frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•7mo ago

Comments

steele•7mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•7mo ago
Lmao, gentrify cracked me up
neilv•7mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•7mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•7mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•7mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•7mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•7mo ago
May as well just release an executable tbh.
theamk•7mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•7mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•7mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

“Erdos problem #728 was solved more or less autonomously by AI”

https://mathstodon.xyz/@tao/115855840223258103
409•cod1r•9h ago•232 comments

Changes to Android Open Source Project

https://source.android.com/
85•TechTechTech•2d ago•38 comments

The Performance Revolution in JavaScript Tooling

https://blog.appsignal.com/2025/12/03/the-performance-revolution-in-javascript-tooling.html
12•PaulHoule•6d ago•0 comments

JavaScript Demos in 140 Characters

https://beta.dwitter.net
238•themanmaran•13h ago•49 comments

Oh My Zsh adds bloat

https://rushter.com/blog/zsh-shell/
139•fla•4h ago•129 comments

RTX 5090 and Raspberry Pi: Can it game?

https://scottjg.com/posts/2026-01-08-crappy-computer-showdown/
214•scottjg•13h ago•81 comments

Start your meetings at 5 minutes past

https://philipotoole.com/start-your-meetings-at-5-minutes-past/
107•otoolep•10h ago•86 comments

Greenland sharks maintain vision for centuries through DNA repair mechanism

https://phys.org/news/2026-01-eye-greenland-sharks-vision-centuries.html
80•pseudolus•3d ago•19 comments

How Markdown took over the world

https://www.anildash.com/2026/01/09/how-markdown-took-over-the-world/
238•zdw•14h ago•191 comments

CDC staff 'blindsided' as child vaccine schedule unilaterally overhauled

https://www.unmc.edu/healthsecurity/transmission/2026/01/07/cdc-staff-blindsided-as-child-vaccine...
62•stopbulying•3h ago•14 comments

Alien: Braun Aromaster KF 20 Coffee Makers (2012)

http://alienexplorations.blogspot.com/1979/05/kf-20-coffee-making-machine.html
24•exvi•1w ago•3 comments

How will the miracle happen today?

https://kk.org/thetechnium/how-will-the-miracle-happen-today/
432•zdw•5d ago•223 comments

Show HN: Miditui – a terminal app/UI for MIDI composing, mixing, and playback

https://github.com/minimaxir/miditui
35•minimaxir•1d ago•4 comments

Show HN: Rocket Launch and Orbit Simulator

https://www.donutthejedi.com/
121•donutthejedi•13h ago•35 comments

Show HN: Scroll Wikipedia like TikTok

https://quack.sdan.io
229•sdan•14h ago•59 comments

Cloudflare CEO on the Italy fines

https://twitter.com/eastdakota/status/2009654937303896492
510•sidcool•15h ago•701 comments

Scientists discover oldest poison, on 60k-year-old arrows

https://www.nytimes.com/2026/01/07/science/poison-arrows-south-africa.html
114•noleary•1d ago•40 comments

My article on why AI is great (or terrible) or how to use it

https://matthewrocklin.com/ai-zealotry/
110•akshayka•14h ago•160 comments

The likely cheapest home-made Michelson interferometer

https://guille.site/posts/3d-printed-michelson/
95•LolWolf•5d ago•58 comments

OLED, Not for Me

https://nuxx.net/blog/2026/01/09/oled-not-for-me/
78•c0nsumer•4h ago•83 comments

Robotopia: A 3D, first-person, talking simulator

https://elbowgreasegames.substack.com/p/introducing-robotopia-a-3d-first
52•psawaya•1d ago•17 comments

Favorite Tech Museums

https://aresluna.org/fav-tech-museums/
43•justincormack•4d ago•21 comments

Kagi releases alpha version of Orion for Linux

https://help.kagi.com/orion/misc/linux-status.html
379•HelloUsername•19h ago•266 comments

How to code Claude Code in 200 lines of code

https://www.mihaileric.com/The-Emperor-Has-No-Clothes/
750•nutellalover•1d ago•230 comments

How to store a chess position in 26 bytes (2022)

https://ezzeriesa.notion.site/How-to-store-a-chess-position-in-26-bytes-using-bit-level-magic-df1...
98•kurinikku•17h ago•79 comments

Sigmund Freud's Begonia

https://observer.co.uk/news/first-person/article/emma-freud-sigmund-freuds-begonia
24•dang•11h ago•7 comments

USDA suspends federal financial awards to Minnesota and Minneapolis

https://turnto10.com/news/nation-world/enough-is-enough-usda-suspends-federal-financial-awards-to...
26•blurbleblurble•5h ago•10 comments

Show HN: I made a memory game to teach you to play piano by ear

https://lend-me-your-ears.specr.net
464•vunderba•15h ago•163 comments

Flock Hardcoded the Password for America's Surveillance Infrastructure 53 Times

https://nexanet.ai/blog/53-times-flocksafety-hardcoded-the-password-for-americas-surveillance-inf...
421•fuck_flock•15h ago•140 comments

Show HN: Similarity = cosine(your_GitHub_stars, Karpathy) Client-side

https://puzer.github.io/github_recommender/
134•puzer•3d ago•36 comments