frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•1y ago

Comments

steele•1y ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•1y ago
Lmao, gentrify cracked me up
neilv•1y ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•1y ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•1y ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•1y ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•1y ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•1y ago
May as well just release an executable tbh.
theamk•1y ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•1y ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•1y ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Claude Sonnet 5

https://www.anthropic.com/news/claude-sonnet-5
611•marinesebastian•2h ago•326 comments

Claude Code is steganographically marking requests

https://thereallo.dev/blog/claude-code-prompt-steganography
1018•kirushik•5h ago•266 comments

Claude Science

https://claude.com/product/claude-science
248•lebovic•3h ago•86 comments

Nano Banana 2 Lite

https://deepmind.google/models/gemini-image/flash-lite/
211•minimaxir•4h ago•76 comments

I built a mmWave material classification radar

https://gauthier-lechevalier.com/radar
92•GL26•3h ago•28 comments

Claude Sonnet 5 – benchmark results

https://artificialanalysis.ai/models/claude-sonnet-5
7•lucamark•42m ago•0 comments

Matrix URIs, a URL syntax from Tim Berners-Lee that never shipped (1996)

https://www.w3.org/DesignIssues/MatrixURIs.html
27•napolux•4d ago•14 comments

County with 37 Data Centers Asks Schools to 'Conserve Electricity'

https://www.404media.co/henrico-virginia-datacenter-energy-cost-email/
349•01-_-•4h ago•149 comments

Memoirs of Extraordinary Popular Delusions and the Madness of Crowds (1852)

https://www.gutenberg.org/ebooks/24518
143•lstodd•8h ago•44 comments

Don't Make Gates Optional, Make Them Flexible

https://wakamoleguy.com/p/flexible-gates
39•wakamoleguy•3d ago•4 comments

Knoppix

https://www.knopper.net/knoppix/index-en.html
192•hoangvmpc•7h ago•84 comments

Open Source Low Tech

https://opensourcelowtech.org/
598•grep_it•4d ago•120 comments

Set up your own DoH (DNS over HTTPS) service

https://nochan.net/b/Internet-Crap/20260602-Set-Up-Your-Own-DoH-Service/
30•Bender•2d ago•11 comments

Tell HN: Installing Cursor on iOS irreversibly changes your privacy settings

140•zkldi•2h ago•20 comments

Building a custom octocopter from scratch with no prior hardware experience

https://karolina.mgdubiel.com/drone/
283•noleary•2d ago•58 comments

A peek into Reddit's anti-spam internals

https://lyra.horse/blog/2026/06/reddit-spam-internals/
51•OuterVale•3d ago•7 comments

CERN bids farewell to the LHC and enters Long Shutdown 3

https://home.cern/cern-bids-farewell-to-the-lhc-and-enters-long-shutdown-3/
31•HelloUsername•1d ago•3 comments

Something Is Wrong with Modern Longevity Science

https://www.newyorker.com/magazine/2026/07/06/morbid-saul-justin-newman-book-review-eat-your-ice-...
6•nabbed•34m ago•4 comments

I built a 10 inch mini rack from aluminium extrusions

https://louwrentius.com/i-build-a-10-inch-mini-rack-from-aluminium-extrusions.html
25•louwrentius•2d ago•10 comments

Crypto firms have spent $189M so far on 2026 US election, report says

https://www.reuters.com/world/crypto-firms-have-spent-189-million-so-far-2026-us-election-report-...
179•tartoran•4h ago•80 comments

Factorio 2.1 Experimental Release

https://factorio.com/blog/post/fff-444
127•ibobev•3d ago•66 comments

SedonaDB 0.4: GPU-accelerated spatial joins

https://sedona.apache.org/latest/blog/2026/06/26/sedonadb-04-gpu-accelerated-spatial-joins/
26•dr-jia-yu•4d ago•4 comments

1.38 Millimeter Microcontroller

https://www.ti.com/product/MSPM0C1104
120•kristianpaul•4d ago•84 comments

A Fake Shell for Pangenomics

https://www.cs.cornell.edu/~asampson/blog/flash.html
17•matt_d•4d ago•0 comments

Zluda 6 release (run unmodified CUDA applications on non-Nvidia GPUs)

https://vosen.github.io/ZLUDA/blog/zluda-update-q1q2-2026/
125•Tiberium•10h ago•12 comments

Counterexamples in type systems (2021)

https://counterexamples.org/
35•bramadityaw•1d ago•1 comments

RF Hacking My Cloud-Controlled Ceiling Fan

https://samwilkinson.io/posts/2026-06-24-rf-hacking-dreo
13•sammycdubs•6d ago•2 comments

The best thing that's ever happened for multiplayer games?

https://mas-bandwidth.com/the-best-thing-thats-ever-happened-for-multiplayer-games/
8•gafferongames•52m ago•2 comments

6 years and 360 patches to clean all instances of strnpy out of the Linux kernel

https://smist08.wordpress.com/2026/06/25/linux-kills-strncpy/
49•ingve•4d ago•31 comments

Supreme Court upholds broad conception of birthright citizenship

https://apnews.com/live/birthright-citizenship-decision-supreme-court-updates-06-30-2026
122•toomuchtodo•6h ago•279 comments