frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

We're going to need default hard budget caps on pretty much everything

https://simonwillison.net/2026/Oct/3/default-hard-budget-caps/
232•elffjs•2h ago•125 comments

Bob Cringely Has Died

168•paveworld•2h ago•28 comments

Treachery in the Rodin Museum 3D scan verdict

https://cosmowenman.substack.com/p/rodin-museum-3d-scan-verdict
99•CosmoWenman•9h ago•52 comments

Hole Punch: Sling your spaceship around gravitational fields

https://notoriousbfg.com/hole-punch/
246•trwhite•9h ago•62 comments

The work by Valve's Timur Kristóf on improving old AMD GPUs on Linux

https://www.phoronix.com/news/XDC-2026-Valve-Timur-AMDGPU
164•speckx•7h ago•21 comments

Reasons I didn't become an EMT, ranked

https://ben.stolovitz.com/posts/reasons-not-emt-ranked/
112•citelao•6h ago•55 comments

So You Think You Could Be an Electrician?

https://asteriskmag.com/issues/15/so-you-think-you-could-be-an-electrician
32•zdw•3d ago•16 comments

Celebrating the 100th birthday of the kidney donated to him as a teenager

https://www.whec.com/top-news/webster-man-celebrating-the-100th-birthday-of-the-kidney-his-mom-do...
153•gscott•2d ago•40 comments

Kolibri: A Sovereign Open-Weight Model

https://aleph-alpha.com/en/blog/kolibri-has-landed-a-sovereign-open-weight-model/
533•bastitx•17h ago•304 comments

OpenAI safety leader quits, warning AI company's culture is 'broken'

https://www.theguardian.com/technology/2026/oct/03/openai-safety-leader-quits-warning-ai-companys...
206•jethronethro•4h ago•161 comments

Math's pedagogical curse – Grant Sanderson [video]

https://www.youtube.com/watch?v=UOuxo6SA8Uc
15•bobajeff•1d ago•6 comments

Getting the most out of Opus 5.5 in Claude and Claude Code

https://claude.dev/blog/getting-the-most-out-of-opus-5-5/
177•saikatsg•8h ago•126 comments

Your body of work thinks back at you

https://photoni.st/index.php/2026/09/25/your-body-of-work-thinks-back-at-you/
26•surprisetalk•3d ago•1 comments

Show HN: Thoreau BASIC – What if BASIC hadn't gone out of fashion?

https://thoreaubasic.com/
37•Gorsefound•19h ago•13 comments

FTL: A new operating system for clouds

https://ftl-os.org/
152•romac•12h ago•61 comments

New York City should carefully measure a new tree

https://blog.willmeye.rs/new-york-city-should-carefully-measure-a-new-tree/
53•willmeyers•1d ago•10 comments

Agents don't need memory, they need documentation

https://liao.gg/blog/agents-dont-need-memory
69•kmeh•10h ago•52 comments

Three AI agents, two countries, and one uneven world wide web

https://royapakzad.substack.com/p/multilingual-ai-agents
9•effects•1d ago•0 comments

Surely you have ultra-wideband radios on your bins too?

https://sjg.io/writing/binrange-have-you-actually-put-the-bins-out/
48•simonjgreen•6h ago•25 comments

Show HN: Pi pod – Run your pi coding agent in sandboxes on your own server

https://pipod.dev/
80•edverma2•1d ago•30 comments

Federal judge calls Flock 'indiscriminate mass surveillance'

https://techcrunch.com/2026/10/03/federal-judge-calls-flock-indiscriminate-mass-surveillance/
339•sbulaev•5h ago•208 comments

Docker has always used microVMs (well since 2016)

https://dave.recoil.org/docker-has-always-used-microvms/
24•avsm•11h ago•18 comments

Woking Electrical Control Room (2016)

http://www.darbiansphotography.com/woking-electrical-control-room-urbex
126•NaOH•1d ago•25 comments

RSS Feed Best Practices (2022)

https://kevincox.ca/2022/05/06/rss-feed-best-practices/
41•KomoD•8h ago•8 comments

RetailReady (YC W24) Is Hiring

https://www.ycombinator.com/companies/retailready/jobs/bFcgIe4-implementations
1•sarah74•10h ago

Memory-Safe WebP Decoding

https://halide.cx/blog/wpd/
43•computerbuster•21h ago•14 comments

Apple's "Clean Design" Is Stupidity When It Comes to Hiding Fire Extinguishers

https://www.gadgetreview.com/apples-clean-design-is-stupidity-when-it-comes-to-hiding-fire-exting...
62•josephcsible•3h ago•23 comments

We want you to build the next Git platform on Cloudflare

https://blog.cloudflare.com/next-git-platform-on-cloudflare/
104•geoffbp•7h ago•96 comments

How to hack time, with C2PA

https://www.da.vidbuchanan.co.uk/blog/hacking-time.html
25•Retr0id•8h ago•3 comments

C++ Insights – See your source code with the eyes of a Compiler

https://github.com/andreasfertig/cppinsights
142•rramadass•2d ago•28 comments
Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•1y ago

Comments

steele•1y ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•1y ago
Lmao, gentrify cracked me up
neilv•1y ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•1y ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•1y ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•1y ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•1y ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•1y ago
May as well just release an executable tbh.
theamk•1y ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•1y ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•1y ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."