frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Show HN: Hextrap – Package Firewall with OPA Policies and MCP Support

https://hextrap.com/products/firewall/
1•thenrich99•1h ago
We’re building Hextrap (https://hextrap.com/products/firewall/), a package firewall to make it easier for teams and organizations to govern the packages installed from their favorite NPM, PyPI, Go, and Rust registries using managed allow/deny lists, custom OPA policies, and built-in safeguards like soak time (new versions are quarantined for a configurable amount of time - most malicious packages are discovered within 48h) and typosquatting detection. Every `pip install`, `npm install`, and `go get` is proxied through Hextrap and evaluated against a target firewall.

Hextrap is designed to work with LLMs (via MCP) so tools like Claude Code will check if a package is allow-listed before downloading or adding it to a project (in addition to using the proxy at install time). This bridges the gap between Claude’s planning and execution phases and creates a more collaborative experience with the developer when libraries are being chosen (i.e. pyramid is not allow-listed, should I try Django or Flask instead?)

In addition to the above, security data and package metadata is made available to OPA so teams can use the extra information to craft their own custom Rego policies (i.e. package must have had at least n commits in the past 6 months, have at least 1,000 stars, and a Hextrap security score above 75). We pull in data directly from the public registries and generate security signals that help identify version-level threats within packages.

You can try it out without signing up or giving us an email address here: https://hextrap.com/try

We’re actively building this product and are curious what the HN crowd thinks about the proxy-approach, the MCP integration point, and whether OPA was the right choice for policy as code.

ZCode

https://zcode.z.ai/en
2•chvid•1m ago•0 comments

The LCD7-Panel-LIME2: A Ready-to-Mount Linux Touch Panel Computer

https://olimex.wordpress.com/2026/06/17/introducing-the-lcd7-panel-lime2-a-ready-to-mount-linux-t...
2•jandeboevrie•2m ago•0 comments

Versioning the Harness Itself

https://blog.tacoda.dev/versioning-the-harness-itself-38ddf7abffe0
2•tacoda•3m ago•0 comments

Elon – Official Movie Trailer – The Story of Tesla – Based on a True Story[video]

https://www.youtube.com/watch?v=o-GbEHKeMM8
2•pgroverman•3m ago•0 comments

See What's Next for Firefox

https://www.firefox.com/en-US/whatsnext/
2•birdculture•4m ago•0 comments

Show HN: How to Read a Dosa Menu

https://dosadecoder.com/
2•michaeljnatkin•4m ago•0 comments

A Hidden Infrastructure: Arbuscular Mycorrhizal Fungi Networks

https://a-hidden-infrastructure.spun.earth/story
2•tinkelenberg•5m ago•0 comments

The Rape of Britain

https://world.hey.com/dhh/the-rape-of-britain-610412f8
4•Tomte•7m ago•2 comments

FP8 GEMM Optimization on AMD CDNA4 Architecture

https://rocm.blogs.amd.com/software-tools-optimization/cdna4-gemm-kernels/README.html
2•skidrow•8m ago•0 comments

How Claude Code Broke My Git Worktree

https://medium.com/@Koukyosyumei/how-claude-code-completely-broke-my-git-worktree-fc74effc9c4e
2•syumei•8m ago•0 comments

Show HN: Infinite – query your GA4/Stripe/PostHog data locally, on your machine

https://github.com/Infinite-Labs-AI/infinite-os
2•RiverXR•8m ago•0 comments

Europe's housing shortages are worse than America's

https://www.worksinprogress.news/p/europes-housing-shortages-are-even
2•bensouthwood•8m ago•0 comments

Occupancy Math on the AMD MI355X: A From-First-Principles Guide

https://indianspeedster.github.io/blog/occupancy-math-mi355x/
2•skidrow•8m ago•0 comments

Horizons

https://ssd.jpl.nasa.gov/horizons/
2•andsoitis•8m ago•0 comments

Show HN: Agentspace – long-running YOLO agent sessions in Docker

https://github.com/ImreC/agentspace
2•Notch123•9m ago•0 comments

Ask HN: Are other people seeing a spike in IT problems with businesses?

2•PaulHoule•9m ago•0 comments

Bolivia's Big Reset: 20 Years of Mas Over, Economy in Emergency

https://www.riotimesonline.com/bolivia-economy-elections-2026-guide/
2•simonebrunozzi•10m ago•0 comments

Show HN: Quake ported to 3D CSS (no WebGL)

https://cssquake.com/
2•rofko•10m ago•0 comments

Nobody clicks your share buttons

https://ankursethi.com/blog/nobody-clicks-your-share-buttons/
2•dredmorbius•10m ago•1 comments

Kernel 7.1: Graphics, Rust, and SoC Improvements

https://www.collabora.com/news-and-blog/news-and-events/kernel-7.1-graphics,-rust,-and-soc-improv...
2•losgehts•10m ago•0 comments

How real are real numbers? (2004)

https://arxiv.org/abs/math/0411418
2•downbad_•11m ago•0 comments

Interview with a Pornhub Web Developer (2019)

https://davidwalsh.name/pornhub-interview
2•downbad_•12m ago•0 comments

Show HN: TTT – A terminal IDE with standard keybindings, no modal editing

https://tttedit.dev/
2•eugenioenko•12m ago•0 comments

Clone any fashion video with AI

1•mohitkinra•13m ago•0 comments

Epic Games announces Lore version control system

https://lore.org/
31•regnerba•13m ago•17 comments

Treasure Hunting: Trillions of dollars of critical minerals sitting on sea floor

https://arenamag.com/articles/treasure-hunting
2•crescit_eundo•13m ago•1 comments

There is no such thing as f*cked

https://www.joanwestenberg.com/p/there-is-no-such-thing-as-fked
1•spking•13m ago•0 comments

Brighton woman acquitted on charge of persistent emails to cause annoyance to PM

https://www.doughtystreet.co.uk/news/brighton-woman-acquitted-charge-persistent-emails-cause-anno...
1•randycupertino•15m ago•0 comments

Journalling (The Herman Way)

https://marcg.net/journalling-the-herman-way/
1•speckx•15m ago•0 comments

Show HN: Code and reviews that only count if they survive an attack

https://github.com/lolu1032/pantheon-skills
1•lolu1032•15m ago•0 comments