frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•7mo ago

Comments

steele•7mo ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•7mo ago
Lmao, gentrify cracked me up
neilv•7mo ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•7mo ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•7mo ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•7mo ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•7mo ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•7mo ago
May as well just release an executable tbh.
theamk•7mo ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•7mo ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•7mo ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Private equity firms acquired more than 500 autism centers in past decade: study

https://www.brown.edu/news/2026-01-07/private-equity-autism-centers
123•hhs•1h ago•61 comments

Show HN: Librario, a book metadata API that aggregates G Books, ISBNDB, and more

24•jamesponddotco•1h ago•11 comments

Show HN: I used Claude Code to discover connections between 100 books

https://trails.pieterma.es/
197•pmaze•8h ago•68 comments

Finding and fixing Ghostty's largest memory leak

https://mitchellh.com/writing/ghostty-memory-leak-fix
210•thorel•6h ago•50 comments

Open Chaos: A self-evolving open-source project

https://www.openchaos.dev/
299•stefanvdw1•9h ago•62 comments

Show HN: Play poker with LLMs, or watch them play against each other

https://llmholdem.com/
53•projectyang•5h ago•32 comments

Eulogy for Dark Sky, a data visualization masterpiece (2023)

https://nightingaledvs.com/dark-sky-weather-data-viz/
363•skadamat•12h ago•156 comments

AI is a business model stress test

https://dri.es/ai-is-a-business-model-stress-test
149•amarsahinovic•8h ago•188 comments

Code and Let Live

https://fly.io/blog/code-and-let-live/
201•usrme•1d ago•68 comments

1970 Paris, cut into a grid and photographed

https://paris1970.jeantho.eu/index.html
16•panic•1w ago•4 comments

Show HN: GlyphLang – An AI-first programming language

12•goose0004•1h ago•8 comments

Code Is Clay

https://campedersen.com/code-is-clay
24•ecto•5h ago•13 comments

Overdose deaths are falling in America because of a 'supply shock': study

https://www.economist.com/united-states/2026/01/08/why-overdose-deaths-are-falling-in-america
62•marojejian•5h ago•42 comments

Rats caught on camera hunting flying bats

https://scienceclock.com/rats-caught-on-camera-hunting-flying-bats-for-the-first-time/
71•akg130522•6h ago•8 comments

Show HN: mcpc – Universal command-line client for Model Context Protocol (MCP)

https://github.com/apify/mcp-cli
5•jancurn•4d ago•2 comments

ASCII-Driven Development

https://medium.com/@calufa/ascii-driven-development-850f66661351
89•_hfqa•2d ago•62 comments

ChatGPT Health is a marketplace, guess who is the product?

https://consciousdigital.org/chatgpt-health-is-a-marketplace-guess-who-is-the-product/
221•yoaviram•2d ago•229 comments

The eight ways that all the elements in the Universe are made (2021)

https://bigthink.com/starts-with-a-bang/8-ways-elements-made/
48•zdw•5d ago•20 comments

I replaced Windows with Linux and everything's going great

https://www.theverge.com/tech/858910/linux-diary-gaming-desktop
530•rorylawless•9h ago•451 comments

Side-by-side comparison of how AI models answer moral dilemmas

https://civai.org/p/ai-values
67•jesenator•2d ago•44 comments

A child in the state of nature

https://lareviewofbooks.org/article/a-child-in-the-state-of-nature/
9•Caiero•3d ago•0 comments

UpCodes (YC S17) is hiring PMs, SWEs to automate construction compliance

https://up.codes/careers?utm_source=HN
1•Old_Thrashbarg•8h ago

New information extracted from Snowden PDFs through metadata version analysis

https://libroot.org/posts/going-through-snowden-documents-part-4/
277•libroot•13h ago•115 comments

Org Mode Syntax Is One of the Most Reasonable Markup Languages for Text (2017)

https://karl-voit.at/2017/09/23/orgmode-as-markup-only/
243•adityaathalye•15h ago•172 comments

Extracting books from production language models (2026)

https://arxiv.org/abs/2601.02671
23•logicprog•4h ago•2 comments

How wolves became dogs

https://www.economist.com/christmas-specials/2025/12/18/how-wolves-became-dogs
101•mooreds•5d ago•87 comments

How your high school affects your chances of UC Admission

https://sfeducation.substack.com/p/how-your-high-school-affects-your
60•mutator•2d ago•133 comments

Varnish and Virtue

https://literaryreview.co.uk/varnish-virtue
5•prismatic•2d ago•0 comments

UK Orders Ofcom to Explore Encryption Backdoors

https://reclaimthenet.org/uk-orders-ofcom-to-explore-encryption-backdoors
74•worldofmatthew•3h ago•25 comments

NASA announces unprecedented return of sick ISS astronaut and crew

https://www.livescience.com/space/space-exploration/nasa-cancels-spacewalk-and-considers-early-cr...
92•bookofjoe•11h ago•87 comments