frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•1y ago

Comments

steele•1y ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•1y ago
Lmao, gentrify cracked me up
neilv•1y ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•1y ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•1y ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•1y ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•1y ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•1y ago
May as well just release an executable tbh.
theamk•1y ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•1y ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•1y ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

GrapheneOS user reported to authorities for using GrapheneOS

https://discuss.grapheneos.org/d/36134-grapheneos-user-reported-to-authorities-for-using-grapheneos
203•Cider9986•1h ago•93 comments

Zig Zen Update

https://codeberg.org/ziglang/zig/commit/621844bde551ee1a9b8142d7d146d1fa804247a2
42•tosh•2h ago•13 comments

How LLMs work

https://www.0xkato.xyz/how-llms-actually-work/
376•0xkato•2d ago•110 comments

The intracies of modern camera lens repair (2024)

https://salvagedcircuitry.com/sigma-45mm.html
176•transistor-man•10h ago•60 comments

S&P 500 rejects SpaceX, also blocking entry for OpenAI and Anthropic

https://arstechnica.com/tech-policy/2026/06/sp-500-blocks-fast-spacex-entry-wont-waive-rule-for-u...
510•maltalex•6h ago•169 comments

Pre-Modern Armies for Worldbuilders, Part I: Why They Fight

https://acoup.blog/2026/06/05/collections-pre-modern-armies-for-worldbuilders-part-i-why-they-fight/
78•gostsamo•6h ago•21 comments

Social Cache Busting

https://www.autodidacts.io/social-cache-busting/
37•surprisetalk•3d ago•8 comments

New method turns ocean water into drinking water, without waste

https://www.rochester.edu/newscenter/what-is-desalination-definition-ocean-water-704732/
377•speckx•19h ago•161 comments

Astronauts told to return to ISS after sheltering over air leak repairs

https://www.bbc.com/news/live/c4g44ew3g1kt
399•janpot•19h ago•251 comments

pg_durable: Microsoft open sources in-database durable execution

https://github.com/microsoft/pg_durable
406•coffeemug•18h ago•90 comments

Ask HN: What was your "oh shit" moment with GenAI?

345•andrehacker•1d ago•653 comments

Gemma 4 QAT models: Optimizing compression for mobile and laptop efficiency

https://blog.google/innovation-and-ai/technology/developers-tools/quantization-aware-training-gem...
354•theanonymousone•18h ago•108 comments

The back cover of C++: The Language raises questions not answered by front cover

https://devblogs.microsoft.com/oldnewthing/20260605-01/?p=112391
98•paulmooreparks•7h ago•28 comments

Did Claude increase bugs in rsync?

https://alexispurslane.github.io/rsync-analysis/
419•logicprog•21h ago•433 comments

Ten Years of Franz

https://meetfranz.com/blog/ten-years-of-franz
36•tosh•3d ago•25 comments

Mouseless – keyboard-driven control of macOS/Linux/Windows

https://mouseless.click
532•riddley•2d ago•216 comments

Raytracing Geometries in 3D Rendering

https://andeplane.github.io/Raytracing/
8•kvakkefly•3d ago•1 comments

Lockdown Mode

https://help.openai.com/en/articles/20001061-lockdown-mode
61•berlianta•7h ago•26 comments

My Agent Skill for Test-Driven Development

https://www.saturnci.com/my-agent-skill-for-test-driven-development.html
183•laxmena•1d ago•79 comments

Nine Ways to Do Inheritance in Rust, a Language Without Inheritance

https://medium.com/@carlmkadie/nine-ways-to-do-inheritance-in-rust-a-language-without-inheritance...
51•pjmlp•2d ago•8 comments

Gov.uk has replaced Stripe with Dutch provider Adyen

https://www.theregister.com/public-sector/2026/06/04/govuk-goes-dutch-on-payments-as-it-dumps-str...
460•toomuchtodo•17h ago•167 comments

Azure Linux Desktop

https://www.boxofcables.dev/azure-linux-desktop-a-build-2026-mashup-of-wslc-winui-reactor-and-azu...
11•haydenbarnes•2h ago•2 comments

Conventional Commits encourages focus on the wrong things

https://sumnerevans.com/posts/software-engineering/stop-using-conventional-commits/
314•jsve•18h ago•233 comments

The perils of UUID primary keys in SQLite

https://andersmurphy.com/2026/06/05/the-perils-of-uuid-primary-keys-in-sqlite.html
94•emschwartz•11h ago•54 comments

Exact UNORM8 to Float

https://fgiesen.wordpress.com/2024/11/06/exact-unorm8-to-float/
5•firephox•3d ago•1 comments

Tracing a powerful GNSS interference source over Europe

https://arxiv.org/abs/2606.03673
398•mimorigasaka•1d ago•206 comments

The Quiet Numbers Station: Decoding Nineteen Years of GPS Cryptography

https://www.benthamsgaze.org/2026/06/02/the-quiet-numbers-station-decoding-nineteen-years-of-gps-...
92•lordgilman•21h ago•71 comments

Ask HN: Why is the HN crowd so anti-AI?

168•Ekami•8h ago•303 comments

India's surprise baby bust

https://www.economist.com/leaders/2026/06/04/indias-surprise-baby-bust-is-a-warning-to-the-world
186•hakonbogen•19h ago•789 comments

Transformers are inherently succinct

https://openreview.net/pdf?id=Yxz92UuPLQ
122•brandonb•15h ago•36 comments