frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•10mo ago

Comments

steele•10mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•10mo ago
Lmao, gentrify cracked me up
neilv•10mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•10mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•10mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•10mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•10mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•10mo ago
May as well just release an executable tbh.
theamk•10mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•10mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•10mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Cohere Transcribe: Speech Recognition

https://cohere.com/blog/transcribe
43•gmays•1h ago•9 comments

Axios compromised on NPM – Malicious versions drop remote access trojan

https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-t...
1597•mtud•14h ago•626 comments

Open source CAD in the browser (Solvespace)

https://solvespace.com/webver.pl
163•phkahler•4h ago•52 comments

GitHub Monaspace Case Study

https://lettermatic.com/custom/monaspace-case-study
54•homebrewer•2h ago•18 comments

A Love Letter to 'Girl Games'

https://aftermath.site/a-love-letter-to-girl-games/
78•zdw•5d ago•53 comments

Ollama is now powered by MLX on Apple Silicon in preview

https://ollama.com/blog/mlx
551•redundantly•13h ago•273 comments

Artemis II is not safe to fly

https://idlewords.com/2026/03/artemis_ii_is_not_safe_to_fly.htm
732•idlewords•15h ago•463 comments

Oracle slashes 30k jobs

https://rollingout.com/2026/03/31/oracle-slashes-30000-jobs-with-a-cold-6/
578•pje•3h ago•478 comments

Show HN: Forkrun – NUMA-aware shell parallelizer (50×–400× faster than parallel)

https://github.com/jkool702/forkrun
18•jkool702•4d ago•5 comments

Claude Code's source code has been leaked via a map file in their NPM registry

https://twitter.com/Fried_rice/status/2038894956459290963
1214•treexs•8h ago•653 comments

Combinators

https://tinyapl.rubenverg.com/docs/info/combinators
91•tosh•5h ago•25 comments

Good code will still win

https://www.greptile.com/blog/ai-slopware-future
14•dakshgupta•3h ago•18 comments

Audio tapes reveal mass rule-breaking in Milgram's obedience experiments

https://www.psypost.org/audio-tapes-reveal-mass-rule-breaking-in-milgram-s-obedience-experiments-...
139•lentoutcry•3d ago•85 comments

RubyGems Fracture Incident Report

https://rubycentral.org/news/rubygems-fracture-incident-report/
42•schneems•3h ago•4 comments

Securing Elliptic Curve Cryptocurrencies Against Quantum Vulnerabilities [pdf]

https://quantumai.google/static/site-assets/downloads/cryptocurrency-whitepaper.pdf
10•jandrewrogers•1h ago•3 comments

Microsoft: Copilot is for entertainment purposes only

https://www.microsoft.com/en-us/microsoft-copilot/for-individuals/termsofuse
187•lpcvoid•3h ago•65 comments

Tell HN: Chrome says "suspicious download" when trying to download yt-dlp

177•joering2•2h ago•57 comments

Accidentally created my first fork bomb with Claude Code

https://www.droppedasbaby.com/posts/2602-01/
4•offbyone42•9h ago•0 comments

Ask HN: Academic study on AI's impact on software development – want to join?

9•research2026•39m ago•3 comments

What major works of literature were written after age of 85? 75? 65?

https://statmodeling.stat.columbia.edu/2026/03/25/what-major-works-of-literature-were-written-aft...
81•paulpauper•3d ago•52 comments

Show HN: Loreline, narrative language transpiled via Haxe: C++/C#/JS/Java/Py/Lua

https://loreline.app/en/docs/technical-overview/
23•jeremyfa•3d ago•8 comments

Multiple Sclerosis

https://subfictional.com/multiple-sclerosis/
45•luu•4d ago•20 comments

Scotty: A beautiful SSH task runner

https://freek.dev/3064-scotty-a-beautiful-ssh-task-runner
9•speckx•1h ago•1 comments

Fedware: Government apps that spy harder than the apps they ban

https://www.sambent.com/the-white-house-app-has-huawei-spyware-and-an-ice-tip-line/
643•speckx•23h ago•253 comments

From 300KB to 69KB per Token: How LLM Architectures Solve the KV Cache Problem

https://news.future-shock.ai/the-weight-of-remembering/
6•future-shock-ai•2d ago•0 comments

Universal Claude.md – cut Claude output tokens

https://github.com/drona23/claude-token-efficient
418•killme2008•16h ago•150 comments

Google's 200M-parameter time-series foundation model with 16k context

https://github.com/google-research/timesfm
262•codepawl•12h ago•97 comments

RamAIn (YC W26) Is Hiring

https://www.ycombinator.com/companies/ramain/jobs/jezgwo5-ai-ml-research-engineer
1•svee•10h ago

Do your own writing

https://alexhwoods.com/dont-let-ai-write-for-you/
691•karimf•1d ago•222 comments

Good CTE, Bad CTE

https://boringsql.com/posts/good-cte-bad-cte/
146•radimm•1d ago•34 comments