frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•8mo ago

Comments

steele•8mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•8mo ago
Lmao, gentrify cracked me up
neilv•8mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•8mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•8mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•8mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•8mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•8mo ago
May as well just release an executable tbh.
theamk•8mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•8mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•8mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Floppinux – An Embedded Linux on a Single Floppy, 2025 Edition

https://krzysztofjankowski.com/floppinux/floppinux-2025.html
51•GalaxySnail•2h ago•26 comments

How does misalignment scale with model intelligence and task complexity?

https://alignment.anthropic.com/2026/hot-mess-of-ai/
159•salkahfi•6h ago•41 comments

Coding assistants are solving the wrong problem

https://www.bicameral-ai.com/blog/introducing-bicameral
36•jinhkuan•2h ago•6 comments

The Codex App

https://openai.com/index/introducing-the-codex-app/
612•meetpateltech•12h ago•435 comments

Anki ownership transferred to AnkiHub

https://forums.ankiweb.net/t/ankis-growing-up/68610
325•trms•9h ago•80 comments

GitHub experience various partial-outages/degradations

https://www.githubstatus.com?todayis=2026-02-02
193•bhouston•9h ago•58 comments

Todd C. Miller – Sudo maintainer for over 30 years

https://www.millert.dev/
374•wodniok•13h ago•198 comments

Carnegie Mellon Unversity Computer Club FTP Server

http://128.237.157.9/pub/
62•1vuio0pswjnm7•5d ago•12 comments

xAI joins SpaceX

https://www.spacex.com/updates#xai-joins-spacex
619•g-mork•8h ago•1364 comments

The Connection Machine CM-1 "Feynman" T-shirt

https://tamikothiel.com/cm/cm-tshirt.html
64•tosh•3d ago•14 comments

Ask HN: Who is hiring? (February 2026)

256•whoishiring•14h ago•319 comments

See how many words you have written in Hacker News comments

https://serjaimelannister.github.io/hn-words/
38•Imustaskforhelp•3d ago•52 comments

The TSA's New $45 Fee to Fly Without ID Is Illegal

https://www.frommers.com/tips/airfare/the-tsa-new-45-fee-to-fly-without-id-is-illegal-says-regula...
347•donohoe•7h ago•383 comments

Phenakistoscopes (1833)

https://publicdomainreview.org/collection/phenakistoscopes-1833/
5•tobr•2d ago•0 comments

Ask HN: Anyone else struggle with how to learn coding in the AI era?

17•44Bulldog•3h ago•15 comments

Hacking Moltbook

https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys
291•galnagli•14h ago•168 comments

50 years ago, a young Bill Gates took on the 'software pirates'

https://thenewstack.io/50-years-ago-a-young-bill-gates-took-on-the-software-pirates/
25•MilnerRoute•1d ago•16 comments

Archive.today is directing a DDoS attack against my blog?

https://gyrovague.com/2026/02/01/archive-today-is-directing-a-ddos-attack-against-my-blog/
97•gyrovague-com•2d ago•37 comments

Court orders restart of all US offshore wind power construction

https://arstechnica.com/science/2026/02/court-orders-restart-of-all-us-offshore-wind-construction/
315•ck2•8h ago•182 comments

4x faster network file sync with rclone (vs rsync) (2025)

https://www.jeffgeerling.com/blog/2025/4x-faster-network-file-sync-rclone-vs-rsync/
285•indigodaddy•4d ago•137 comments

Linux From Scratch ends SysVinit support

https://lists.linuxfromscratch.org/sympa/arc/lfs-announce/2026-02/msg00000.html
133•cf100clunk•13h ago•173 comments

Frog 'saunas' could help endangered species beat a deadly fungus (2024)

https://www.science.org/content/article/frog-saunas-could-help-endangered-species-beat-deadly-fungus
5•noleary•2h ago•1 comments

Julia

https://borretti.me/fiction/julia
89•ashergill•7h ago•12 comments

Flying Around the World in under 80 Days

https://pinchito.es/2026/avis-lxxx
4•alexfernandez•1d ago•4 comments

Zig Libc

https://ziglang.org/devlog/2026/#2026-01-31
208•ingve•13h ago•89 comments

Joedb, the Journal-Only Embedded Database

https://www.joedb.org/index.html
62•mci•3d ago•8 comments

G Lang – A lightweight interpreter written in D (2.4MB)

28•pouyathe•3d ago•6 comments

Nano-vLLM: How a vLLM-style inference engine works

https://neutree.ai/blog/nano-vllm-part-1
233•yz-yu•17h ago•24 comments

On being sane in insane places (1973) [pdf]

https://www.weber.edu/wsuimages/psychology/FacultySites/Horvat/OnBeingSaneInInsanePlaces.PDF
77•dbgrman•13h ago•47 comments

Pretty soon, heat pumps will be able to store and distribute heat as needed

https://www.sintef.no/en/latest-news/2026/pretty-soon-heat-pumps-will-be-able-to-store-and-distri...
177•PaulHoule•1d ago•150 comments