frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•1y ago

Comments

steele•1y ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•1y ago
Lmao, gentrify cracked me up
neilv•1y ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•1y ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•1y ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•1y ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•1y ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•1y ago
May as well just release an executable tbh.
theamk•1y ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•1y ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•1y ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Deno Desktop

https://docs.deno.com/runtime/desktop/
638•GeneralMaximus•7h ago•233 comments

GLM 5.2 vs. Opus

https://techstackups.com/comparisons/glm-5.2-vs-opus/
224•ritzaco•5h ago•172 comments

Codex logging bug may write TBs to local SSDs

https://github.com/openai/codex/issues/28224
209•vantareed•5h ago•109 comments

Help I accidentally a wigglegram

https://lmao.center/blog/wiggle-accidents/
349•gregsadetsky•2d ago•74 comments

Did my old job only exist because of fraud?

https://david.newgas.net/did-my-old-job-only-exist-because-of-fraud/
665•advisedwang•15h ago•287 comments

Munich 1991: The Roots of the Current AI Boom

https://people.idsia.ch/~juergen/ai-boom-roots-munich-1991.html
128•tosh•2d ago•48 comments

Apertus – Open Foundation Model for Sovereign AI

https://apertvs.ai/
451•T-A•15h ago•150 comments

Investors get real-time view of UK bond market activity for the first time

https://www.fca.org.uk/news/press-releases/investors-get-real-time-view-uk-bond-market-activity-f...
59•monkeydust•5h ago•23 comments

window.showDirectoryPicker opens up a whole new world

https://steveharrison.dev/showdirectorypicker-opens-up-a-whole-new-world/
3•steveharrison•35m ago•1 comments

Manticore Search 27.1.5: Auth, sharding, conversational and faster vector search

https://manticoresearch.com/blog/manticore-search-27-1-5/
16•snikolaev•2h ago•0 comments

There is minimal downside to switching to open models

https://www.marble.onl/posts/cancel_claude.html
286•amarble•16h ago•236 comments

Sakana Fugu

https://sakana.ai/fugu/
149•Finbarr•11h ago•92 comments

Writing Postcards with a 3D Printer

https://severinbucher.com/posts/writing-postcards-with-a-3d-printer/
32•typesafeJ•3d ago•15 comments

My 1992 view of the problems of computer programming in 1992

https://blog.plover.com/prog/fortran-i.html
51•speckx•2d ago•12 comments

Memory Safe Inline Assembly

https://fil-c.org/inlineasm
133•pizlonator•2d ago•30 comments

Everything is logarithms

https://alexkritchevsky.com/2026/05/25/everything-is-logarithms.html
250•E-Reverance•16h ago•52 comments

Identity verification on Claude

https://support.claude.com/en/articles/14328960-identity-verification-on-claude
809•bathory•1d ago•679 comments

Good results fine tuning a local LLM like Qwen 3:0.6B to categorize questions

https://www.teachmecoolstuff.com/viewarticle/fine-tuning-a-local-llm-to-categorize-questions
166•dev-experiments•14h ago•32 comments

Lisp in the Rust Type System

https://github.com/playX18/lisp-in-types/
83•quasigloam•2d ago•4 comments

Danish privacy activist Lars Andersen raided by police

https://twitter.com/LarsAnders1620/status/2068208864747540516#m
311•I_am_tiberius•8h ago•263 comments

JSON-LD explained for personal websites

https://hawksley.dev/blog/json-ld-explained-for-personal-websites/
239•ethanhawksley•18h ago•75 comments

UTFS: A Tar-Like File System for Embedded Systems (2025)

https://clisystems.com/article-UTFS-intro/
12•zdw•4d ago•6 comments

Japanese verb conjugation the simple hard way

https://underreacted.leaflet.pub/3mmevu6woys27
123•valzevul•14h ago•184 comments

Show HN: Teach your kids perfect pitch

https://github.com/paytonjjones/bsharp
165•paytonjjones•1d ago•110 comments

How I play video games with spinal muscular atrophy

https://www.openassistivetech.org/how-i-actually-play-video-games-with-sma-the-tools-i-use-every-...
133•dannyobrien•3d ago•17 comments

Efficient C++ Programming for Modern 64-bit CPUs: Chapter 4/part 2

https://6it.dev/blog/infographics-operation-costs-in-cpu-clock-cycles-take-2-80736
76•birdculture•2d ago•17 comments

Minecraft: Java Edition 26.2, the first version with Vulkan 1.2

https://www.minecraft.net/en-us/article/minecraft-java-edition-26-2
171•ObviouslyFlamer•5d ago•72 comments

Why Drawing Tablet Brands Won't Collaborate on Linux Floss Drivers

https://www.davidrevoy.com/article1154/why-drawing-tablet-brands-wont-collaborate-on-linux-floss-...
12•Tomte•1h ago•0 comments

PowerFox Browser

https://powerfox.jazzzny.me/
151•thisislife2•15h ago•42 comments

Show HN: Criterion Closet as a website – pull any of 1,247 films off the shelf

https://the-criterion-closet.vercel.app
145•olievans•1d ago•45 comments