frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•6mo ago

Comments

steele•6mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•6mo ago
Lmao, gentrify cracked me up
neilv•6mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•6mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•6mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•6mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•6mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•6mo ago
May as well just release an executable tbh.
theamk•6mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•6mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•6mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Show HN: Wealthfolio 2.0- Open source investment tracker. Now Mobile and Docker

https://wealthfolio.app/?v=2.0
321•a-fadil•4h ago•105 comments

Helping Valve to power up Steam devices

https://www.igalia.com/2025/11/helpingvalve.html
203•TingPing•4h ago•48 comments

You can make PS2 games in JavaScript

https://jslegenddev.substack.com/p/you-can-now-make-ps2-games-in-javascript
178•tosh•4h ago•26 comments

Arduino published updated terms and conditions: no longer an open commons

https://www.molecularist.com/2025/11/did-qualcomm-kill-arduino-for-good.html
227•felineflock•5h ago•82 comments

We Remain Alive Also in a Dead Internet

https://slavoj.substack.com/p/why-we-remain-alive-also-in-a-dead-954
13•achierius•44m ago•1 comments

We should all be using dependency cooldowns

https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
196•todsacerdoti•6h ago•135 comments

We remember the internet bubble. This mania looks and feels the same

https://crazystupidtech.com/2025/11/21/boom-bubble-bust-boom-why-should-ai-be-different/
14•speckx•1h ago•2 comments

Building a Durable Execution Engine with SQLite

https://www.morling.dev/blog/building-durable-execution-engine-with-sqlite/
70•ingve•1d ago•17 comments

Solving Fizz Buzz with Cosines

https://susam.net/fizz-buzz-with-cosines.html
73•hprotagonist•4h ago•16 comments

Shop Sans is a typeface for curved text paths

https://www.futurefonts.com/hex/shop-sans
65•tobr•1w ago•21 comments

Samsung's 60% DRAM Price Hike Signals a New Phase of Global Memory Tightening

https://www.buysellram.com/blog/samsungs-memory-price-surge-sends-shockwaves-through-the-global-d...
13•redohmy•6d ago•2 comments

FAWK: LLMs can write a language interpreter

https://martin.janiczek.cz/2025/11/21/fawk-llms-can-write-a-language-interpreter.html
184•todsacerdoti•11h ago•165 comments

Olmo 3: Charting a path through the model flow to lead open-source AI

https://allenai.org/blog/olmo3
333•mseri•14h ago•105 comments

Making a Small RPG

https://jslegenddev.substack.com/p/making-a-small-rpg
139•ibobev•8h ago•27 comments

Pivot Robotics (YC W24) Is Hiring for an Industrial Automation Hardware Engineer

https://www.ycombinator.com/companies/pivot-robotics/jobs/7xG9Dc6-mechanical-engineer-controls
1•vigneshrajmohan•4h ago

Command Lines

https://www.wreflection.com/p/command-lines-ai-coding
37•nowflux•4h ago•5 comments

How/why to sweep async tasks under a Postgres table

https://taylor.town/pg-task
24•ostler•3h ago•11 comments

Prozac 'no better than placebo' for treating children with depression, experts

https://www.theguardian.com/society/2025/nov/20/prozac-no-better-than-placebo-for-treating-childr...
129•pseudolus•21h ago•146 comments

EXIF orientation info in PNGs isn't used for image-orientation: from-image

https://bugzilla.mozilla.org/show_bug.cgi?id=1627423
78•justin-reeves•8h ago•67 comments

It's hard to build an oscillator

https://lcamtuf.substack.com/p/its-hard-to-build-an-oscillator
200•chmaynard•13h ago•74 comments

Scientists now know that bees can process time, a first in insects

https://www.cnn.com/2025/11/12/science/bees-visual-stimulus-study-scli-intl
173•Brajeshwar•6d ago•99 comments

Homeschooling hits record numbers

https://reason.com/2025/11/19/homeschooling-hits-record-numbers/
126•bilsbie•20h ago•346 comments

More tales about outages and numeric limits

https://rachelbythebay.com/w/2025/11/18/down/
38•todsacerdoti•7h ago•3 comments

XBMC 4.0 for the Original Xbox

https://www.xbox-scene.info/articles/announcing-xbmc-40-for-the-original-xbox-r64/
99•zdw•6h ago•49 comments

Solving the Whole Year Puzzle with Z3

https://jcrowell.net/posts/whole-year-sat
10•jaycrowell•4d ago•2 comments

The New AI Consciousness Paper

https://www.astralcodexten.com/p/the-new-ai-consciousness-paper
95•rbanffy•5h ago•179 comments

Brazil charges 31 people in major carbon credit fraud investigation

https://news.mongabay.com/short-article/2025/11/brazil-charges-31-people-in-major-carbon-credit-f...
42•PaulHoule•3h ago•10 comments

I converted a rotary phone into a meeting handset

https://www.stavros.io/posts/i-converted-a-rotary-phone-into-a-meeting-handset/
140•todsacerdoti•1w ago•67 comments

FEX-emu – Run x86 applications on ARM64 Linux devices

https://fex-emu.com/
278•open-paren•1w ago•118 comments

WebAssembly from the Ground Up

https://wasmgroundup.com/
236•gurjeet•6d ago•53 comments