frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Building my npx business card

https://ashley.dev/posts/turning-feedback-into-features/
8•edent•1y ago

Comments

steele•1y ago
Ooh, free real estate, let's colonize and gentrify package management
aabhay•1y ago
Lmao, gentrify cracked me up
neilv•1y ago
Do these npx business cards run arbitrary code on your computer?
cypherpunks01•1y ago
npx

Run a command from a local or remote npm package

Description

This command allows you to run an arbitrary command from an npm package (either one installed locally, or fetched remotely), in a similar context as running it via npm run.

neilv•1y ago
Yes, then is a "command from an npm package" arbitrary code?

And what is this "similar context as running it via npm run"?

Would it be better to answer the question directly?

joshka•1y ago
Yeah, this seems like a very smart but inherently flawed idea.
cypherpunks01•1y ago
Yes I agree! OSS package management ecosystems are a great idea, but allowing submissions without any review or vetting is just asking for supply chain attacks.
Xss3•1y ago
May as well just release an executable tbh.
theamk•1y ago
Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

[0] https://www.perlmonks.org/?node_id=412464

watusername•1y ago
Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

$ curl ashley.dev

Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

$ finger @ashley.dev

queezey•1y ago
This would be a great advertisement for security consulting.

"I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

Tailscale didn't stop the Hugging Face intrusion

https://tailscale.com/blog/hugging-face-intrusion
257•bluehatbrit•2h ago•104 comments

Elevators

https://john.fun/elevators
724•Jrh0203•6h ago•186 comments

qm

https://github.com/yc-software/qm
302•tosh•3h ago•69 comments

Twenty-five years ago it was cryptography, today it's model weights

https://weeraman.com/because-we-can/
36•aweeraman•3d ago•6 comments

Golang proposal: container/: generic collection types

https://github.com/golang/go/issues/80590
81•jabits•3h ago•38 comments

Severance

https://lcamtuf.substack.com/p/severance
148•surprisetalk•4h ago•39 comments

Progressive Web Components

https://arielsalminen.com/2026/progressive-web-components/
24•hosteur•11h ago•3 comments

Loops (YC W22) Is Hiring a Product Educator

https://www.ycombinator.com/companies/loops/jobs/zqUnwqB-product-educator-technical-content-creator
1•chrisfrantz•1h ago

Demystifying DRAM Read Disturbance: RowHammer and RowPress Phenomena

https://arxiv.org/abs/2607.28233
10•Jimmc414•1h ago•4 comments

Big Food vs. the People

https://www.lighthousereports.com/investigation/big-food-vs-the-people/
164•jruohonen•5h ago•106 comments

June in Servo: real world compat, media queries, SharedWorker, and more

https://servo.org/blog/2026/07/31/june-in-servo/
59•iamnothere•3h ago•16 comments

Getting 25 Gbps Thunderbolt Ethernet on My Mac Studio

https://www.jeffgeerling.com/blog/2026/getting-25g-ethernet-mac-thunderbolt/
105•speckx•5h ago•67 comments

Let's make the worst Htmx

https://zserge.com/posts/worst-htmx-ever/
30•RebelPotato•16h ago•8 comments

DeepSeek V4 Flash 0731 Intelligence, Performance and Price Analysis

https://artificialanalysis.ai/models/deepseek-v4-flash
497•theanonymousone•14h ago•275 comments

DeepSeek-V4-Flash Update

https://api-docs.deepseek.com/updates/
657•dnhkng•15h ago•313 comments

Termixer (TUI DJ Mixer)

https://github.com/l00sed/termixer
37•l00sed•3h ago•27 comments

The most official water costs $120k a gallon

https://signoregalilei.com/2026/07/26/the-most-official-water-costs-120000-a-gallon/
100•surprisetalk•7h ago•81 comments

Authorize, don't authenticate

https://blog.marcua.net/2026/07/31/authorize-dont-authenticate.html
22•marcua•7h ago•4 comments

Using the railway network as a flatbed scanner [video]

https://media.ccc.de/v/emf2026-74-1-using-the-railway-network-as-a-flatbed-scanner
36•Jimmc414•3h ago•14 comments

Run Kimi K3 using 29 GB of RAM at 0.50 tok/s

https://github.com/sqliteai/waste
107•marcobambini•7h ago•44 comments

Everyone is building LLM routers, we deprecated ours

https://manifest.build/blog/why-we-deprecated-our-llm-router/
67•brunaxLorax•3h ago•36 comments

Predictive Speculative KV Replication for Bursty LLM Inference

https://jwlabs.vercel.app/post/biting-the-bullet
9•shreybirmiwal•2h ago•0 comments

Dubious research tied to Red Bull has shaped energy drink policy

https://www.theexamination.org/articles/red-bull-funded-research-energy-drinks-alcohol
82•Jimmc414•6h ago•140 comments

Algorithms on billion-scale graph using 10GB RAM: I love DataFusion

https://semyonsinchenko.github.io/ssinchenko/post/datafusion-graphs-cc-2/
82•speckx•6h ago•30 comments

How JPEG works: Interactively explore JPEG's lossy compression methods

https://cgjennings.ca/articles/jpeg-compression/
75•at1as•4d ago•7 comments

Show HN: How to build and self-host a code review agent

https://www.trytilde.ai/blog/how-to-build-code-review-agent
9•solsol94•1h ago•2 comments

Orca-Bench: How Ready Are Language Model Agents for Oncall?

https://arxiv.org/abs/2607.28545
20•yruzin•3h ago•5 comments

Just brute force your embeddings

https://softwaredoug.com/blog/2026/07/29/just-brute-force-embeddings
8•JohnBerryman•17h ago•9 comments

A simple clustering algorithm for lists

https://cassidoo.co/post/clustering-tiles/
16•nreece•3d ago•2 comments

A GTK4 SSH-askpass in Zig

https://xn--gckvb8fzb.com/a-gtk4-ssh-askpass-in-zig/
58•surprisetalk•6h ago•18 comments