frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•9mo ago

Comments

steele•9mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•9mo ago
Lmao, gentrify cracked me up
neilv•9mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•9mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•9mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•9mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•9mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•9mo ago
May as well just release an executable tbh.
theamk•9mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•9mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•9mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

3D-Knitting: The Ultimate Guide

https://www.oliver-charles.com/pages/3d-knitting
74•ChadNauseam•2h ago•26 comments

SBCL: A Sanely-Bootstrappable Common Lisp (2008) [pdf]

https://research.gold.ac.uk/id/eprint/2336/1/sbcl.pdf
53•pabs3•4h ago•30 comments

Show HN: s@: decentralized social networking over static sites

http://satproto.org/
299•remywang•10h ago•126 comments

Returning to Rails in 2026

https://www.markround.com/blog/2026/03/05/returning-to-rails-in-2026/
149•stanislavb•5h ago•86 comments

Avoiding Trigonometry (2013)

https://iquilezles.org/articles/noacos/
30•WithinReason•2h ago•5 comments

Printf-Tac-Toe

https://github.com/carlini/printf-tac-toe
33•carlos-menezes•3d ago•4 comments

Temporal: The 9-year journey to fix time in JavaScript

https://bloomberg.github.io/js-blog/post/temporal/
694•robpalmer•19h ago•222 comments

Making WebAssembly a first-class language on the Web

https://hacks.mozilla.org/2026/02/making-webassembly-a-first-class-language-on-the-web/
572•mikece•1d ago•204 comments

Datahäxan

https://0dd.company/galleries/witches/7.html
75•akkartik•2d ago•5 comments

1B identity records exposed in ID verification data leak

https://www.aol.com/articles/1-billion-identity-records-exposed-152505381.html
48•robtherobber•1h ago•10 comments

WebPKI and You

https://blog.brycekerley.net/2026/03/08/webpki-and-you.html
63•aragilar•2d ago•5 comments

Tested: How Many Times Can a DVD±RW Be Rewritten? Methodology and Results

https://goughlui.com/2026/03/07/tested-how-many-times-can-a-dvd%C2%B1rw-be-rewritten-part-2-metho...
171•giuliomagnifico•3d ago•46 comments

I was interviewed by an AI bot for a job

https://www.theverge.com/featured-video/892850/i-was-interviewed-by-an-ai-bot-for-a-job
327•speckx•16h ago•301 comments

Dolphin Progress Release 2603

https://dolphin-emu.org/blog/2026/03/12/dolphin-progress-report-release-2603/
7•BitPirate•1h ago•0 comments

Reliable Software in the LLM Era

https://quint-lang.org/posts/llm_era
12•mempirate•2h ago•0 comments

Many SWE-bench-Passing PRs would not be merged

https://metr.org/notes/2026-03-10-many-swe-bench-passing-prs-would-not-be-merged-into-main/
244•mustaphah•14h ago•122 comments

Don't post generated/AI-edited comments. HN is for conversation between humans

https://news.ycombinator.com/newsguidelines.html#generated
3629•usefulposter•15h ago•1356 comments

NASA's DART spacecraft changed an asteroid's orbit around the sun

https://www.sciencenews.org/article/spacecraft-changed-asteroid-orbit-nasa
35•pseudolus•3d ago•14 comments

The MacBook Neo

https://daringfireball.net/2026/03/the_macbook_neo
550•etothet•23h ago•878 comments

Newcomb's Paradox Needs a Demon

https://samestep.com/blog/newcombs-paradox/
3•sestep•2d ago•0 comments

Show HN: I built a tool that watches webpages and exposes changes as RSS

https://sitespy.app
259•vkuprin•18h ago•60 comments

Google closes deal to acquire Wiz

https://www.wiz.io/blog/google-closes-deal-to-acquire-wiz
297•aldarisbm•20h ago•172 comments

BitNet: Inference framework for 1-bit LLMs

https://github.com/microsoft/BitNet
344•redm•22h ago•163 comments

Personal Computer by Perplexity

https://www.perplexity.ai/personal-computer-waitlist
164•josephwegner•16h ago•132 comments

Faster asin() was hiding in plain sight

https://16bpp.net/blog/post/faster-asin-was-hiding-in-plain-sight/
209•def-pri-pub•20h ago•115 comments

Entities enabling scientific fraud at scale (2025)

https://doi.org/10.1073/pnas.2420092122
290•peyton•21h ago•202 comments

Galaxy Zoo

https://www.zooniverse.org/projects/zookeeper/galaxy-zoo
8•mooreds•3d ago•2 comments

About memory pressure, lock contention, and Data-oriented Design

https://mnt.io/articles/about-memory-pressure-lock-contention-and-data-oriented-design/
55•vinhnx•3d ago•6 comments

Show HN: Klaus – OpenClaw on a VM, batteries included

https://klausai.com/
144•robthompson2018•19h ago•84 comments

5,200 holes carved into a Peruvian mountain left by an ancient economy

https://newatlas.com/environment/5-200-holes-peruvian-mountain/
128•defrost•2d ago•66 comments