frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Whose Trust Is It Anyway? Configuration Boundaries in AI Development Tools

3•kundanydv•1h ago
Writeup: https://github.com/kunn007/claude-code-trust-boundaries

When an AI coding agent runs in a CI/CD pipeline against a repository it didn't author, should that repository's configuration be able to expand the agent's permissions?

Two vendors gave opposite answers in April 2026 to closely related versions of this question. Google rated Gemini CLI's headless workspace trust behavior as Critical (CVSS 10.0) and patched it. Anthropic, after reviewing two related findings I reported for Claude Code, classified the behavior as working as designed — non-interactive mode delegates trust decisions to the automation caller.

The writeup tries to lay out both positions fairly. Anthropic's view aligns with how Make, npm, and Cargo have always handled project config (operator owns the trust decision). Google's view is that AI agents are different enough to warrant a stricter default.

AI optimism is waning

https://bayeslord.substack.com/p/ai-optimism-is-waning
1•swah•1m ago•0 comments

Guardians: Static verification for AI agent workflows

https://github.com/metareflection/guardians
1•matt_d•1m ago•0 comments

CopyFail Was Not Disclosed to Distros

https://www.openwall.com/lists/oss-security/2026/04/30/10
1•ori_b•2m ago•0 comments

Show HN: I built a private GitHub in 650 lines of PostgreSQL

https://github.com/calebwin/gitgres
1•calebhwin•3m ago•0 comments

AI Investment Boosted Economic Growth, While Consumers Tapped the Brakes

https://www.wsj.com/economy/central-banking/u-s-economy-grew-at-2-rate-in-first-quarter-6e0c18cc
1•JumpCrisscross•4m ago•0 comments

Show HN: Larkin – Authorization middleware for x402 agent payments

https://larkin.sh
1•mikebom•4m ago•0 comments

Vision agents vs. structured APIs on the same internal tool task

1•FirestarAlpha•4m ago•0 comments

The Whistleblower Who Uncovered the NSA's 'Big Brother Machine'

https://thereader.mitpress.mit.edu/the-whistleblower-who-uncovered-the-nsas-big-brother-machine/
2•the-mitr•5m ago•0 comments

Xatastor: ZFS and NVMe-Of for Postgres Databases

https://xata.io/blog/xatastor-zfs-nvme-of-for-millions-of-postgres-databases
2•tee-es-gee•6m ago•0 comments

Fast GPU Linear Algebra via Compile Time Expression Fusion

https://arxiv.org/abs/2604.22242
1•matt_d•7m ago•0 comments

American Dads Became the Parents Their Fathers Never Were

https://www.derekthompson.org/p/why-do-richer-dads-spend-more-time
1•ozozozd•7m ago•0 comments

Command Decision System for organizational risk (not average-based)

https://github.com/knuppjason-source/Human-Factors-App
1•Knuppjason•8m ago•0 comments

Show HN: Phase Router – capacity-aware routing for MoE

https://github.com/TSltd/phase_router_rs
1•TSltd•8m ago•0 comments

Largest Digital Human Rights Conference Suddenly Canceled

https://www.404media.co/rightscon-human-rights-conference-suddenly-postponed/
3•Brajeshwar•10m ago•0 comments

Long-Running Agents

https://addyo.substack.com/p/long-running-agents
2•swolpers•11m ago•0 comments

Maximilian Schwarzmüller – GitHub is facing problems [video]

https://www.youtube.com/watch?v=pekbl3Yz02g
1•mindcrime•12m ago•0 comments

Constraints That Compute: A Unified Framework for Efficient Intelligence

https://zenodo.org/records/19895574
1•massimiliano_c•12m ago•0 comments

Dotcl: Common Lisp Implementation on .NET

https://github.com/dotcl/dotcl
4•reikonomusha•12m ago•0 comments

Illegal vs. Unwanted States

https://buttondown.com/hillelwayne/archive/illegal-vs-unwanted-states/
1•azhenley•13m ago•0 comments

SatoshiGuesser – Roll for Bitcoin

https://github.com/Pathos0925/SatoshiGuesser
6•ilarum•16m ago•1 comments

China pushes EU capitals to scrap 'Made in Europe' law or face retaliation

https://www.euronews.com/my-europe/2026/04/29/china-pushes-eu-capitals-to-scrap-made-in-europe-la...
2•Teever•19m ago•1 comments

A text editor as a user interface

https://ratfactor.com/cards/text-editor-as-ui
1•ibobev•20m ago•0 comments

Nvidia Nemotron 3 Nano Omni

https://huggingface.co/blog/nvidia/nemotron-3-nano-omni-multimodal-intelligence
1•ibobev•21m ago•0 comments

The Day I Logged 1 in Every 2000 Public IPv4: Visualizing the AI Scraper DDoS

https://vulpinecitrus.info/blog/one-in-every-2000-ipv4-visualizing-ddos-ai-web-scrapers/
1•birdculture•21m ago•0 comments

Ask HN: Instead of intrusive age-check why can't we have "two internet"?

2•kreco•21m ago•3 comments

AI evals are becoming the new compute bottleneck

https://huggingface.co/blog/evaleval/eval-costs-bottleneck
1•ibobev•21m ago•0 comments

Agentic User Research Tool

https://github.com/elpabl0/research-ai
1•elpabl0•23m ago•0 comments

You're probably taking the wrong painkiller

https://dynomight.net/painkillers/
1•ahlCVA•23m ago•0 comments

How to stop your agents from making the same mistakes

https://twitter.com/garrytan/status/2046876981711769720
1•gmays•24m ago•0 comments

Ask HN: Are github.com previews broken on Slack?

1•statico•24m ago•0 comments