frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•11mo ago

Comments

steele•10mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•10mo ago
Lmao, gentrify cracked me up
neilv•10mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•10mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•10mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•10mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•10mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•10mo ago
May as well just release an executable tbh.
theamk•10mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•10mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•10mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

All elementary functions from a single binary operator

https://arxiv.org/abs/2603.21852
393•pizza•8h ago•109 comments

The Economics of Software Teams: Why Most Engineering Orgs Are Flying Blind

https://www.viktorcessan.com/the-economics-of-software-teams/
139•kiyanwang•4h ago•67 comments

Taking on CUDA with ROCm: 'One Step After Another'

https://www.eetimes.com/taking-on-cuda-with-rocm-one-step-after-another/
169•mindcrime•11h ago•127 comments

DIY Soft Drinks

https://blinry.org/diy-soft-drinks/
448•_Microft•17h ago•128 comments

Bring Back Idiomatic Design (2023)

https://essays.johnloeber.com/p/4-bring-back-idiomatic-design
559•phil294•21h ago•320 comments

Show HN: boringBar – a taskbar-style dock replacement for macOS

https://boringbar.app/
370•a-ve•16h ago•206 comments

Optimization of 32-bit Unsigned Division by Constants on 64-bit Targets

https://arxiv.org/abs/2604.07902
78•mpweiher•1d ago•9 comments

A perfectable programming language

https://alok.github.io/lean-pages/perfectable-lean/
129•yuppiemephisto•12h ago•44 comments

Most people can't juggle one ball

https://www.lesswrong.com/posts/jTGbKKGqs5EdyYoRc/most-people-can-t-juggle-one-ball
359•surprisetalk•3d ago•119 comments

Ask HN: What Are You Working On? (April 2026)

223•david927•17h ago•704 comments

I gave every train in New York an instrument

https://www.trainjazz.com/
282•joshuawolk•2d ago•52 comments

Show HN: Oberon System 3 runs natively on Raspberry Pi 3 (with ready SD card)

https://github.com/rochus-keller/OberonSystem3Native/releases
196•Rochus•20h ago•48 comments

Is math big or small?

https://chessapig.github.io/talks/Big-Small
43•robinhouston•1d ago•13 comments

Tell HN: Docker pull fails in Spain due to football Cloudflare block

906•littlecranky67•21h ago•335 comments

We have a 99% email reputation, but Gmail disagrees

https://blogfontawesome.wpcomstaging.com/we-have-a-99-email-reputation-gmail-disagrees/
261•em-bee•21h ago•232 comments

Apple's accidental moat: How the "AI Loser" may end up winning

https://adlrocha.substack.com/p/adlrocha-how-the-ai-loser-may-end
186•walterbell•7h ago•188 comments

Exploiting the most prominent AI agent benchmarks

https://rdi.berkeley.edu/blog/trustworthy-benchmarks-cont/
525•Anon84•1d ago•132 comments

A Canonical Generalization of OBDD

https://arxiv.org/abs/2604.05537
14•luu•5h ago•6 comments

JVM Options Explorer

https://chriswhocodes.com/vm-options-explorer.html
195•0x54MUR41•23h ago•86 comments

How long-distance couples use digital games to facilitate intimacy (2025)

https://arxiv.org/abs/2505.09509
99•radeeyate•17h ago•31 comments

Seven countries now generate nearly all their electricity from renewables (2024)

https://www.the-independent.com/tech/renewable-energy-solar-nepal-bhutan-iceland-b2533699.html
581•mpweiher•20h ago•348 comments

Google removes "Doki Doki Literature Club" from Google Play

https://bsky.app/profile/serenityforge.com/post/3mj3r4nbiws2t
454•super256•14h ago•229 comments

Caffeine, cocaine, and painkillers detected in sharks from The Bahamas

https://www.sciencedirect.com/science/article/abs/pii/S0269749126001880
13•LostMyLogin•1h ago•3 comments

Phyphox – Physical Experiments Using a Smartphone

https://phyphox.org/
217•_Microft•1d ago•34 comments

Opus 4.6 hallucinates twice as more today than when it released

https://www.bridgebench.ai/hallucination
12•jiwidi•1h ago•3 comments

Pro Max 5x quota exhausted in 1.5 hours despite moderate usage

https://github.com/anthropics/claude-code/issues/45756
642•cmaster11•20h ago•570 comments

Haunt, the 70s text adventure game, is now playable on a website

https://haunt.madebywindmill.com
57•jscalo•6h ago•19 comments

I ran Gemma 4 as a local model in Codex CLI

https://blog.danielvaughan.com/i-ran-gemma-4-as-a-local-model-in-codex-cli-7fda754dc0d4
66•dvaughan•13h ago•24 comments

The peril of laziness lost

https://bcantrill.dtrace.org/2026/04/12/the-peril-of-laziness-lost/
392•gpm•14h ago•130 comments

A Tour of Oodi

https://blinry.org/oodi/
142•zdw•3d ago•42 comments