.com/rpgeeganage/lazy-tool
6•like-to-code1•9m ago•0 comments

Fast sandboxed code execution with pre-warmed gVisor pools

https://github.com/shayonj/gvisord
2•shayonj•10m ago•0 comments

From "Show Me" to "Do It": How OdooClaw Takes Action in Your Odoo

https://www.odooclaw.ai/blog/how-odooclaw-takes-action-in-your-odoo
2•oktra_dev•11m ago•0 comments

Show HW: How This Graybeard Built the Fastest and Freest Postgres BM25 Search

https://github.com/timescale/pg_textsearch
2•tjgreen•12m ago•1 comments

Show HN: LeetChess – Solve Chess Puzzles on New Tab Pages

https://chromewebstore.google.com/detail/leetchess/hogbcffpfhmcagfjbpiofabechljdflk
3•0xmattf•13m ago•0 comments

Cohere Transcribe: Speech Recognition

https://cohere.com/blog/transcribe
7•gmays•14m ago•0 comments

Sigil CMS – headless CMS with native multi-tenancy, 22 plugins, GraphQL and CLI

https://github.com/Netrun-Systems/sigil-cms
2•DanielGarza•15m ago•0 comments

Show HN: PhAIL – Real-robot benchmark for AI models. The gap to humans is 20x

https://phail.ai
2•vertix•16m ago•3 comments

Why some American accents have endured – while others have faded away

https://www.vox.com/explain-it-to-me/483964/american-accent-history-identity-southern-new-england...
1•speckx•16m ago•0 comments

AI agent that writes and hot-reloads its own Python modules at runtime

https://github.com/asieltechlab/asiel-core
1•asieltechlab•18m ago•0 comments

Show HN: Wageslave – I quit my soul sucking job to make a game about it

https://cauldron.itch.io/wageslave
3•stonecauldron•20m ago•0 comments

Forth VM and compiler written in C++ and Scryer Prolog

https://github.com/no382001/forth-vm
2•triska•20m ago•0 comments

The Last Fingerprint: How Markdown Training Shapes LLM Prose

https://arxiv.org/abs/2603.27006
1•Er-c•20m ago•0 comments

Interaction Nets

https://en.wikipedia.org/wiki/Interaction_nets
1•tosh•21m ago•0 comments

Build with Veo 3.1 Lite, our most cost-effective video generation model

https://blog.google/innovation-and-ai/technology/ai/veo-3-1-lite/
3•meetpateltech•23m ago•0 comments

Analyzing Geekbench 6 Under Intel's Binary Optimization Tool (Bot)

https://www.geekbench.com/blog/2026/03/analyzing-geekbench-6-under-intels-bot/
1•gloxkiqcza•23m ago•0 comments

Ask HN: What are you building with AI coding agents / tooling?

2•giancarlostoro•24m ago•0 comments

The Overvaluation Trap (2015)

https://hbr.org/2015/12/the-overvaluation-trap
1•toomuchtodo•24m ago•0 comments

I made a 3D Browser to review my HN upvotes [video]

https://www.youtube.com/watch?v=1MiMlorMMJM
2•ppqqrr•27m ago•0 comments

Building a Powerful SIEM with ClickHouse and Clickdetect – Wazuh – SQL Detection

https://medium.com/@me_15345/building-a-powerful-siem-with-clickhouse-and-clickdetect-ae68a4495a76
2•souzo•27m ago•0 comments