frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•1y ago

Comments

steele•1y ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•1y ago
Lmao, gentrify cracked me up
neilv•1y ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•1y ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•1y ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•1y ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•1y ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•1y ago
May as well just release an executable tbh.
theamk•1y ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•1y ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•1y ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Deno Desktop

https://docs.deno.com/runtime/desktop/
82•GeneralMaximus•1h ago•22 comments

Help I accidentally a wigglegram

https://lmao.center/blog/wiggle-accidents/
125•gregsadetsky•2d ago•21 comments

Did my old job only exist because of fraud?

https://david.newgas.net/did-my-old-job-only-exist-because-of-fraud/
443•advisedwang•9h ago•200 comments

Apertus – Open Foundation Model for Sovereign AI

https://apertvs.ai/
321•T-A•9h ago•111 comments

Danish privacy activist Lars Andersen raided by police

https://twitter.com/LarsAnders1620/status/2068208864747540516#m
132•I_am_tiberius•1h ago•75 comments

There is minimal downside to switching to open models

https://www.marble.onl/posts/cancel_claude.html
163•amarble•9h ago•116 comments

Memory Safe Inline Assembly

https://fil-c.org/inlineasm
82•pizlonator•2d ago•15 comments

Sakana Fugu

https://sakana.ai/fugu/
92•Finbarr•4h ago•50 comments

Good results fine tuning a local LLM like Qwen 3:0.6B to categorize questions

https://www.teachmecoolstuff.com/viewarticle/fine-tuning-a-local-llm-to-categorize-questions
98•dev-experiments•7h ago•19 comments

Everything is logarithms

https://alexkritchevsky.com/2026/05/25/everything-is-logarithms.html
185•E-Reverance•9h ago•41 comments

How I play video games with spinal muscular atrophy

https://www.openassistivetech.org/how-i-actually-play-video-games-with-sma-the-tools-i-use-every-...
93•dannyobrien•3d ago•14 comments

Identity verification on Claude

https://support.claude.com/en/articles/14328960-identity-verification-on-claude
688•bathory•18h ago•580 comments

1983 Northern Telecom Commodore Phone

https://www.oldtelephoneroom.ca/1983-northern-telecom-commodore-phone/
44•arexxbifs•6h ago•12 comments

JSON-LD explained for personal websites

https://hawksley.dev/blog/json-ld-explained-for-personal-websites/
194•ethanhawksley•11h ago•57 comments

Japanese verb conjugation the simple hard way

https://underreacted.leaflet.pub/3mmevu6woys27
76•valzevul•7h ago•92 comments

Beyond All Reason (Free Total Annihilation Inspired RTS)

https://www.beyondallreason.info
467•mosiuerbarso•19h ago•275 comments

PowerFox Browser

https://powerfox.jazzzny.me/
113•thisislife2•9h ago•31 comments

Lisp in the Rust Type System

https://github.com/playX18/lisp-in-types/
35•quasigloam•2d ago•0 comments

Minecraft: Java Edition 26.2, the first version with Vulkan 1.2

https://www.minecraft.net/en-us/article/minecraft-java-edition-26-2
118•ObviouslyFlamer•4d ago•35 comments

Show HN: Teach your kids perfect pitch

https://github.com/paytonjjones/bsharp
109•paytonjjones•17h ago•63 comments

Efficient C++ Programming for Modern C++ CPUs, Chapter 4/part 2

https://6it.dev/blog/infographics-operation-costs-in-cpu-clock-cycles-take-2-80736
35•birdculture•2d ago•3 comments

Prefer duplication over the wrong abstraction (2016)

https://sandimetz.com/blog/2016/1/20/the-wrong-abstraction
460•rafaepta•14h ago•310 comments

Rent collections are down in New York

https://www.politico.com/news/2026/06/21/rent-collections-are-down-in-new-york-and-no-ones-sure-w...
69•JumpCrisscross•8h ago•254 comments

Shape Suffixes – Good Coding Style

https://medium.com/@NoamShazeer/shape-suffixes-good-coding-style-f836e72e24fd
11•sebg•3d ago•0 comments

Show HN: Criterion Closet as a website – pull any of 1,247 films off the shelf

https://the-criterion-closet.vercel.app
84•olievans•1d ago•16 comments

The minimum viable unit of saleable software

https://brandur.org/minimum-viable-unit
150•brandur•14h ago•56 comments

Show HN: Recall – Local project memory for Claude Code

https://github.com/raiyanyahya/recall
99•mateenah•9h ago•65 comments

Architecting a Conversion Engine in Swift

https://blog.minimal.app/conversion-engine/
22•arthurofbabylon•4d ago•4 comments

FDA advisors unanimously vote to approve Moderna's mRNA after agency drama

https://arstechnica.com/health/2026/06/fda-advisors-unanimously-vote-to-approve-modernas-mrna-aft...
170•worik•9h ago•86 comments

(How to Write a (Lisp) Interpreter (In Python)) (2010)

https://norvig.com/lispy.html
180•tosh•15h ago•60 comments