frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•11mo ago

Comments

steele•11mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•11mo ago
Lmao, gentrify cracked me up
neilv•11mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•11mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•11mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•11mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•11mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•11mo ago
May as well just release an executable tbh.
theamk•11mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•11mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•11mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Windows 9x Subsystem for Linux

https://social.hails.org/@hailey/116446826733136456
486•sohkamyung•5h ago•126 comments

3.4M Solar Panels

https://tech.marksblogg.com/american-solar-farms-v2.html
153•marklit•3h ago•89 comments

Our eighth generation TPUs: two chips for the agentic era

https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/eighth-generation-tpu...
161•xnx•3h ago•96 comments

Treetops glowing during storms captured on film for first time

https://www.psu.edu/news/earth-and-mineral-sciences/story/treetops-glowing-during-storms-captured...
61•t-3•1h ago•8 comments

GitHub CLI now collects pseudoanonymous telemetry

https://cli.github.com/telemetry
207•ingve•3h ago•158 comments

Show HN submissions tripled and are now mostly "look" vibe-coded

https://www.adriankrebs.ch/blog/design-slop/
40•hubraumhugo•38m ago•18 comments

Qwen3.6-27B: Flagship-Level Coding in a 27B Dense Model

https://qwen.ai/blog?id=qwen3.6-27b
44•mfiguiere•2h ago•16 comments

The best time to post on Hacker News

https://blog.alcazarsec.com/tech/posts/best-time-to-post-on-hacker-news
7•alcazar•26m ago•0 comments

Columnar Storage Is Normalization

https://buttondown.com/jaffray/archive/columnar-storage-is-normalization/
38•ibobev•2h ago•17 comments

Making RAM at Home [video]

https://www.youtube.com/watch?v=h6GWikWlAQA
491•kaipereira•1d ago•136 comments

ChatGPT Images 2.0

https://openai.com/index/introducing-chatgpt-images-2-0/
945•wahnfrieden•20h ago•824 comments

How does GPS work?

https://perthirtysix.com/how-the-heck-does-gps-work
129•alfanick•6h ago•28 comments

Kernel code removals driven by LLM-created security reports

https://lwn.net/Articles/1068928/
67•edward•3h ago•46 comments

DuckDB 1.5.2 – SQL database that runs on laptop, server, in the browser

https://duckdb.org/2026/04/13/announcing-duckdb-152
24•janandonly•33m ago•2 comments

XOR'ing a register with itself is the idiom for zeroing it out. Why not sub?

https://devblogs.microsoft.com/oldnewthing/20260421-00/?p=112247
116•ingve•8h ago•129 comments

Another Day Has Come

https://daringfireball.net/2026/04/another_day_has_come
76•ndr42•18h ago•73 comments

All your agents are going async

https://zknill.io/posts/all-your-agents-are-going-async/
95•zknill•2d ago•56 comments

Prefill-as-a-Service:KVCache of Next-Generation Models Could Go Cross-Datacenter

https://arxiv.org/abs/2604.15039
28•matt_d•3d ago•1 comments

MuJoCo – Advanced Physics Simulation

https://github.com/google-deepmind/mujoco
76•modinfo•3d ago•15 comments

Expansion Artifacts

https://mattstromawn.com/writing/expansion-artifacts/
16•tobr•1d ago•1 comments

Monitor your Pi / OMP sessions

https://github.com/BlackBeltTechnology/pi-agent-dashboard
11•ankitg12•3d ago•1 comments

Contact Lens Uses Microfluidics to Monitor and Treat Glaucoma

https://spectrum.ieee.org/smart-contact-lens-glaucoma-microfluidics
78•pseudolus•3d ago•2 comments

Garbage Collection Without Unsafe Code

https://fitzgen.com/2024/02/06/safe-gc.html
86•foota•3d ago•29 comments

Drunk post: Things I've learned as a senior engineer (2021)

https://luminousmen.substack.com/p/drunk-post-things-ive-learned-as
226•zdw•15h ago•170 comments

Windows Server 2025 Runs Better on ARM

https://jasoneckert.github.io/myblog/server-2025-arm64/
163•jasoneckert•3d ago•123 comments

Nobody Got Fired for Uber's $8M Ledger Mistake?

https://news.alvaroduran.com/p/nobody-got-fired-for-ubers-8-million
87•ohduran•4h ago•60 comments

The Vercel breach: OAuth attack exposes risk in platform environment variables

https://www.trendmicro.com/en_us/research/26/d/vercel-breach-oauth-supply-chain.html
350•queenelvis•22h ago•112 comments

Acetaminophen vs. ibuprofen

https://asteriskmag.com/issues/14/the-mystery-in-the-medicine-cabinet
575•nkurz•2d ago•364 comments

SpaceX says it has agreement to acquire Cursor for $60B

https://twitter.com/spacex/status/2046713419978453374
732•dmarcos•17h ago•890 comments

CATL's new LFP battery can charge from 10 to 98% in less than 7 minutes

https://arstechnica.com/cars/2026/04/catls-new-lfp-battery-can-charge-from-10-to-98-in-less-than-...
84•PotatoNinja•4h ago•39 comments