frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•1y ago

Comments

steele•1y ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•1y ago
Lmao, gentrify cracked me up
neilv•1y ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•1y ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•1y ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•1y ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•1y ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•1y ago
May as well just release an executable tbh.
theamk•1y ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•1y ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•1y ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

2D Vehicles

https://patkerr.co.uk/2d-vehicles/
258•Michelangelo11•3d ago•60 comments

A city-building game in which the city would prefer you didn't

https://housing.over.pizza/
39•JumpCrisscross•1h ago•6 comments

Why DuckDB 2.0 is faster

https://motherduck.com/blog/why-duckdb-20-is-faster/
91•tosh•4h ago•28 comments

Knuth reward check

https://www.thomas-huehn.com/knuth-reward-check/
116•Curiositry•6h ago•44 comments

Nix wrote half of my debugger

https://fzakaria.com/2026/10/07/nix-wrote-half-of-my-debugger
63•ingve•1d ago•4 comments

The Lightbulb Computer

https://lightbulbcomputer.com/
123•oskarth•18h ago•34 comments

Recent AI models struggled to match a human algorithmic innovation

https://epoch.ai/publications/innovationeval
53•merksittich•23h ago•41 comments

Talorys – A self-hosted personal AI agent on Cloudflare's free tier

https://github.com/rociiu/talorys
221•rociiu•11h ago•112 comments

Mxc: Microsoft Execution Containers version 1.0.0

https://blogs.windows.com/windowsdeveloper/2026/10/07/microsoft-execution-containers-policy-drive...
140•smokel•1d ago•28 comments

Nvidia in talks to acquire US 'open' model startup Reflection AI

https://www.ft.com/content/052610c5-22b4-4dd4-932e-b7f9f0628b6a
87•arkj•3h ago•52 comments

Apple/macOS removed from official Unix registry

https://www.opengroup.org//openbrand/register/
222•john_alan•11h ago•198 comments

REA Reverse – Engineer Anything

https://rea.tools/
659•modinfo•21h ago•290 comments

Grieving the loss of details

https://purplesyringa.moe/blog/grieving-the-loss-of-details/
287•signa11•4d ago•229 comments

OpenSCAD the Programmers Solid 3D CAD Modeller

https://openscad.org/
75•b-man•4d ago•65 comments

Rampart: Browser native on-device PII radaction

https://ndstudio.gov/posts/say-hello-to-rampart
58•nateb2022•1d ago•25 comments

Unikernels were hard. key word: were

https://ghuntley.com/unikernels/
54•ghuntley•7h ago•23 comments

Telegram Desktop vulnerability allowed any user's file to be stolen

https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
390•g-b-r•19h ago•234 comments

How strong is the strong interaction?

https://cerncourier.com/how-strong-is-the-strong-interaction/
38•EA-3167•22h ago•7 comments

Bitwarden Dual License Model

https://community.bitwarden.com/t/published-version-update-in-app-stores/102750
315•Cider9986•7h ago•235 comments

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-bing-redirects-to-push-cl...
13•PicardManeuver•54m ago•4 comments

A nuclear clock synchronized to 229Th

https://www.nature.com/articles/s41586-026-11122-1
7•sbulaev•3d ago•2 comments

I would like the value of my home to rise, while my property taxes fall

https://conversableeconomist.com/2026/09/28/i-would-like-the-value-of-my-home-to-rise-while-my-pr...
179•colinprince•8h ago•435 comments

Whooping Cranes Learned to Migrate by Following Costumed Pilots

https://theverifiedpost.com/article/whooping-cranes-ultralight-costumed-pilots-operation-migration
48•kgolubic•1d ago•6 comments

Chip-hex:cost-benefit, energy efficiency and hexagonal

https://github.com/lzprograma/Chip-Hexa
4•Engineercom•1d ago•2 comments

Eye of Sauron: Long-Range Hidden Spy Camera Detection (2024)

https://www.usenix.org/conference/usenixsecurity24/presentation/zhang-qibo
292•ortusdux•3d ago•69 comments

Chernobyl particles reveal unexpectedly stable nuclear fuel after 40 years

https://phys.org/news/2026-10-chernobyl-particles-reveal-unexpectedly-stable.html
118•geox•3d ago•42 comments

50MB operating system can resurrect your old PC

https://www.makeuseof.com/this-50mb-operating-system-can-resurrect-your-old-pc/
20•makerdiety•2h ago•4 comments

Takeshi's Castle

https://en.wikipedia.org/wiki/Takeshi%27s_Castle
65•tosh•3h ago•24 comments

`123456' password used in Danish CPR data breach

https://cphpost.dk/2026-10-10/news/round-up/123456-password-used-in-massive-danish-cpr-data-breach/
368•baal80spam•12h ago•190 comments

How Protein Took over the World

https://www.ft.com/content/e26574cf-94cc-40d9-921e-5c7417fc5dbd
46•thm•6h ago•111 comments