frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•8mo ago

Comments

steele•8mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•8mo ago
Lmao, gentrify cracked me up
neilv•8mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•8mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•8mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•8mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•8mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•8mo ago
May as well just release an executable tbh.
theamk•8mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•8mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•8mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Claude Cowork Exfiltrates Files

https://www.promptarmor.com/resources/claude-cowork-exfiltrates-files
424•takira•5h ago•175 comments

Furiosa: 3.5x efficiency over H100s

https://furiosa.ai/blog/introducing-rngd-server-efficient-ai-inference-at-data-center-scale
37•written-beyond•41m ago•7 comments

Anthropic Explicitly Blocking OpenCode

https://gist.github.com/R44VC0RP/bd391f6a23185c0fed6c6b5fb2bac50e
92•ryanvogel•1h ago•50 comments

Scaling long-running autonomous coding

https://cursor.com/blog/scaling-agents
105•samwillis•3h ago•59 comments

The State of OpenSSL for pyca/cryptography

https://cryptography.io/en/latest/statements/state-of-openssl/
67•SGran•3h ago•15 comments

Ask HN: Share your personal website

391•susam•8h ago•1262 comments

Show HN: WebTiles – create a tiny 250x250 website with neighbors around you

https://webtiles.kicya.net/
113•dimden•5d ago•16 comments

Generate QR Codes with Pure SQL in PostgreSQL

https://tanelpoder.com/posts/generate-qr-code-with-pure-sql-in-postgres/
40•tanelpoder•4d ago•1 comments

Billion-Dollar Idea Generator

https://www.pivotgpt.ceo/
17•greenRust•1h ago•10 comments

Sun Position Calculator

https://drajmarsh.bitbucket.io/earthsun.html
58•sanbor•4h ago•12 comments

Why some clothes shrink in the wash and how to unshrink them

https://www.swinburne.edu.au/news/2025/08/why-some-clothes-shrink-in-the-wash-and-how-to-unshrink...
431•OptionOfT•3d ago•237 comments

SparkFun Officially Dropping AdaFruit due to CoC Violation

https://www.sparkfun.com/official-response
379•yaleman•11h ago•375 comments

Find a pub that needs you

https://www.ismypubfucked.com/
209•thinkingemote•9h ago•171 comments

Roam 50GB is now Roam 100GB

https://starlink.com/support/article/58c9c8b7-474e-246f-7e3c-06db3221d34d
245•bahmboo•9h ago•276 comments

ChromaDB Explorer

https://www.chroma-explorer.com/
21•arsentjev•3h ago•1 comments

I hate GitHub Actions with passion

https://xlii.space/eng/i-hate-github-actions-with-passion/
417•xlii•14h ago•296 comments

Native ZFS VDEV for Object Storage (OpenZFS Summit)

https://www.zettalane.com/blog/openzfs-summit-2025-mayanas-objbacker.html
86•suprasam•6h ago•18 comments

Rubik's Cube in Prolog – Order

https://medium.com/@kenichisasagawa/i-am-preparing-material-for-a-prolog-book-af7580acfee7
15•myth_drannon•4d ago•4 comments

How can I build a simple pulse generator to demonstrate transmission lines

https://electronics.stackexchange.com/questions/764155/how-can-i-build-a-simple-pulse-generator-t...
7•alphabetter•5d ago•2 comments

Show HN: Webctl – Browser automation for agents based on CLI instead of MCP

https://github.com/cosinusalpha/webctl
57•cosinusalpha•11h ago•18 comments

Ford F-150 Lightning outsold the Cybertruck and was then canceled for poor sales

https://electrek.co/2026/01/13/ford-f150-lightning-outsold-tesla-cybertruck-canceled-not-selling-...
433•MBCook•8h ago•583 comments

The hunt for a stolen Jackson Pollock

https://www.washingtonpost.com/entertainment/art/interactive/2026/jackson-pollock-theft-isaacs-fa...
16•prismatic•17h ago•1 comments

Anthropic is making a huge mistake

https://geohot.github.io//blog/jekyll/update/2026/01/15/anthropic-huge-mistake.html
9•swah•2h ago•1 comments

Is Rust faster than C?

https://steveklabnik.com/writing/is-rust-faster-than-c/
221•vincentchau•4d ago•253 comments

Ask HN: How do you safely give LLMs SSH/DB access?

55•nico•6h ago•79 comments

GitHub should charge everyone $1 more per month to fund open source

https://blog.greg.technology/2025/11/27/github-should-charge-1-dollar-more-per-month.html
214•evakhoury•9h ago•202 comments

Every country should set 16 as the minimum age for social media accounts

https://www.afterbabel.com/p/why-every-country-should-set-16
141•paulpauper•5h ago•194 comments

Ski map artist James Niehues, the 'Monet of the mountains' (2021)

https://adventure.com/ski-map-artist-james-niehues/
116•gyomu•4d ago•13 comments

So, you’ve hit an age gate. What now?

https://www.eff.org/deeplinks/2026/01/so-youve-hit-age-gate-what-now
295•hn_acker•8h ago•229 comments

You Can Just Buy Far-UVC

https://www.jefftk.com/p/you-can-just-buy-far-uvc
62•surprisetalk•4d ago•95 comments