frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•1y ago

Comments

steele•1y ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•1y ago
Lmao, gentrify cracked me up
neilv•1y ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•1y ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•12mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•1y ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•1y ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•1y ago
May as well just release an executable tbh.
theamk•1y ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•1y ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•12mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Gaussian Splat of a Strawberry

https://superspl.at/scene/84df8849
22•danybittel•36m ago•13 comments

I Found Ultra-Pure Quantum Crystals in an Abandoned Mine in the Atacama Desert

https://medium.com/@breid.at/ultra-pure-quantum-crystals-from-an-abandoned-mine-in-a-mysterious-d...
82•vi_sextus_vi•2d ago•18 comments

Polypad

https://polypad.amplify.com/
84•ivank•2d ago•7 comments

Peter Neumann has died

https://www.tuhs.org/pipermail/tuhs/2026-May/033748.html
138•pabs3•7h ago•8 comments

Click (2016)

https://clickclickclick.click/
312•andrewzeno•12h ago•76 comments

The last six months in LLMs in five minutes

https://simonwillison.net/2026/May/19/5-minute-llms/
479•yakkomajuri•9h ago•350 comments

Kv4p HT – A homebrew 1W radio (VHF or UHF) that plugs into an Android phone

https://www.kv4p.com/
98•krupan•2d ago•33 comments

The lasting influence of Netscape Time

https://thehistoryoftheweb.com/the-lasting-influence-of-netscape-time/
38•zdw•2d ago•8 comments

Cursor Introduces Composer 2.5

https://cursor.com/blog/composer-2-5
160•asar•17h ago•116 comments

Anthropic acquires Stainless

https://www.anthropic.com/news/anthropic-acquires-stainless
458•tomeraberbach•18h ago•325 comments

PyTorch Landscape

https://pytorch.landscape2.io
47•salamo•6h ago•10 comments

1024000^2 Blocks, 2B2T Minecraft Server World Download Project, and Discoveries

https://github.com/2b2tplace/1m_release
146•exploraz•21h ago•91 comments

Regex Chess: A 2-ply minimax chess engine in 84,688 regular expressions

https://nicholas.carlini.com/writing/2025/regex-chess.html
129•surprisetalk•4d ago•28 comments

Pope Leo XIV’s first encyclical Magnifica humanitas to be published May 25

https://www.vaticannews.va/en/pope/news/2026-05/pope-leo-xiv-first-encyclical-magnifica-humanitas...
236•cucho•11h ago•155 comments

We let AIs run radio stations

https://andonlabs.com/blog/andon-fm
273•lukaspetersson•17h ago•216 comments

Hyperpolyglot Lisp: Common Lisp, Racket, Clojure, Emacs Lisp

https://hyperpolyglot.org/lisp
162•veqq•15h ago•39 comments

Show HN: Hsrs – Type-Safe Haskell Bindings Generator for Rust

https://github.com/harmont-dev/hsrs
36•suis_siva•7h ago•2 comments

Show HN: Number Gacha, a gacha game distilled to its essence

https://isabisabel.com/gacha/
161•babel16•5d ago•66 comments

When can the C++ compiler devirtualize a call?

https://quuxplusone.github.io/blog/2021/02/15/devirtualization/
67•lionkor•2d ago•45 comments

Make ZIP files smaller with ZIP Shrinker

https://evanhahn.com/make-zip-files-smaller-with-zip-shrinker/
29•zdw•2d ago•15 comments

Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/
116•theanonymousone•6h ago•61 comments

AI eats the world (Spring 26) [pdf]

https://static1.squarespace.com/static/50363cf324ac8e905e7df861/t/6a0af5d0484fbf5fe9a7743e/177910...
240•topherjaynes•22h ago•134 comments

Peter Salus has died

https://www.tuhs.org/pipermail/tuhs/2026-May/033750.html
142•speckx•8h ago•12 comments

Two computers, one monitor, zero fiddling (2025)

https://alexplescan.com/posts/2025/08/16/kvm/
226•ankitg12•3d ago•132 comments

Elon Musk has lost his lawsuit against Sam Altman and OpenAI

https://techcrunch.com/2026/05/18/elon-musk-has-lost-his-lawsuit-against-sam-altman-and-openai/
971•nycdatasci•17h ago•485 comments

Energy return in running shoes explained (2025)

https://runrepeat.com/guides/energy-return-in-running-shoes
9•jstrieb•1d ago•4 comments

Alignment pretraining: AI discourse creates self-fulfilling (mis)alignment

https://arxiv.org/abs/2601.10160
58•anigbrowl•13h ago•24 comments

Agora-1: The Multi-Agent World Model

https://odyssey.ml/introducing-agora-1
113•olivercameron•16h ago•22 comments

Why is it called Kent House?

https://diamondgeezer.blogspot.com/2026/05/kent-house.html
35•susam•3d ago•7 comments

Show HN: Files.md – Open-source alternative to Obsidian

https://github.com/zakirullin/files.md
642•zakirullin•21h ago•312 comments