frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Non-determinism is an issue with patching CVEs

https://flox.dev/blog/achieving-rapid-cve-remediation-in-an-era-of-escalating-vulnerabilities/
21•mathewpregasen•1h ago

Comments

jambay•1h ago
There has been so much discussion about the increase of volume in CVEs. I love that it's super apparent from looking at that graph of CVEs by year, there is a noticeable bend in the slope upward in the 2026 plot. It's not just hype, the rate of CVEs is changing faster than prior years.
LoganDark•1h ago
That is not the title of the article:

> Achieving CVE Remediation in an Era of Escalating Vulnerabilities

tptacek•1h ago
Reads kind of sales-pitchy. Every day we see another actively exploited Linux LPE; have you thought about your SBOM today?
ronef•48m ago
I feel we should definitely be digging way beyond the SBOM... but also wondering if the forecasting in the general ecosystem is on point or not.
ronef•47m ago
I.e. is this overhyped?
ohnei•15m ago
I like nix and its approach but if I'm being honest I think its also getting easier to be sloppy about dependencies and ask AI to find any dependencies that might be missing from the cleanly installed packaging metadata. There's maybe a paradox for developers in that we can try to drop structure and brute force scan first intensively enough to catch anything likely to get caught or we can ask AI to finally apply all the rigorous methods we decided were too expensive for routine software and probably have minimally more things to run with each release.
tremon•13m ago
Are you offering an easy fix for that "Linux" line on your SBOM?

Palo Alto Lost Its Zoning War (and Now Looks Like This)

https://www.youtube.com/watch?v=XBWyE2bGaLk
1•bane•2m ago•0 comments

Student sues matchmaking app for allegedly stealing her likeness for an ad

https://mashable.com/article/student-sues-meete-for-allegedly-stealing-likeness-geofencing
5•gnabgib•5m ago•0 comments

Show HN: Contral – the agent which will teach you while you build with AI

https://contral.ai
2•samagragune•6m ago•1 comments

So that's why they call it "YOLO-mode"

3•neurodiv_dennis•9m ago•2 comments

The Moth Story Map

https://themoth.org/dispatches/story-map
1•jxmorris12•10m ago•0 comments

The Eye in Your Pocket

https://aeon.co/essays/things-have-jobs-and-digital-devices-are-made-to-track-you
3•billybuckwheat•11m ago•0 comments

Thunderbird donation page consumes CPU/GPU due to animation

https://bugzilla.mozilla.org/show_bug.cgi?id=2038287
1•nh2•12m ago•0 comments

AI makes weak engineers less harmful

https://www.seangoedecke.com/ai-makes-weak-engineers-less-harmful/
2•bsgada•16m ago•0 comments

GrapheneOS isn't vulnerable to the 3 recent Linux memory logic vulnerabilities

https://discuss.grapheneos.org/d/35353-grapheneos-isnt-vulnerable-to-the-3-recent-linux-memory-lo...
3•Cider9986•17m ago•0 comments

Humanity Is Self-Deprecating

https://not-an-llm.bearblog.dev/humanity-is-self-deprecating/
2•nusl•19m ago•1 comments

Scroll Animation in Pure CSS

https://www.joshwcomeau.com/animation/scroll-driven-animations/
1•zane__chen•19m ago•0 comments

NetBSD Wii IP6 Webserver

http://wii.sjmulder.nl/
1•jaypatelani•20m ago•0 comments

The 'dangerous' promise of a techno-utopian future

https://www.cbc.ca/radio/ideas/tech-billionaires-ai-utopia-1.7440698
2•lbrito•21m ago•1 comments

Disappearing Polymorph

https://en.wikipedia.org/wiki/Disappearing_polymorph
2•ZeljkoS•25m ago•0 comments

Teaching Claude Why

https://alignment.anthropic.com/2026/teaching-claude-why/
1•cebert•27m ago•0 comments

How Do You Know If a Skill Is Any Good? LLM-as-Judge Scoring

http://instructionmanuel.com/scoring-skills-with-llm-as-judge
2•eigenBasis•29m ago•0 comments

US judge will not rubber-stamp Elon Musk settlement with SEC

https://www.reuters.com/legal/government/us-judge-will-not-rubber-stamp-elon-musk-settlement-with...
5•tartoran•31m ago•0 comments

Next.js May 2026 security release

https://vercel.com/changelog/next-js-may-2026-security-release
1•bcye•32m ago•0 comments

Onboarding Is a Hazing Ritual and You Call It Agile

https://dhung.dev/blog/onboarding-hazing-ritual
2•birdculture•33m ago•0 comments

Judge rules DOGE cancellation of humanities grants was unconstitutional

https://apnews.com/article/trump-doge-humanities-funding-cuts-dda1383436c41be08da3bbf7cc08818e
10•1659447091•34m ago•3 comments

NixOS and Secrets

https://isabelroses.com/blog/nixos-and-secrets/
3•isabelroses•34m ago•0 comments

Show HN: Signegy - free in-browser PDF toolkit, no signup

https://signegy.com/
1•DiligentPeasant•34m ago•0 comments

Ask HN: What kind of computer language will LLM use?

2•folderquestion•37m ago•2 comments

Anthropic weighs deal for near $1T valuation as revenue surges

https://www.ft.com/content/a40cafcc-0fa4-4e70-9e24-90d826aea56d
6•alecco•39m ago•1 comments

I made Meta's TRIBE v2 watch YouTube in real time

https://www.youtube.com/watch?v=I4oGPLMVoC0
1•merlin_mimer•39m ago•0 comments

Compound drivers of Antarctic sea ice loss and Southern Ocean destratification

https://www.science.org/doi/10.1126/sciadv.aeb0166
3•littlexsparkee•40m ago•0 comments

General Motors fined $12.75M for selling location data

https://privacy.ca.gov/2026/05/when-it-comes-to-data-privacy-consumers-must-be-in-the-drivers-sea...
4•jboggan•41m ago•1 comments

Show HN: Tuxedo – A fast, keyboard-driven terminal UI for todo.txt

https://github.com/webstonehq/tuxedo
1•mikenikles•41m ago•1 comments

Scaling Trusted Access for Cyber with GPT‑5.5 and GPT‑5.5‑Cyber

https://openai.com/index/gpt-5-5-with-trusted-access-for-cyber/
2•allanrbo•46m ago•0 comments

55 Hours of Codex /Goal: What a Port Task Teaches You About Autonomous Loops

https://vexjoy.com/posts/55-hours-of-codex/
1•AndyNemmity•49m ago•0 comments