frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: SafeInstall – local install-time guardrails for NPM/pnpm/bun

https://www.safeinstall.dev/
2•MichaelLabitzke•3h ago
Hey HN — after the Axios attack I went looking for something that could help against this kind of install-time risk. I didn’t find a tool that did what I wanted, so I built one. SafeInstall is a local CLI for npm, pnpm, and bun. It checks policy before the package manager runs. Especially now, when tons of people are building with AIs like Cursor and Claude and either give them full rights or just hit enter on every prompt, I thought it was important to build a guardrail before the install happens.

By default it: blocks very fresh registry releases blocks lifecycle scripts unless explicitly allowed blocks git, tarball, and URL installs by default catches trust downgrades, like registry-to-git changes or newly introduced install scripts

Optional checks: typo-squat detection Sigstore provenance verification with publisher/repo pinning, so a package can be tied to an expected source instead of accepting any valid signature

It’s MIT licensed, runs locally, and doesn’t require an account or signup. Repo: https://github.com/Mickdownunder/SafeInstall Website: https://safeinstall.dev I’m interested in feedback on the policy model and on which checks should or shouldn’t be enabled by default.

It's OK to compare floating-points for equality

https://lisyarus.github.io/blog/posts/its-ok-to-compare-floating-points-for-equality.html
1•coinfused•48s ago•0 comments

80386 Memory Pipeline

https://nand2mario.github.io/posts/2026/80386_memory_pipeline/
1•wicket•48s ago•0 comments

Show HN: A Birth Control Pill Reminder for Couples

https://paircare.love/
1•oyaa52•1m ago•0 comments

OpenAI rips Anthropic, distances itself from Microsoft

https://www.axios.com/2026/04/13/openai-microsoft-anthropic-amazon
1•Brajeshwar•3m ago•0 comments

Show HN: I Added Support for Qwen3-ASR and Qwen3 ForcedAligner in WhisperX

https://github.com/m-bain/whisperX/pull/1401
1•mahfouz22•3m ago•0 comments

I built an AI to do my job end-to-end. The problem wasn't the AI

https://medium.com/@iroy2000/i-tried-to-automate-my-own-job-heres-what-i-found-15fb86d415c2
1•iroy2000•5m ago•1 comments

Using Actor Network Theory to rethink work in the age of generative AI

https://stripepartners.substack.com/p/this-months-frame-using-actor-network
1•laurex•5m ago•0 comments

Show HN: Messaging without phone numbers, email, or metadata

https://tunnelmessenger.com/access
1•trpfnc•6m ago•0 comments

Show HN: LoadLens – See why queues hide overload instead of solving it

https://loadlens.dev
1•janbalangue•7m ago•0 comments

Show HN: AriaType – open-source privacy-first and local-first voice-to-text app

https://github.com/joe223/AriaType
1•Joe_Harris•8m ago•0 comments

Bot Bait – Just hit $2K MRR after 8 months of grinding

https://old.reddit.com/r/SaaS/comments/1sl3mrh/just_hit_2k_mrr_after_8_months_of_grinding
1•csomar•8m ago•0 comments

Show HN: Cliparr – Export clips from your personal media server

https://github.com/TechSquidTV/Cliparr
1•TechSquidTV•9m ago•0 comments

Same LLM, different agent: a CI debugger built on Claude

https://www.mendral.com/blog/same-llm-different-agent
1•shad42•11m ago•0 comments

The Meta Product Manager

https://k2xl.substack.com/p/the-meta-product-manager
2•k2xl•11m ago•0 comments

Building a Browser for the Agent Era

https://www.tinyfish.ai/blog/building-a-browser-for-the-agent-era
3•tiny-automates•12m ago•2 comments

Missing Emails in Gmail? It's Your Tabs – and It Costs You More Than You Think

https://clearmailapp.com/blog/gmail-missing-emails-hidden-cost/
1•raghukumar•12m ago•0 comments

Ozempic Dreams

https://daverupert.com/2026/04/ozempic-dreams/
2•speckx•13m ago•0 comments

Hyperbridge exploited two weeks after April Fools' hack joke

https://www.web3isgoinggreat.com/single/hyperbridge-exploit
3•LorenDB•14m ago•0 comments

Is This Agent Safe? Free security checker with scores no platform can revoke

https://agentgraph.co/check
1•kenneives•14m ago•0 comments

Zig 0.16.0 Release Notes

https://ziglang.org/download/0.16.0/release-notes.html
4•ska80•14m ago•0 comments

Amazon Bio Discovery

https://aws.amazon.com/blogs/industries/introducing-amazon-bio-discovery/
1•firasd•14m ago•0 comments

Google, Microsoft, Meta All Tracking You Even When You Opt Out

https://www.404media.co/google-microsoft-meta-all-tracking-you-even-when-you-opt-out-according-to...
13•Cider9986•14m ago•0 comments

Airbnb Hosts Dont Want to Talk to Guests Anymore, Are Outsourcing Messages to AI

https://www.404media.co/airbnb-hosts-dont-want-to-talk-to-guests-anymore-are-outsourcing-messages...
1•Cider9986•15m ago•0 comments

New toothpaste stops gum disease without killing good bacteria

https://www.sciencedaily.com/releases/2026/04/260413043141.htm
1•atombender•15m ago•0 comments

Prolog Implementation of the IRS Fact Graph

https://github.com/alexpetros/factgraph.pl
1•triska•15m ago•0 comments

IMF warns global economy at risk of recession if Iran war persists

https://www.bbc.com/news/articles/c4g66p2q075o
1•Cider9986•15m ago•0 comments

For the First Time in the U.S., Renewables Generate More Power Than Natural Gas

https://e360.yale.edu/digest/us-renewables-natural-gas-coal
18•Brajeshwar•17m ago•1 comments

1-Bit Bonsai: The First Commercially Viable 1-Bit LLMs

https://prismml.com/news/bonsai-8b
1•wicket•18m ago•2 comments

The Fediverse deserves a dumb graphical client

https://adele.pages.casa/md/blog/the-fediverse-deserves-a-dumb-graphical-client.md
4•speckx•18m ago•1 comments

Show HN: A memory database that forgets, consolidates, and detects contradiction

https://github.com/yantrikos/yantrikdb-server
2•pranabsarkar•20m ago•1 comments