frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•1y ago

Comments

steele•1y ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•1y ago
Lmao, gentrify cracked me up
neilv•1y ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•1y ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•1y ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•1y ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•1y ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•1y ago
May as well just release an executable tbh.
theamk•1y ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•1y ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•1y ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Want your images back? Sure... That'll be $5!

https://www.lutr.dev/want-your-images-back-sure-that-ll-be-5-dollars
305•lutr•2h ago•123 comments

Epic Games announces Lore version control system

https://lore.org/
101•regnerba•40m ago•52 comments

GLM-5.2 is the new leading open weights model on Artificial Analysis

https://artificialanalysis.ai/articles/glm-5-2-is-the-new-leading-open-weights-model-on-the-artif...
457•himata4113•5h ago•250 comments

Sixty percent of US consumers say 'AI' in brand messaging is a turnoff

https://wpvip.com/future-of-the-web-2026/
494•thm•2h ago•254 comments

RFC 10008: The new HTTP Query Method

https://www.rfc-editor.org/info/rfc10008/
151•schappim•4h ago•75 comments

MicroUI – A tiny, portable, immediate-mode UI library written in ANSI C

https://github.com/rxi/microui
65•peter_d_sherman•3h ago•23 comments

Hacker News but for Independent Blogs

https://bubbles.town/
301•headalgorithm•7h ago•93 comments

Show HN: High-Res Neural Cellular Automata

https://cells2pixels.github.io/
132•esychology•5h ago•32 comments

AI demands more engineering discipline. Not less

https://charitydotwtf.substack.com/p/ai-demands-more-engineering-discipline
43•BerislavLopac•49m ago•6 comments

GrapheneOS has been ported to Android 17

https://discuss.grapheneos.org/d/36469-grapheneos-has-been-ported-to-android-17-and-official-rele...
911•Cider9986•18h ago•476 comments

Running local models is good now

https://vickiboykis.com/2026/06/15/running-local-models-is-good-now/
1450•jfb•1d ago•558 comments

Image Compression

https://www.makingsoftware.com/chapters/image-compression
44•vinhnx•3d ago•5 comments

Abandoned and Little-Known Airfields

https://airfields-freeman.com/
83•wizardforhire•2d ago•15 comments

Show HN: Inkwash, a watercolor sketching app and explanation

https://johnowhitaker.github.io/inkwash/about
31•Yenrabbit•3d ago•11 comments

Why stdx is not on crates.io

https://kerkour.com/stdx-cratesio
13•Keyb0ardWarri0r•25m ago•4 comments

Map Clustering Is Not My Favorite

https://blog.greg.technology/2026/06/12/map-clustering-is-not-my-favorite.html
80•gregsadetsky•4d ago•31 comments

GLM 5.2 Performance Benchmarks

https://artificialanalysis.ai/models/glm-5-2
89•theanonymousone•7h ago•29 comments

Show HN: Capacitor Alarm Clock

https://github.com/ArcaEge/capacitor-alarm-clock
94•arcaege•3d ago•29 comments

ICE Appears to Be Buying Immigrants' Tax Identifiers from a Data Broker

https://www.404media.co/ice-appears-to-be-buying-immigrants-tax-identifiers-from-a-data-broker/
25•ilreb•1h ago•5 comments

Humiliating IIS servers for fun and jail time

https://mll.sh/humiliating-iis-servers-for-fun-and-jail-time/
320•denysvitali•16h ago•78 comments

The Rise and (Potential) Fall of Letterboxd

https://www.statsignificant.com/p/the-rise-and-potential-fall-of-letterboxd
8•speckx•1w ago•0 comments

TIL: You can make HTTP requests without curl using Bash /dev/TCP

https://mareksuppa.com/til/bash-dev-tcp-http-without-curl/
497•mrshu•22h ago•214 comments

Subterranean fungi networks more than 100 quadrillion km in length

https://www.theguardian.com/science/2026/jun/11/arbuscular-mycorrhizal-fungi-plant-life-climate-g...
133•tosh•5d ago•33 comments

From Chesterton's fence to Chesterton's gap

https://stephantul.github.io/blog/unfence/
53•stephantul•8h ago•39 comments

Calvin and Hobbes and the price of integrity

https://therepublicofletters.substack.com/p/calvin-and-hobbes-and-the-price-of
503•pseudolus•23h ago•219 comments

Has AI already killed self-help nonfiction books?

https://tim.blog/2026/06/12/has-ai-already-killed-nonfiction/
371•imakwana•21h ago•419 comments

GPT‑NL: a sovereign language model for the Netherlands

https://www.tno.nl/en/digital/artificial-intelligence/gpt-nl/
239•root-parent•21h ago•273 comments

Wolfram Language and Mathematica version 15

https://writings.stephenwolfram.com/2026/06/launching-version-15-of-wolfram-language-mathematica-...
198•alok-g•15h ago•105 comments

Stop Using JWTs

https://gist.github.com/samsch/0d1f3d3b4745d778f78b230cf6061452
454•dzonga•22h ago•264 comments

Show HN: I built 184 free browser tools – PDF, image, dev, AI tasks, no upload

https://brevio.pro
43•ruimbarreira•5h ago•11 comments