frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Fran Sans – font inspired by San Francisco light rail displays

https://emilysneddon.com/fran-sans-essay
532•ChrisArchitect•6h ago•75 comments

Native Secure Enclave backed SSH keys on macOS

https://gist.github.com/arianvp/5f59f1783e3eaf1a2d4cd8e952bb4acf
299•arianvanp•7h ago•126 comments

Show HN: I wrote a minimal memory allocator in C

https://github.com/t9nzin/memory
30•t9nzin•2h ago•2 comments

Calculus for Mathematicians, Computer Scientists, and Physicists [pdf]

https://mathcs.holycross.edu/~ahwang/print/calc.pdf
222•o4c•8h ago•46 comments

A desktop app for isolated, parallel agentic development

https://github.com/coder/mux
26•mercat•2h ago•7 comments

µcad: New open source programming language that can generate 2D sketches and 3D

https://microcad.xyz/
49•todsacerdoti•4h ago•10 comments

Show HN: Gitlogue – A terminal tool that replays your Git commits with animation

https://github.com/unhappychoice/gitlogue
91•unhappychoice•5d ago•11 comments

Sunsetting Supermaven

https://supermaven.com/blog/sunsetting-supermaven
26•vednig•2h ago•11 comments

Shaders: How to draw high fidelity graphics with just x and y coordinates

https://www.makingsoftware.com/chapters/shaders
333•Garbage•12h ago•74 comments

Racket v9.0

https://blog.racket-lang.org/2025/11/racket-v9-0.html
265•Fice•11h ago•91 comments

Liva AI (YC S25) Is Hiring

https://www.ycombinator.com/companies/liva-ai/jobs/fYP8QP8-growth-intern
1•ashlleymo•2h ago

Particle Life – Sandbox Science

https://sandbox-science.com/particle-life
34•StromFLIX•3h ago•3 comments

Iowa City made its buses free. traffic cleared, and so did the air

https://www.nytimes.com/2025/11/18/climate/iowa-city-free-buses.html
134•bookofjoe•3h ago•128 comments

Mount Proton Drive on Linux using rclone and systemd

https://github.com/dadtronics/protondrive-linux
102•cf100clunk•9h ago•34 comments

New magnetic component discovered in the Faraday effect after nearly 2 centuries

https://phys.org/news/2025-11-magnetic-component-faraday-effect-centuries.html
16•rbanffy•4d ago•0 comments

Doge 'doesn't exist' with eight months left on its charter

https://www.reuters.com/world/us/doge-doesnt-exist-with-eight-months-left-its-charter-2025-11-23/
38•the_mitsuhiko•1h ago•10 comments

A time-travelling door bug in Half Life 2

https://mastodon.gamedev.place/@TomF/115589875974658415
314•AshleysBrain•2d ago•36 comments

ISPs more likely to throttle netizens who connect through CG-NAT: Cloudflare

https://www.theregister.com/2025/11/03/cloudflare_cgnat_bias_research/
25•throw0101a•1h ago•3 comments

X's new country-of-origin feature reveals many 'US' accounts to be foreign-run

https://www.hindustantimes.com/world-news/us-news/xs-new-country-of-origin-feature-shakes-maga-an...
272•ourmandave•1h ago•137 comments

1M Downloads of Zorin OS 18

https://blog.zorin.com/2025/11/18/test-the-upgrade-from-zorin-os-17-to-18-and-celebrating-1-milli...
204•m463•5h ago•167 comments

After my dad died, we found the love letters

https://www.jenn.site/after-my-dad-died-we-found-the-love-letters/
764•eatitraw•16h ago•368 comments

An Economy of AI Agents

https://arxiv.org/abs/2509.01063
86•nerder92•23h ago•58 comments

MCP Apps: Extending servers with interactive user interfaces

http://blog.modelcontextprotocol.io/posts/2025-11-21-mcp-apps/
167•mercury24aug•21h ago•108 comments

'Invisible' microplastics spread in skies as global pollutant

https://www.asahi.com/ajw/articles/16137995
12•devonnull•58m ago•1 comments

Terence Tao: At the Erdos problem website, AI assistance now becoming routine

https://mathstodon.xyz/@tao/115591487350860999
169•dwohnitmok•1d ago•22 comments

Editing Code in Emacs

https://redpenguin101.github.io/html/posts/2025_11_23_emacs_for_code_editing.html
118•redpenguin101•10h ago•34 comments

"Good engineering management" is a fad

https://lethain.com/good-eng-mgmt-is-a-fad/
146•jkbyc•5h ago•53 comments

Court filings allege Meta downplayed risks to children and misled the public

https://time.com/7336204/meta-lawsuit-files-child-safety/
311•binning•9h ago•137 comments

Several core problems with Rust

https://bykozy.me/blog/rust-is-a-disappointment/
86•byko3y•3h ago•98 comments

Giving the Jakks Atari Paddle a Spin

https://nicole.express/2025/paddle-me-atari.html
8•ingve•4h ago•0 comments
Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•6mo ago

Comments

steele•6mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•6mo ago
Lmao, gentrify cracked me up
neilv•6mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•6mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•6mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•6mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•6mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•6mo ago
May as well just release an executable tbh.
theamk•6mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•6mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•6mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."