frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

No one owes you supply-chain security

https://purplesyringa.moe/blog/no-one-owes-you-supply-chain-security/
20•birdculture•1h ago

Comments

MeetingsBrowser•48m ago
> So, I have opinions about criticism of crates.io for supply-chain attacks.

I also strongly disagree with most of the criticisms of crates.io, but…

We are owed supply chain security. The moment a group says “use our stuff for critical projects” they take on some baseline level of responsibility for making things secure.

You cannot offer a taxi service in a car that is not fit for the road, and then just shrug when it crashes a people get hurt.

The good news is the people behind crates.io and the Rust ecosystem care about security. They have given conference talks about what they are doing behind the scenes. Features like Trusted Publishing are a huge step in the right direction.

As far as I can tell, the issue is not with the crates.io team, but funding and incentives as a whole. We all rely on critical infrastructure like package managers, but not many are willing to fund big security improving features.

trollbridge•34m ago
Owed by whom, though? That seemed to the point of the article - "owed" implies some kind of debt or obligation. Free software developers don't have any obligations to anyone else.
MeetingsBrowser•27m ago
Once you advertise and ask people use your software in production, you have an obligation to make sure it is somewhat safe.

If you actively advertise and give away free food, there is a baseline assumption that you are at least cooking the food in sanitary conditions.

If people get sick after eating the food you gave them, you can’t just shrug and say it was free.

6keZbCECT2uB•6m ago
Your reasonable options are: 1. I stop sharing the software I write 2. You take responsibility for the software you use

Any software you use with this clause, "THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE."

Already attests that the authors do not offer guarantees that the software will have the features you need, supply chain security or otherwise.

Zigurd•36m ago
This is bad by being a categorical statement. But it's also a bad categorical statement because it's like saying nobody owes you being able to assume your car has airbags and seatbelts that meet high standards.
1970-01-01•14m ago
It's the gift of open source: Nobody owes you anything except the source code. Any and all guarantees must be via written contracts. Nobody owes you a secure supply chain until there is a contract stating such.

158-year-old home distilling ban ruled unconstitutional

https://www.reuters.com/legal/government/us-appeals-court-declares-158-year-old-home-distilling-b...
1•PessimalDecimal•44s ago•0 comments

Dario Says Continual Learning Is Solved. Is It?

https://twitter.com/tianle_cai/status/2042459055483207818
1•gmays•1m ago•0 comments

Show HN: Kafkaesque – a wire-compatible mock Kafka

https://github.com/dcminter/kafkaesque
1•dcminter•4m ago•0 comments

HappyHorse AI Video Generator

https://openhappyhorse.io/
1•cathy246•7m ago•1 comments

LRTS – Regression testing for LLM prompts (open source, local-first)

https://github.com/rufus-SD/lrts
1•arthur-G•14m ago•0 comments

Metallic θ-phase tantalum nitride has thermal conductivity triple that of copper

https://www.science.org/doi/10.1126/science.aeb1142
2•bookofjoe•15m ago•0 comments

Seven countries now generate 100% of their electricity from renewable energy

https://www.the-independent.com/tech/renewable-energy-solar-nepal-bhutan-iceland-b2533699.html
3•mpweiher•16m ago•0 comments

Tell HN: OpenAI silently removed Study Mode from ChatGPT

12•smokel•16m ago•1 comments

Malvertising and the trend of curl – sh install on macOS

https://pgaleone.eu/security/2026/04/12/paying-google-to-hack-macos-users/
1•me2too•16m ago•0 comments

Simple Git Server

https://sigit.si/
1•kampak212•17m ago•1 comments

Ask HN: How to build an "AI native" company?

1•canxerian•18m ago•1 comments

My adventure in designing API keys

https://vjay15.github.io/blog/apikeys/
1•vjay15•20m ago•1 comments

Apple Is Launching an 'Ultra' Line of Products with New Capabilitie

https://www.entrepreneur.com/business-news/apple-is-launching-an-ultra-line
1•f1shy•20m ago•0 comments

Pro Max 5x Quota Exhausted in 1.5 Hours Despite Moderate Usage

https://github.com/anthropics/claude-code/issues/45756
71•cmaster11•22m ago•14 comments

The physics behind Flow Matching models [video]

https://www.youtube.com/watch?v=3mFNpeJQjmw
2•kburman•25m ago•1 comments

Replacing Lenovo's WWAN Unlock Blob with a 100-Line Bash Script

https://blog.hofstede.it/replacing-lenovos-wwan-unlock-blob-with-a-100-line-bash-script/
1•birdculture•28m ago•0 comments

Show HN: Homebutler – Verify your backups restore, automatically

https://github.com/Higangssh/homebutler
3•swq115•28m ago•1 comments

AI builds anything. I Claude-coded tasteID so every AI tool just knows

https://tasteid.xyz
2•kev_earth•29m ago•0 comments

Show HN: Oberon System 3 runs natively on Raspberry Pi 3 (with ready SD card)

https://github.com/rochus-keller/OberonSystem3Native/releases
2•Rochus•31m ago•0 comments

Show HN: Ghapin – Tool to pin GitHub Actions to SHAs for supply-chain security

https://github.com/TheDen/ghapin
1•theden•35m ago•0 comments

World Socialist Web Site to Launch Socialism AI (2025)

https://www.wsws.org/en/articles/2025/11/23/ohvk-n23.html
1•darccio•35m ago•0 comments

Over 4,732 Messages, He Fell in Love with an AI Chatbot. Now He's Dead

https://www.wsj.com/tech/ai/google-gemini-jonathan-gavalas-death-07351ab2
1•Brajeshwar•37m ago•1 comments

Firms Promised HighTech Ransomware Solutions;They Usually Just Pay Hackers(2019)

https://features.propublica.org/ransomware/ransomware-attack-data-recovery-firms-paying-hackers/
1•bookofjoe•42m ago•0 comments

Show HN: SpecSource – AI That Writes Linear Specs from Sentry, GitHub, & Slack

https://www.specsource.ai
2•bring-shrubbery•43m ago•2 comments

The philosophy of great customer service (2014)

https://sive.rs/cs
3•Michelangelo11•43m ago•0 comments

Touch some grass or how to survive during AI times

https://www.mcbaguetti.xyz/touchgrass.html
2•mcbaguetti•44m ago•0 comments

OpenAI's vision for AI economy: public wealth funds, robot taxes, 4-day workweek

https://techcrunch.com/2026/04/06/openais-vision-for-the-ai-economy-public-wealth-funds-robot-tax...
2•genphy1976•46m ago•2 comments

Show HN: Real-Time OLAP Infrastructure

https://modolap.com
2•ronfriedhaber•46m ago•0 comments

Why weekends are under threat

https://thehustle.co/originals/why-weekends-are-under-threat
24•Anon84•53m ago•16 comments

Glass – a replay-first bounded investigation surface for runtime activity

https://github.com/StealthEyeLLC/glass
1•stealtheyellc•54m ago•0 comments