frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•9mo ago

Comments

steele•9mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•9mo ago
Lmao, gentrify cracked me up
neilv•9mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•9mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•9mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•9mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•9mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•9mo ago
May as well just release an executable tbh.
theamk•9mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•9mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•9mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Meta’s AI smart glasses and data privacy concerns

https://www.svd.se/a/K8nrV4/metas-ai-smart-glasses-and-data-privacy-concerns-workers-say-we-see-e...
965•sandbach•9h ago•548 comments

British Columbia is permanently adopting daylight time

https://www.cbc.ca/news/canada/british-columbia/b-c-adopting-year-round-daylight-time-9.7111657
726•ireflect•11h ago•362 comments

Ars Technica fires reporter after AI controversy involving fabricated quotes

https://futurism.com/artificial-intelligence/ars-technica-fires-reporter-ai-quotes
205•danso•6h ago•127 comments

Daily Driving GrapheneOS

https://blog.matthewbrunelle.com/8-4-months-of-daily-driving-grapheneos/
59•zdw•2h ago•26 comments

Simple screw counter

https://mitxela.com/projects/screwcounter
87•jk_tech•2d ago•19 comments

Buckle Up for Bumpier Skies

https://www.newyorker.com/magazine/2026/03/09/buckle-up-for-bumpier-skies
16•littlexsparkee•1h ago•3 comments

Intent-Based Commits

https://github.com/adamveld12/ghost
34•adamveld12•3h ago•21 comments

Show HN: I built a sub-500ms latency voice agent from scratch

https://www.ntik.me/posts/voice-agent
342•nicktikhonov•10h ago•101 comments

Moldova broke our data pipeline

https://www.avraam.dev/blog/moldova-broke-our-pipeline
34•almonerthis•2d ago•23 comments

Physicists developing a quantum computer that’s entirely open source

https://physics.aps.org/articles/v19/24
90•tzury•8h ago•20 comments

First in-utero stem cell therapy for fetal spina bifida repair is safe: study

https://health.ucdavis.edu/news/headlines/first-ever-in-utero-stem-cell-therapy-for-fetal-spina-b...
292•gmays•16h ago•51 comments

New iPad Air, powered by M4

https://www.apple.com/newsroom/2026/03/apple-introduces-the-new-ipad-air-powered-by-m4/
371•Garbage•17h ago•597 comments

Guilty Displeasures

https://www.hopefulmons.com/p/what-are-your-guilty-displeasures
55•aregue•1d ago•61 comments

Seed of Might Color Correction Process (2023) [pdf]

https://andrewvanner.github.io/som/SoM_CC_Process_Day.pdf
84•haunter•8h ago•20 comments

The Excommunicated Devs Making Games with AI

https://www.tyleo.com/blog/the-excommunicated-devs-making-games-with-ai
44•tyleo•5h ago•28 comments

Launch HN: OctaPulse (YC W26) – Robotics and computer vision for fish farming

97•rohxnsxngh•15h ago•33 comments

Elevated Errors in Claude.ai

https://status.claude.com/incidents/yf48hzysrvl5
88•LostMyLogin•4h ago•66 comments

Guido van Rossum Interviews Thomas Wouters (Python Core Dev)

https://gvanrossum.github.io/interviews/Thomas.html
15•azhenley•1d ago•1 comments

Motorola announces a partnership with GrapheneOS

https://motorolanews.com/motorola-three-new-b2b-solutions-at-mwc-2026/
2165•km•1d ago•785 comments

I built an RGB controller with Arduino

https://svana.name/2026/02/i-built-an-rgb-controller-with-arduino/
4•msvana•2d ago•0 comments

iPhone 17e

https://www.apple.com/newsroom/2026/03/apple-introduces-iphone-17e/
257•meetpateltech•17h ago•360 comments

Show HN: Govbase – Follow a bill from source text to news bias to social posts

https://govbase.com
187•foxfoxx•14h ago•74 comments

The Cathode Ray Tube site

https://www.crtsite.com/didactic-crt.html
37•joebig•1d ago•2 comments

Against Query Based Compilers

https://matklad.github.io/2026/02/25/against-query-based-compilers.html
58•surprisetalk•1d ago•33 comments

Inside the M4 Apple Neural Engine, Part 1: Reverse Engineering

https://maderix.substack.com/p/inside-the-m4-apple-neural-engine
319•zdw•1d ago•91 comments

The 185-Microsecond Type Hint

https://blog.sturdystatistics.com/posts/type_hint/
66•kianN•9h ago•8 comments

DOS Memory Management

https://www.os2museum.com/wp/dos-memory-management/
21•ingve•2d ago•0 comments

RCade: Building a Community Arcade Cabinet

https://www.frankchiarulli.com/blog/building-the-rcade/
76•evakhoury•4d ago•14 comments

Ask HN: Who is hiring? (March 2026)

202•whoishiring•15h ago•237 comments

Programmable Cryptography (2024)

https://0xparc.org/writings/programmable-cryptography-1
65•fi-le•2d ago•36 comments