frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: How do you defend against supply chain attacks today?

5•elric•1h ago
Seems like software supply chain attacks have been increasing in speed, scope, and complexity of late. Especially in NPM and PyPi packages.

How are people defending against this increased threat? Relying on dependency scanners seems way too slow now. Automagically updating to the latest & greatest is likely to include the latest & greatest malware. Auditing every version of every dependency in use is going to be a costly affair.

Comments

tuananh•1h ago
You can setup local proxy registry. set policy for the registry to set cool down period (7-14 days maybe). That will at least limit some of the blast radius
josteinhylin•1h ago
Lol
ggeorgovassilis•48m ago
On two levels: architecture and understanding. Architecture: I divide the solution components of my architecture into two groups: the ones where a security breach spills over their scope and the ones where it doesn't. For the first category (eg. network- or user-facing), dependencies will be limited as much as possible, meaning I'll forgo convenience and features. I'll pick LTS or older versions with no known vulnerabilities. The second category is locked up in containers with minimal connectivity, with on-demand run-time schedules. Understanding: depending on risk and importance, I actually check out a dependency's source code and have an AI review it. Then rebuild and self-host.

Edit: this approach sounds like it could be bundled into a couple of agents.

elric•14m ago
I wasn't expecting any architectural answers when I asked the question (not that I knew what to expect, hence the question), but I'm adding this one to my list of "why architecture matters".

AI Symfony: Build AI-powered applications with PHP components

https://ai.symfony.com/
1•BafS•1m ago•0 comments

Seedream47 Is on the Way

https://seedream47.com
1•Jenny249•1m ago•0 comments

Glint of light in therapy for deadly ALS after decades of struggle

https://news.harvard.edu/gazette/story/2026/05/glint-of-light-in-therapy-for-deadly-als-after-dec...
1•speckx•2m ago•0 comments

China's Grey Market for Cheap Claude Tokens

https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens-in
2•tristanj•4m ago•1 comments

List of JJ Aliases

https://www.lysator.liu.se/~axl/jj-aliases/
2•nvahalik•4m ago•0 comments

The Subaru X-100: The Plane-Shaped Car to Cross the US on a Single Tank of Gas

https://www.jalopnik.com/2152373/subaru-x-100-plane-shaped-car-cross-u-s-one-tank/
2•voxadam•6m ago•0 comments

You can reverse much of the damage alcohol has done to your body, science says

https://www.cnn.com/2026/05/14/health/alcohol-harm-reversed-wellness
2•sleepyguy•7m ago•1 comments

100 million degrees: Step inside the heart of our fusion machine [video]

https://www.youtube.com/watch?v=ksSr4mREK6I
2•breve•8m ago•0 comments

Marketing Roadmap

https://github.com/marketingtoolslist/marketing-roadmap
3•dariubs•9m ago•0 comments

Show HN: A simple Claude skin for ChatGPT

https://github.com/dmd/aimpostor
3•dmd•12m ago•0 comments

Government privatization efforts grow, contractor lawsuits more get difficult

https://theconversation.com/as-government-privatization-efforts-grow-lawsuits-against-federal-con...
2•PaulHoule•12m ago•0 comments

Ask HN: What's the hardest part of building a SaaS that users keep paying for?

4•specwiseai•13m ago•0 comments

Show HN: An opinionated index of AI developer tools

https://devindex.ai/
2•karphi•14m ago•0 comments

Ctx-opt: TypeScript middleware to trim LLM chats to a token budget

https://github.com/EvanPaules/ctx-opt
1•ep13•14m ago•0 comments

The AI layoffs end in 12 months and I know why [video][10 mins]

https://www.youtube.com/watch?v=doI1GYZ7r-w
2•Bender•14m ago•0 comments

Meta's New Reality: Record High Profits. Record Low Morale

https://www.wired.com/story/meta-layoffs-bad-vibes-mark-zuckerberg-ai/
6•rustoo•15m ago•0 comments

Show HN: Ungate – use Claude and GPT subscriptions in Cursor without API costs

https://github.com/orchidfiles/ungate
1•theorchid•15m ago•1 comments

Quip Retirement

https://help.salesforce.com/s/articleView?language=en_US&id=005299603&type=1
1•zeroonetwothree•15m ago•0 comments

Show HN: Race to the Bottom

https://race-to-the-bottom.onrender.com
1•maxwellito•16m ago•0 comments

For three years I scoured the world for answers to Europe's big problems

https://www.theguardian.com/commentisfree/2026/may/14/europe-big-problems-japan-taiwan-care-systems
1•robtherobber•17m ago•0 comments

An AI Poop Analysis App Offered to Sell Me Database of Its Users' Poops

https://www.404media.co/ai-poop-analysis-app-offered-to-sell-me-access-to-its-users-poops/
2•SpyCoder77•19m ago•0 comments

Why Can't Writers Seem to Quit Substack?

https://www.talkscratch.com/why-cant-writers-seem-to-quit-substack/
3•tolerance•21m ago•1 comments

Remove ML Compatibility (F#)

https://github.com/dotnet/fsharp/pull/19143
3•DASD•22m ago•0 comments

AI helps man recover $400k in Bitcoin 11 years after

https://www.dexerto.com/entertainment/ai-helps-man-recover-400000-in-bitcoin-11-years-after-he-go...
3•kouosi•24m ago•0 comments

How do we incentivize students not to cheat using AI?

https://twitter.com/NirZicherman/status/2054922354074026456
3•nir-zicherman•25m ago•0 comments

Fate 1.0: An Async React data framework

https://fate.technology/posts/fate-1.0
3•cpojer•26m ago•0 comments

I started a restaurant and it ruined my life

https://torontolife.com/food/restaurant-ruined-life/
5•ewf•26m ago•0 comments

FCC angers small carriers by helping AT&T and Starlink buy EchoStar spectrum

https://arstechnica.com/tech-policy/2026/05/fcc-angers-small-carriers-by-helping-att-and-starlink...
2•voxadam•26m ago•0 comments

US Oil Storage Tanks to Run Empty Around July 4, Currie Says [video]

https://www.youtube.com/watch?v=ckSW3gM7Lqc
3•mooreds•28m ago•0 comments

Time-Series Feature Engineering with Python Itertools

https://www.kdnuggets.com/time-series-feature-engineering-with-python-itertools
5•eigenBasis•28m ago•0 comments