frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Avoid UUIDv4 Primary Keys

https://andyatkinson.com/avoid-uuid-version-4-primary-keys
46•pil0u•1h ago•37 comments

Adafruit: Arduino’s Rules Are ‘Incompatible With Open Source’

https://thenewstack.io/adafruit-arduinos-rules-are-incompatible-with-open-source/
222•MilnerRoute•17h ago•115 comments

Unscii

http://viznut.fi/unscii/
126•Levitating•7h ago•6 comments

Arborium: Tree-sitter code highlighting with Native and WASM targets

https://arborium.bearcove.eu/
120•zdw•7h ago•20 comments

Roomba maker goes bankrupt, Chinese owner emerges

https://news.bloomberglaw.com/bankruptcy-law/robot-vacuum-roomba-maker-files-for-bankruptcy-after...
202•nreece•10h ago•203 comments

Ask HN: What Are You Working On? (December 2025)

291•david927•18h ago•929 comments

$5 whale listening hydrophone making workshop

https://exclav.es/2025/08/03/dinacon-2025-passive-acoustic-listening/
38•gsf_emergency_6•4d ago•12 comments

The Whole App is a Blob

https://drobinin.com/posts/the-whole-app-is-a-blob/
91•valzevul•7h ago•37 comments

John Varley has died

http://floggingbabel.blogspot.com/2025/12/john-varley-1947-2025.html
81•decimalenough•8h ago•34 comments

If AI replaces workers, should it also pay taxes?

https://english.elpais.com/technology/2025-11-30/if-ai-replaces-workers-should-it-also-pay-taxes....
143•PaulHoule•11h ago•227 comments

Common Rust Lifetime Misconceptions

https://github.com/pretzelhammer/rust-blog/blob/master/posts/common-rust-lifetime-misconceptions.md
45•CafeRacer•5h ago•7 comments

The Problem of Teaching Physics in Latin America (1963)

https://calteches.library.caltech.edu/46/2/LatinAmerica.htm
50•rramadass•14h ago•34 comments

Show HN: I wrote a book – Debugging TypeScript Applications (in beta)

https://pragprog.com/titles/aodjs/debugging-typescript-applications/
18•ozornin•6d ago•9 comments

Rob Reiner has died

https://www.hollywoodreporter.com/movies/movie-news/rob-reiner-dead-harry-met-sally-princess-brid...
105•RickJWagner•7h ago•42 comments

Running on Empty: Copper

https://thehonestsorcerer.substack.com/p/running-on-empty-copper
65•the-needful•6d ago•48 comments

Hashcards: A plain-text spaced repetition system

https://borretti.me/article/hashcards-plain-text-spaced-repetition
333•thomascountz•18h ago•149 comments

JSDoc is TypeScript

https://culi.bearblog.dev/jsdoc-is-typescript/
174•culi•15h ago•200 comments

CapROS: Capability-Based Reliable Operating System

https://www.capros.org/
85•gjvc•10h ago•33 comments

A trip through the Graphics Pipeline (2011)

https://fgiesen.wordpress.com/2011/07/09/a-trip-through-the-graphics-pipeline-2011-index/
12•kruuuder•4d ago•2 comments

AI agents are starting to eat SaaS

https://martinalderson.com/posts/ai-agents-are-starting-to-eat-saas/
143•jnord•11h ago•168 comments

The History of Xerox

https://www.abortretry.fail/p/the-history-of-xerox
25•rbanffy•3d ago•2 comments

Read Something Wonderful

https://readsomethingwonderful.com/
118•snorbleck•7h ago•19 comments

The Java Ring: A Wearable Computer (1998)

https://www.nngroup.com/articles/javaring-wearable-computer/
4•cromulent•4d ago•0 comments

Rio de Janeiro's talipot palm trees bloom for the first and only time

https://apnews.com/article/brazil-rio-talipot-palm-flamengo-park-dcfb1ce237af7a10ab72205fc9bbdc02
162•1659447091•1w ago•39 comments

Elevated errors across many models

https://status.claude.com/incidents/9g6qpr72ttbr
302•pablo24602•13h ago•141 comments

In the Beginning was the Command Line (1999)

https://web.stanford.edu/class/cs81n/command.txt
157•wseqyrku•1w ago•72 comments

An attempt to articulate Forth's practical strengths and eternal usefulness

https://im-just-lee.ing/forth-why-cb234c03.txt
68•todsacerdoti•1w ago•34 comments

Price of a bot army revealed across online platforms

https://www.cam.ac.uk/stories/price-bot-army-global-index
150•teleforce•19h ago•69 comments

Shai-Hulud compromised a dev machine and raided GitHub org access: a post-mortem

https://trigger.dev/blog/shai-hulud-postmortem
235•nkko•1d ago•147 comments

How well do you know C++ auto type deduction?

https://www.volatileint.dev/posts/auto-type-deduction-gauntlet/
60•volatileint•5d ago•47 comments
Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•7mo ago

Comments

steele•7mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•7mo ago
Lmao, gentrify cracked me up
neilv•7mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•7mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•6mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•7mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•7mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•7mo ago
May as well just release an executable tbh.
theamk•7mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•7mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•6mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."