frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•9mo ago

Comments

steele•9mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•9mo ago
Lmao, gentrify cracked me up
neilv•9mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•9mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•9mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•9mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•9mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•9mo ago
May as well just release an executable tbh.
theamk•9mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•9mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•9mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

I Fixed Windows Native Development

https://marler8997.github.io/blog/fixed-windows/
381•deevus•6h ago•203 comments

LT6502: A 6502-based homebrew laptop

https://github.com/TechPaula/LT6502
12•classichasclass•20m ago•0 comments

EU bans the destruction of unsold apparel, clothing, accessories and footwear

https://environment.ec.europa.eu/news/new-eu-rules-stop-destruction-unsold-clothes-and-shoes-2026...
59•giuliomagnifico•22m ago•29 comments

Hideki Sato, designer of all Sega's consoles, has died

https://www.videogameschronicle.com/news/hideki-sato-designer-of-segas-consoles-dies-age-75/
76•magoghm•1h ago•1 comments

I love the work of the ArchWiki maintainers

https://k7r.eu/i-love-the-work-of-the-archwiki-maintainers/
763•panic•16h ago•127 comments

An Enslaved Gardener Transformed the Pecan into a Cash Crop

https://lithub.com/how-an-enslaved-gardener-transformed-the-pecan-into-a-cash-crop/
31•PaulHoule•1h ago•22 comments

Flashpoint Archive – Over 200k web games and animations preserved

https://flashpointarchive.org
255•helloplanets•11h ago•57 comments

Reversed engineered game Starflight (1986)

https://github.com/s-macke/starflight-reverse
57•tosh•5h ago•31 comments

Gwtar: A static efficient single-file HTML format

https://gwern.net/gwtar
8•theblazehen•1h ago•0 comments

Oat – Ultra-lightweight, semantic, zero-dependency HTML UI component library

https://oat.ink/
284•twapi•9h ago•81 comments

Amazon, Google Unwittingly Reveal the Severity of the U.S. Surveillance State

https://greenwald.substack.com/p/amazons-ring-and-googles-nest-unwittingly
388•mikece•4h ago•258 comments

How Is Data Stored?

https://www.makingsoftware.com/chapters/how-is-data-stored
59•tzury•5d ago•3 comments

RynnBrain

https://github.com/alibaba-damo-academy/RynnBrain
39•jsemrau•4d ago•1 comments

My smart sleep mask broadcasts users' brainwaves to an open MQTT broker

https://aimilios.bearblog.dev/reverse-engineering-sleep-mask/
547•minimalthinker•1d ago•233 comments

Two different tricks for fast LLM inference

https://www.seangoedecke.com/fast-llm-inference/
119•swah•8h ago•52 comments

The seam through the center of things

https://usefulfictions.substack.com/p/the-seam-through-the-center-of-things
12•surprisetalk•2d ago•0 comments

A practical guide to observing the night sky for real skies and real equipment

https://stargazingbuddy.com/
96•constantinum•3d ago•16 comments

Constraint Propagation for Fun

https://eli.li/constraint-propagation-for-fun
32•rickcarlino•5d ago•0 comments

Zvec: A lightweight, fast, in-process vector database

https://github.com/alibaba/zvec
196•dvrp•2d ago•35 comments

Interference Pattern Formed in a Finger Gap Is Not Single Slit Diffraction

https://note.com/hydraenids/n/nbe89030deaba
79•uolmir•2d ago•10 comments

Build Gaussian Splat Experiences with SuperSplat Studio

https://blog.playcanvas.com/build-gaussian-splat-experiences-with-supersplat-studio/
12•ovenchips•4d ago•1 comments

Inner-Platform Effect

https://en.wikipedia.org/wiki/Inner-platform_effect
25•tosh•2h ago•4 comments

Instagram's URL Blackhole

https://medium.com/@shredlife/instagrams-url-blackhole-c1733e081664
274•tkp-415•2d ago•44 comments

DjVu and its connection to Deep Learning (2023)

https://scottlocklin.wordpress.com/2023/05/31/djvu-and-its-connection-to-deep-learning/
43•tosh•8h ago•7 comments

uBlock filter list to hide all YouTube Shorts

https://github.com/i5heu/ublock-hide-yt-shorts/
1049•i5heu•23h ago•311 comments

Show HN: Copy-and-patch compiler for hard real-time Python

https://github.com/Nonannet/copapy
45•Saloc•4d ago•2 comments

5,300-year-old 'bow drill' rewrites story of ancient Egyptian tools

https://www.ncl.ac.uk/press/articles/latest/2026/02/ancientegyptiandrillbit/
148•geox•4d ago•61 comments

Guitars of the USSR and the Jolana Special in Azerbaijani Music (2012)

https://caucascapades.wordpress.com/2012/06/14/guitars-of-the-ussr-and-the-jolana-special-in-azer...
83•bpierre•14h ago•12 comments

Amsterdam Compiler Kit

https://github.com/davidgiven/ack
151•andsoitis•1d ago•57 comments

OpenAI should build Slack

https://www.latent.space/p/ainews-why-openai-should-build-slack
228•swyx•1d ago•278 comments