frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Show HN: LocalGPT – A local-first AI assistant in Rust with persistent memory

https://github.com/localgpt-app/localgpt
135•yi_wang•4h ago•40 comments

Haskell for all: Beyond agentic coding

https://haskellforall.com/2026/02/beyond-agentic-coding
57•RebelPotato•4h ago•13 comments

SectorC: A C Compiler in 512 bytes (2023)

https://xorvoid.com/sectorc.html
256•valyala•12h ago•51 comments

Speed up responses with fast mode

https://code.claude.com/docs/en/fast-mode
166•surprisetalk•12h ago•158 comments

Software factories and the agentic moment

https://factory.strongdm.ai/
199•mellosouls•15h ago•353 comments

Total surface area required to fuel the world with solar (2009)

https://landartgenerator.org/blagi/archives/127
22•robtherobber•4d ago•16 comments

Bye Bye Humanity: The Potential AMOC Collapse

https://thatjoescott.com/2026/02/03/bye-bye-humanity-the-potential-amoc-collapse/
41•rolph•2h ago•26 comments

LLMs as the new high level language

https://federicopereiro.com/llm-high/
66•swah•4d ago•120 comments

Brookhaven Lab's RHIC concludes 25-year run with final collisions

https://www.hpcwire.com/off-the-wire/brookhaven-labs-rhic-concludes-25-year-run-with-final-collis...
73•gnufx•11h ago•59 comments

Hoot: Scheme on WebAssembly

https://www.spritely.institute/hoot/
180•AlexeyBrin•17h ago•35 comments

Stories from 25 Years of Software Development

https://susam.net/twenty-five-years-of-computing.html
172•vinhnx•15h ago•17 comments

Vocal Guide – belt sing without killing yourself

https://jesperordrup.github.io/vocal-guide/
320•jesperordrup•22h ago•97 comments

First Proof

https://arxiv.org/abs/2602.05192
135•samasblack•14h ago•79 comments

Vouch

https://twitter.com/mitchellh/status/2020252149117313349
67•chwtutha•3h ago•11 comments

Why there is no official statement from Substack about the data leak

https://techcrunch.com/2026/02/05/substack-confirms-data-breach-affecting-email-addresses-and-pho...
17•witnessme•1h ago•6 comments

Show HN: I saw this cool navigation reveal, so I made a simple HTML+CSS version

https://github.com/Momciloo/fun-with-clip-path
83•momciloo•12h ago•17 comments

Wood Gas Vehicles: Firewood in the Fuel Tank (2010)

https://solar.lowtechmagazine.com/2010/01/wood-gas-vehicles-firewood-in-the-fuel-tank/
31•Rygian•2d ago•8 comments

Homeland Security Spying on Reddit Users

https://www.kenklippenstein.com/p/homeland-security-spies-on-reddit
63•duxup•2h ago•14 comments

Al Lowe on model trains, funny deaths and working with Disney

https://spillhistorie.no/2026/02/06/interview-with-sierra-veteran-al-lowe/
105•thelok•14h ago•24 comments

Show HN: A luma dependent chroma compression algorithm (image compression)

https://www.bitsnbites.eu/a-spatial-domain-variable-block-size-luma-dependent-chroma-compression-...
40•mbitsnbites•3d ago•5 comments

Start all of your commands with a comma (2009)

https://rhodesmill.org/brandon/2009/commands-with-comma/
580•theblazehen•3d ago•211 comments

FDA intends to take action against non-FDA-approved GLP-1 drugs

https://www.fda.gov/news-events/press-announcements/fda-intends-take-action-against-non-fda-appro...
112•randycupertino•7h ago•235 comments

The AI boom is causing shortages everywhere else

https://www.washingtonpost.com/technology/2026/02/07/ai-spending-economy-shortages/
306•1vuio0pswjnm7•18h ago•488 comments

Learning from context is harder than we thought

https://hy.tencent.com/research/100025?langVersion=en
233•limoce•4d ago•125 comments

Where did all the starships go?

https://www.datawrapper.de/blog/science-fiction-decline
156•speckx•4d ago•241 comments

Microsoft account bugs locked me out of Notepad – Are thin clients ruining PCs?

https://www.windowscentral.com/microsoft/windows-11/windows-locked-me-out-of-notepad-is-the-thin-...
144•josephcsible•10h ago•179 comments

OpenCiv3: Open-source, cross-platform reimagining of Civilization III

https://openciv3.org/
904•klaussilveira•1d ago•276 comments

Selection rather than prediction

https://voratiq.com/blog/selection-rather-than-prediction/
34•languid-photic•4d ago•16 comments

Show HN: Look Ma, No Linux: Shell, App Installer, Vi, Cc on ESP32-S3 / BreezyBox

https://github.com/valdanylchuk/breezydemo
304•isitcontent•1d ago•39 comments

I write games in C (yes, C) (2016)

https://jonathanwhiting.com/writing/blog/games_in_c/
189•valyala•12h ago•178 comments
Open in hackernews

Triaging security issues reported by third parties

https://gitlab.gnome.org/GNOME/libxml2/-/issues/913
33•zdw•7mo ago

Comments

tptacek•7mo ago
Wow, this is a whole thing. Like: absolutely, unpaid volunteers shouldn't feel like they're on deadlines to fix security bugs in open source code. They're not. But you're reading this and assuming, "ok, they're getting a lot of dumb reports from random bounty seekers or whatever", and, nope, he's complaining about GPZ.

Which, again, fair enough! But the bugs he's apparently talking about are presumably very serious.

(If maintainers of projects like libxslt stop fixing bugs, Google will ultimately just fix them.)

mdaniel•7mo ago
It took me a second: "Google Project Zero" which I accept responsibility for because I come to the comments before TFA but I hadn't seen that initialism before
ndiddy•7mo ago
This library was originally written to parse GNOME configuration XML files. It was never intended for parsing untrusted data. From GNOME's perspective, if you can crash the XML parser with a malformed config file, that's just a regular bug. If an attacker is able to write to arbitrary files in your home directory, he's already won.

I agree with the maintainer's perspective that it's irresponsible for Apple, Microsoft, and Google to rely on this library for parsing untrusted data in products that they make billions of dollars off of, not provide him any monetary or other support, and expect him to prioritize fixing "security bugs" that don't impact security for his use case. If I was the maintainer, I'd make the same decision he made.

tptacek•7mo ago
All of us agree!
Aurornis•7mo ago
I definitely have empathy for OSS maintainers but getting to the bottom of what was going on here was a rollercoaster.

They mentioned Google Project Zero “breathing down our necks” but then later said Google Project Zero hadn’t even reported anything this year:

> That said, Project Zero has notably reported zero security vulnerabilities in libxml2 since the start of this year.

windward•7mo ago
Michael and Nick are different people
runningmike•7mo ago
“ These organizations are very exclusive clubs and anything but open.” This is so true! Many tests of the OpenSSF Scorecards do not make sense when you e.g do not use github actions and have a one persons project…..
cwillu•7mo ago
Proof of work captcha appears to be busted?