frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•8mo ago

Comments

steele•8mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•8mo ago
Lmao, gentrify cracked me up
neilv•8mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•8mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•8mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•8mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•8mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•8mo ago
May as well just release an executable tbh.
theamk•8mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•8mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•8mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

ASML firing 1700 people, mostly managers

https://www.ed.nl/binnenland/asml-wil-veel-managementbanen-schrappen-rekent-op-1700-ontslagen~a04...
75•dep_b•1h ago•36 comments

There's only one Woz, but we can all learn from him

https://www.fastcompany.com/91477114/steve-wozniak-woz-apple-the-tech-interactive-humanitarian-award
80•coloneltcb•4d ago•23 comments

Make.ts

https://matklad.github.io/2026/01/27/make-ts.html
27•ingve•1h ago•17 comments

SVG Path Editor

https://yqnn.github.io/svg-path-editor/
56•gurjeet•5d ago•2 comments

Prism

https://openai.com/index/introducing-prism
632•meetpateltech•15h ago•360 comments

A few random notes from Claude coding quite a bit last few weeks

https://twitter.com/karpathy/status/2015883857489522876
596•bigwheels•1d ago•475 comments

Golden Ratio using an equilateral triangle inscribed in a circle

https://geometrycode.com/free/how-to-graphically-derive-the-golden-ratio-using-an-equilateral-tri...
74•peter_d_sherman•4d ago•20 comments

I Stopped Following the News

https://mertbulan.com/2026/01/28/why-i-stopped-following-the-news/
4•mertbio•33m ago•1 comments

430k-year-old well-preserved wooden tools are the oldest ever found

https://www.nytimes.com/2026/01/26/science/archaeology-neanderthals-tools.html
420•bookofjoe•17h ago•217 comments

Rust’s Standard Library on the GPU

https://www.vectorware.com/blog/rust-std-on-gpu/
167•justaboutanyone•4d ago•24 comments

Parametric CAD in Rust

https://campedersen.com/vcad
163•ecto•12h ago•106 comments

Lennart Poettering, Christian Brauner founded a new company

https://amutable.com/about
294•hornedhob•14h ago•417 comments

Doing the thing is doing the thing

https://www.softwaredesign.ing/blog/doing-the-thing-is-doing-the-thing
374•prakhar897•1d ago•123 comments

Xfwl4 – The Roadmap for a Xfce Wayland Compositor

https://alexxcons.github.io/blogpost_15.html
313•pantalaimon•19h ago•237 comments

Time Station Emulator

https://github.com/kangtastic/timestation
164•FriedPickles•12h ago•41 comments

Amazon closing its Fresh and Go stores

https://finance.yahoo.com/news/amazon-closing-fresh-grocery-convenience-150437789.html
232•trenning•17h ago•436 comments

AI2: Open Coding Agents

https://allenai.org/blog/open-coding-agents
180•publicmatt•15h ago•28 comments

Rust at Scale: An Added Layer of Security for WhatsApp

https://engineering.fb.com/2026/01/27/security/rust-at-scale-security-whatsapp/
7•ubj•2h ago•0 comments

Show HN: One Human + One Agent = One Browser From Scratch in 20K LOC

https://emsh.cat/one-human-one-agent-one-browser/
226•embedding-shape•19h ago•109 comments

SoundCloud Data Breach Now on HaveIBeenPwned

https://haveibeenpwned.com/Breach/SoundCloud
177•gnabgib•15h ago•92 comments

FBI is investigating Minnesota Signal chats tracking ICE

https://www.nbcnews.com/tech/internet/fbi-investigating-minnesota-signal-minneapolis-group-ice-pa...
734•duxup•15h ago•955 comments

I found the perfect yearly calendar (for me)

https://blog.notmyhostna.me/posts/i-found-the-perfect-yearly-calendar-for-me
57•dewey•4d ago•17 comments

Bridging the Gap Between PLECS and SPICE

https://erickschulz.dev/posts/plecs-spice/
36•eschu•2d ago•15 comments

AISLE’s autonomous analyzer found all CVEs in the January OpenSSL release

https://aisle.com/blog/aisle-discovered-12-out-of-12-openssl-vulnerabilities
154•mmsc•7h ago•109 comments

Notes on starting to use Django

https://jvns.ca/blog/2026/01/27/some-notes-on-starting-to-use-django/
76•ingve•10h ago•32 comments

Try text scaling support in Chrome Canary

https://www.joshtumath.uk/posts/2026-01-27-try-text-scaling-support-in-chrome-canary/
99•linolevan•13h ago•33 comments

Extremophile molds are invading art museums

https://www.scientificamerican.com/article/how-extremophile-molds-are-destroying-museum-artifacts/
93•sohkamyung•4d ago•47 comments

Show HN: LemonSlice – Upgrade your voice agents to real-time video

89•lcolucci•15h ago•96 comments

The Texas Instruments CC-40 invades Gopherspace (plus TI-74 BASICALC)

http://oldvcr.blogspot.com/2025/12/the-texas-instruments-cc-40-invades.html
18•PaulHoule•5d ago•1 comments

Show HN: Fuzzy Studio – Apply live effects to videos/camera

https://fuzzy.ulyssepence.com/
37•ulyssepence•17h ago•10 comments