frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•1y ago

Comments

steele•1y ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•1y ago
Lmao, gentrify cracked me up
neilv•1y ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•1y ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•1y ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•1y ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•1y ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•1y ago
May as well just release an executable tbh.
theamk•1y ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•1y ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•1y ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Claude Opus 4.8

https://www.anthropic.com/news/claude-opus-4-8
1093•craigmart•6h ago•868 comments

Bricks and Minifigs Stole a Man's $200k Lego Collection

https://mybricklog.com/blog/bricks-minifigs-corporate-stole-old-mans-200000-lego-collection
417•philips•3h ago•231 comments

Just Use Postgres for Durable Workflows

https://www.dbos.dev/blog/postgres-is-all-you-need-for-durable-execution
227•KraftyOne•4h ago•92 comments

Various LLM Smells

https://shvbsle.in/various-llm-smells/
131•speckx•3h ago•97 comments

I Made a Million Dollar Product from My Dorm Room (2025)

https://nick.winans.io/blog/nice-nano/
74•mattrighetti•2h ago•4 comments

Nitpicking the shell history scene in 'Tron: Legacy'

https://www.chiark.greenend.org.uk/~sgtatham/quasiblog/tron-legacy/
96•speckx•3h ago•33 comments

I hated writing until I learned there’s a science to it (2024)

https://www.science.org/content/article/i-hated-writing-until-i-learned-there-s-science-it
100•o4c•5h ago•44 comments

News about Raspberry Pi 6 and Microcontroller Development

https://www.jeffgeerling.com/blog/2026/news-about-raspberry-pi-6-and-microcontroller-development/
122•rbanffy•2d ago•89 comments

The Permanent Upper Crow

https://permanent-upper-crow.jasonwu.ink/
140•whiteblossom•7h ago•49 comments

Coalton is an efficient, statically typed Lisp with ideas from Haskell and OCaml

https://coalton-lang.github.io/
63•b-man•2d ago•7 comments

Show HN: Continue? Y/N: A 60-second game about AI agent permission fatigue

https://llmgame.scalex.dev
212•Wirbelwind•9h ago•99 comments

The Most Unlikely School Bag

https://www.carryology.com/insights/carry-culture/the-tale-of-the-worlds-most-unlikely-school-bag/
59•surprisetalk•3d ago•19 comments

Bitburner, programming-based incremental game

https://bitburner-official.github.io/
65•agmater•5h ago•13 comments

Show HN: Ktx – Open-source executable context layer for data agents

https://github.com/Kaelio/ktx
47•lucamrtl•7h ago•6 comments

GitHub bans security researcher who posted zero-day Windows exploits

https://www.tomshardware.com/tech-industry/cyber-security/microsofts-github-bans-security-researc...
43•possibilistic•1h ago•3 comments

Anthropic raises $65B in Series H funding at $965B post-money valuation

https://www.anthropic.com/news/series-h
210•meetpateltech•4h ago•184 comments

Indoor Wi-Fi Roaming with OpenWRT

https://taoofmac.com/space/blog/2026/05/26/1730
190•zdw•2d ago•94 comments

Endive: A JVM native WebAssembly runtime

https://github.com/bytecodealliance/endive
44•theanonymousone•6h ago•13 comments

Separate the Cord from the Device

https://bookofjoe2.blogspot.com/2026/05/blog-post_27.html
30•bookofjoe•3h ago•25 comments

Durable Execution the Hard Way

https://github.com/hatchet-dev/durable-execution-the-hard-way
6•abelanger•10h ago•0 comments

Micromania: The Whole Truth about Home Computers (1984)

https://taff.org.uk/ebooks.php?x=Micromania
4•sohkamyung•3d ago•0 comments

The Lone Lisp Heap

https://www.matheusmoreira.com/articles/lone-lisp-heap
30•stevekemp•4h ago•9 comments

Using Tailscale with an OrbStack VM on macOS

https://github.com/highpost/tailscale-macos-vm
54•highpost•3d ago•11 comments

EU fines Temu €200M for allowing sale of illegal products

https://www.bbc.co.uk/news/articles/c1k2ydn1rz8o
286•jjp•8h ago•211 comments

Protestware for Coding Agents

https://nesbitt.io/2026/05/28/protestware-for-coding-agents.html
4•SVI•1h ago•1 comments

Announcing Rust 1.96

https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/
63•adamch•3h ago•6 comments

Confidence Scores for Exam Questions

https://nomagicpill.substack.com/p/confidence-scores-for-exam-questions
9•surprisetalk•3d ago•7 comments

YouTube to automatically label AI-generated videos

https://blog.youtube/news-and-events/improving-ai-labels-viewers-creators/
1263•nopg•1d ago•751 comments

Sam Altman and Dario Amodei are both walking back AI jobs apocalypse predictions

https://fortune.com/2026/05/26/sam-altman-dario-amodei-walking-back-ai-jobs-apocalypse-prophecies...
135•ianrahman•3h ago•115 comments

Legislation Killed Would Have Effectively Blocked Police LPR, Including Flock

https://ipvm.com/reports/bipartisan-alpr-amendment-killed
83•jhonovich•5h ago•53 comments