frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•6mo ago

Comments

steele•6mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•6mo ago
Lmao, gentrify cracked me up
neilv•6mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•6mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•6mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•6mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•6mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•6mo ago
May as well just release an executable tbh.
theamk•6mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•6mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•6mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

A “frozen” dictionary for Python

https://lwn.net/SubscriberLink/1047238/25c270b077849dc0/
79•jwilk•3h ago•46 comments

Size of Life

https://neal.fun/size-of-life/
2174•eatonphil•21h ago•241 comments

Meta shuts down global accounts linked to abortion advice and queer content

https://www.theguardian.com/global-development/2025/dec/11/meta-shuts-down-global-accounts-linked...
176•ta988•2h ago•99 comments

Show HN: Local Privacy Firewall-blocks PII and secrets before ChatGPT sees them

https://github.com/privacyshield-ai/privacy-firewall
18•arnabkarsarkar•1d ago•1 comments

The Cost of a Closure in C

https://thephd.dev/the-cost-of-a-closure-in-c-c2y
102•ingve•6h ago•33 comments

Getting a Gemini API key is an exercise in frustration

https://ankursethi.com/blog/gemini-api-key-frustration/
617•speckx•17h ago•247 comments

Patterns.dev

https://www.patterns.dev/
362•handfuloflight•12h ago•83 comments

Australia begins enforcing world-first teen social media ban

https://www.reuters.com/legal/litigation/australia-social-media-ban-takes-effect-world-first-2025...
832•chirau•1d ago•1268 comments

Why Startups Die

https://www.techfounderstack.com/p/why-startups-die
54•makle•3d ago•35 comments

Show HN: oeis-tui – A TUI to search OEIS integer sequences in the terminal

https://github.com/hako/oeis-tui
9•wesleyhill•1w ago•0 comments

Helldivers 2 on-disk size 85% reduction

https://store.steampowered.com/news/app/553850/view/491583942944621371
74•SergeAx•1w ago•53 comments

How the Brain Parses Language

https://www.quantamagazine.org/the-polyglot-neuroscientist-resolving-how-the-brain-parses-languag...
47•mylifeandtimes•3d ago•14 comments

Auto-grading decade-old Hacker News discussions with hindsight

https://karpathy.bearblog.dev/auto-grade-hn/
473•__rito__•20h ago•213 comments

Booting Linux in QEMU and Writing PID 1 in Go to Illustrate Kernel as Program

https://serversfor.dev/linux-inside-out/the-linux-kernel-is-just-a-program/
159•birdculture•6d ago•38 comments

South Korea – A Cautionary Tale for the Rest of Humanity

https://worksinprogress.co/issue/two-is-already-too-many/
6•barry-cotter•1h ago•3 comments

How Google Maps allocates survival across London's restaurants

https://laurenleek.substack.com/p/how-google-maps-quietly-allocates
307•justincormack•2d ago•151 comments

Python Workers redux: fast cold starts, packages, and a uv-first workflow

https://blog.cloudflare.com/python-workers-advancements/
77•dom96•2d ago•28 comments

Go's escape analysis and why my function return worked

https://bonniesimon.in/blog/go-escape-analysis
23•bonniesimon•6d ago•11 comments

VCMI: An open-source engine for Heroes III

https://vcmi.eu/
130•eamag•4d ago•15 comments

How can I read the standard output of an already-running process?

https://devblogs.microsoft.com/oldnewthing/20251204-00/?p=111841
4•ibobev•5d ago•0 comments

Rubio stages font coup: Times New Roman ousts Calibri

https://www.reuters.com/world/us/rubio-stages-font-coup-times-new-roman-ousts-calibri-2025-12-09/
317•italophil•1d ago•527 comments

Show HN: Wirebrowser – A JavaScript debugger with breakpoint-driven heap search

https://github.com/fcavallarin/wirebrowser
43•fcavallarin•23h ago•10 comments

Super Mario 64 for the PS1

https://github.com/malucard/sm64-psx
249•LaserDiscMan•18h ago•97 comments

Flow Where You Want – Guidance for Flow Models

https://drscotthawley.github.io/blog/posts/FlowWhereYouWant.html
27•rundigen12•5d ago•1 comments

Qwen3-Omni-Flash-2025-12-01:a next-generation native multimodal large model

https://qwen.ai/blog?id=qwen3-omni-flash-20251201
280•pretext•21h ago•95 comments

Show HN: Automated license plate reader coverage in the USA

https://alpranalysis.com
198•sodality2•19h ago•116 comments

Incomplete list of mistakes in the design of CSS

https://wiki.csswg.org/ideas/mistakes
141•OuterVale•9h ago•93 comments

Fossils reveal anacondas have been giants for over 12 million years

https://www.cam.ac.uk/stories/twelve-million-years-of-giant-anacondas
54•ashishgupta2209•1w ago•24 comments

Scientists create ultra fast memory using light

https://www.isi.edu/news/81186/scientists-create-ultra-fast-memory-using-light/
106•giuliomagnifico•6d ago•24 comments

Common Lisp, ASDF, and Quicklisp: packaging explained

https://cdegroot.com/programming/commonlisp/2025/11/26/cl-ql-asdf.html
92•todsacerdoti•1d ago•24 comments