frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•8mo ago

Comments

steele•8mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•8mo ago
Lmao, gentrify cracked me up
neilv•8mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•8mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•8mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•8mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•8mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•8mo ago
May as well just release an executable tbh.
theamk•8mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•8mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•8mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Internet voting is insecure and should not be used in public elections

https://blog.citp.princeton.edu/2026/01/16/internet-voting-is-insecure-and-should-not-be-used-in-...
74•WaitWaitWha•36m ago•42 comments

Significant US Farm Losses Persist, Despite Federal Assistance

https://www.fb.org/market-intel/significant-farm-losses-persist-despite-federal-assistance
33•toomuchtodo•36m ago•16 comments

Take potentially dangerous PDFs, and convert them to safe PDFs

https://github.com/freedomofpress/dangerzone
78•dp-hackernews•2h ago•26 comments

Show HN: ChartGPU – WebGPU-powered charting library (1M points at 60fps)

https://github.com/ChartGPU/ChartGPU
503•huntergemmer•10h ago•146 comments

Claude's new constitution

https://www.anthropic.com/news/claude-new-constitution
310•meetpateltech•9h ago•307 comments

Binary Fuse Filters: Fast and Smaller Than XOR Filters

https://arxiv.org/abs/2201.01174
21•redbell•4d ago•0 comments

Show HN: RatatuiRuby wraps Rust Ratatui as a RubyGem – TUIs with the joy of Ruby

https://www.ratatui-ruby.dev/
70•Kerrick•4d ago•6 comments

Skip is now free and open source

https://skip.dev/blog/skip-is-free/
280•dayanruben•10h ago•123 comments

Golfing APL/K in 90 Lines of Python

https://aljamal.substack.com/p/golfing-aplk-in-90-lines-of-python
49•aburjg•5d ago•9 comments

Letting Claude play text adventures

https://borretti.me/article/letting-claude-play-text-adventures
73•varjag•5d ago•28 comments

Show HN: Rails UI

https://railsui.com/
104•justalever•7h ago•71 comments

Challenges in join optimization

https://www.starrocks.io/blog/inside-starrocks-why-joins-are-faster-than-youd-expect
43•HermitX•8h ago•11 comments

The WebRacket language is a subset of Racket that compiles to WebAssembly

https://github.com/soegaard/webracket
95•mfru•4d ago•20 comments

An explanation of cheating in Doom2 Deathmatch (1999)

https://www.doom2.net/doom2/cheating.html
23•Lammy•4d ago•1 comments

Jerry (YC S17) Is Hiring

https://www.ycombinator.com/companies/jerry-inc/jobs/QaoK3rw-software-engineer-core-automation-ma...
1•linaz•4h ago

TrustTunnel: AdGuard VPN protocol goes open-source

https://adguard-vpn.com/en/blog/adguard-vpn-protocol-goes-open-source-meet-trusttunnel.html
63•kumrayu•8h ago•14 comments

Three types of LLM workloads and how to serve them

https://modal.com/llm-almanac/workloads
41•charles_irl•9h ago•1 comments

Waiting for dawn in search: Search index, Google rulings and impact on Kagi

https://blog.kagi.com/waiting-dawn-search
220•josephwegner•8h ago•143 comments

Mystery of the Head Activator

https://www.asimov.press/p/head-activator
17•mailyk•3d ago•3 comments

Setting Up a Cluster of Tiny PCs for Parallel Computing

https://www.kenkoonwong.com/blog/parallel-computing/
28•speckx•6h ago•17 comments

Stevey's Birthday Blog

https://steve-yegge.medium.com/steveys-birthday-blog-34f437139cb5
30•throwawayHMM19•1d ago•9 comments

SIMD programming in pure Rust

https://kerkour.com/introduction-rust-simd
53•randomint64•2d ago•15 comments

Tell HN: 2 years building a kids audio app as a solo dev – lessons learned

42•oliverjanssen•11h ago•28 comments

Can you slim macOS down?

https://eclecticlight.co/2026/01/21/can-you-slim-macos-down/
174•ingve•18h ago•216 comments

Show HN: TerabyteDeals – Compare storage prices by $/TB

https://terabytedeals.com
69•vektor888•4h ago•53 comments

Nested code fences in Markdown

https://susam.net/nested-code-fences.html
187•todsacerdoti•12h ago•63 comments

Open source server code for the BitCraft MMORPG

https://github.com/clockworklabs/BitCraftPublic
41•sfkgtbor•8h ago•12 comments

Slouching Towards Bethlehem – Joan Didion (1967)

https://www.saturdayeveningpost.com/2017/06/didion/
61•jxmorris12•8h ago•7 comments

Scientists find a way to regrow cartilage in mice and human tissue samples

https://www.sciencedaily.com/releases/2026/01/260120000333.htm
256•saikatsg•7h ago•73 comments

I finally got my sway layout to autostart the way I like it

https://hugues.betakappaphi.com/2026/01/19/sway-layout/
27•__hugues•16h ago•4 comments