frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•10mo ago

Comments

steele•9mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•9mo ago
Lmao, gentrify cracked me up
neilv•9mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•9mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•9mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•9mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•9mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•9mo ago
May as well just release an executable tbh.
theamk•9mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•9mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•9mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

I Found 39 Algolia Admin Keys Exposed Across Open Source Documentation Sites

https://benzimmermann.dev/blog/algolia-docsearch-admin-keys
46•kernelrocks•1h ago•10 comments

Drone strikes in Haiti that killed 1250, 17 children, condemned by rights group

https://haitiantimes.com/2026/03/11/hrw-condemns-haiti-drone-strikes-killing-children/
90•e12e•1h ago•23 comments

Can I run AI locally?

https://www.canirun.ai/
868•ricardbejarano•11h ago•228 comments

Show HN: Channel Surfer – Watch YouTube like it’s cable TV

https://channelsurfer.tv
391•kilroy123•2d ago•136 comments

Mouser: An open source alternative to Logi-Plus mouse software

https://github.com/TomBadash/MouseControl
162•avionics-guy•5h ago•53 comments

Hammerspoon

https://github.com/Hammerspoon/hammerspoon
182•tosh•5h ago•73 comments

Qatar helium shutdown puts chip supply chain on a two-week clock

https://www.tomshardware.com/tech-industry/qatar-helium-shutdown-puts-chip-supply-chain-on-a-two-...
381•johnbarron•11h ago•355 comments

OpenTelemetry for Rust Developers

https://signoz.io/blog/opentelemetry-rust/
15•dhruv_ahuja•3d ago•1 comments

Parallels confirms MacBook Neo can run Windows in a virtual machine

https://www.macrumors.com/2026/03/13/macbook-neo-runs-windows-11-vm/
172•tosh•10h ago•228 comments

"Added 1M context window for Opus 4.6 by default for Max, Team, and Enterprise"

https://raw.githubusercontent.com/anthropics/claude-code/refs/heads/main/CHANGELOG.md
8•taspeotis•40m ago•1 comments

Stanford researchers report first recording of a blue whale's heart rate (2019)

https://news.stanford.edu/stories/2019/11/first-ever-recording-blue-whales-heart-rate
46•eatonphil•5h ago•33 comments

New 'negative light' technology hides data transfers in plain sight

https://www.unsw.edu.au/newsroom/news/2026/03/New-negative-light-technology-hides-data-transfers-...
51•wjSgoWPm5bWAhXB•2d ago•33 comments

MetaGenesis Core – offline verification for computational claims

https://www.metagenesis-core.dev/
9•Lama9901•2d ago•3 comments

TUI Studio – visual terminal UI design tool

https://tui.studio/
536•mipselaer•13h ago•271 comments

Elon Musk pushes out more xAI founders as AI coding effort falters

https://www.ft.com/content/e5fbc6c2-d5a6-4b97-a105-6a96ea849de5
276•merksittich•7h ago•397 comments

Using Thunderbird for RSS

https://rubenerd.com/using-thunderbird-for-rss/
58•ingve•3d ago•8 comments

Exploring JEPA for real-time speech translation

https://www.startpinch.com/research/en/jepa-encoder-translation/
21•christiansafka•2d ago•4 comments

Show HN: Context Gateway – Compress agent context before it hits the LLM

https://github.com/Compresr-ai/Context-Gateway
57•ivzak•6h ago•39 comments

Lost Doctor Who Episodes Found

https://www.bbc.co.uk/news/articles/c4g7kwq1k11o
203•edent•19h ago•65 comments

Your phone is an entire computer

https://medhir.com/blog/your-phone-is-an-entire-computer
222•medhir•6h ago•226 comments

Bucketsquatting is finally dead

https://onecloudplease.com/blog/bucketsquatting-is-finally-dead
303•boyter•15h ago•158 comments

I beg you to follow Crocker's Rules, even if you will be rude to me

https://lr0.org/blog/p/crocker/
11•ghd_•1h ago•25 comments

Source code of Swedish e-government services has been leaked

https://darkwebinformer.com/full-source-code-of-swedens-e-government-platform-leaked-from-comprom...
197•tavro•14h ago•188 comments

Launch HN: Spine Swarm (YC S23) – AI agents that collaborate on a visual canvas

https://www.getspine.ai/
83•a24venka•10h ago•65 comments

The Wyden Siren Goes Off Again: We'll Be "Stunned" by NSA Under Section 702

https://www.techdirt.com/2026/03/12/the-wyden-siren-goes-off-again-well-be-stunned-by-what-the-ns...
338•cf100clunk•8h ago•102 comments

John Carmack about open source and anti-AI activists

https://twitter.com/id_aa_carmack/status/2032460578669691171
211•tzury•6h ago•309 comments

Launch HN: Captain (YC W26) – Automated RAG for Files

https://www.runcaptain.com/
44•CMLewis•8h ago•23 comments

Hyperlinks in terminal emulators

https://gist.github.com/egmontkob/eb114294efbcd5adb1944c9f3cb5feda
84•nvahalik•20h ago•57 comments

Meta Platforms: Lobbying, dark money, and the App Store Accountability Act

https://github.com/upper-up/meta-lobbying-and-other-findings
1138•shaicoleman•14h ago•477 comments

Okmain: How to pick an OK main colour of an image

https://dgroshev.com/blog/okmain/
239•dgroshev•4d ago•43 comments