frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

The Fed says this is a cube of $1M. They're off by half a million

https://calvin.sh/blog/fed-lie/
744•c249709•5h ago•283 comments

Figma Files Registration Statement for Proposed Initial Public Offering

https://www.figma.com/blog/s1-public/
97•kualto•2h ago•32 comments

The Roman Roads Research Association

https://www.romanroads.org/
14•bjourne•1h ago•2 comments

Feasibility study of a mission to Sedna - Nuclear propulsion and solar sailing

https://arxiv.org/abs/2506.17732
153•speckx•7h ago•51 comments

Ask HN: Who is hiring? (July 2025)

162•whoishiring•7h ago•176 comments

Code⇄GUI bidirectional editing via LSP

https://jamesbvaughan.com/bidirectional-editing/
65•jamesbvaughan•5h ago•23 comments

Show HN: Spegel, a Terminal Browser That Uses LLMs to Rewrite Webpages

https://simedw.com/2025/06/23/introducing-spegel/
282•simedw•9h ago•132 comments

The Hoyle State (2021)

https://johncarlosbaez.wordpress.com/2021/02/04/the-hoyle-state/
38•gone35•3h ago•7 comments

I built something that changed my friend group's social fabric

https://blog.danpetrolito.xyz/i-built-something-that-changed-my-friend-gro-social-fabric/
477•dandano•3d ago•199 comments

Show HN: Core – open source memory graph for LLMs – shareable, user owned

https://github.com/RedPlanetHQ/core
34•Manik_agg•5h ago•4 comments

Muxio: Rust layered stream and RPC toolkit

https://crates.io/crates/muxio
9•zombiej5•2d ago•0 comments

Experience converting a mathematical software package to C++20 modules [PDF]

https://arxiv.org/abs/2506.21654
83•vblanco•8h ago•15 comments

Building a Personal AI Factory

https://www.john-rush.com/posts/ai-20250701.html
17•derek•49m ago•7 comments

Ask HN: Who wants to be hired? (July 2025)

47•whoishiring•7h ago•132 comments

Cua (YC X25) is hiring an engineer

https://www.ycombinator.com/companies/cua/jobs/dIskIB1-founding-engineer-cua-yc-x25
1•GreenGames•5h ago

When Did Nature Burst into Vivid Color?

https://www.quantamagazine.org/when-did-nature-burst-into-vivid-color-20250627/
77•jandrewrogers•4d ago•51 comments

OpenFLOW – Quickly make beautiful infrastructure diagrams local to your machine

https://github.com/stan-smith/OpenFLOW
254•x0z•15h ago•62 comments

Swearing as a Response to Pain: Assessing Effects of Novel Swear Words

https://www.frontiersin.org/journals/psychology/articles/10.3389/fpsyg.2020.00723/full
24•sega_sai•2d ago•21 comments

Graph Theory Applications in Video Games

https://utk.claranguyen.me/talks.php?id=videogames
43•haywirez•3d ago•4 comments

All Good Editors Are Pirates: In Memory of Lewis H. Lapham

https://www.laphamsquarterly.org/roundtable/all-good-editors-are-pirates
44•Caiero•2d ago•4 comments

Show HN: HackerNewt - Breadth-first exploring HN client for iOS

https://apps.apple.com/us/app/hackernewt-for-hacker-news/id6448201970
34•hnand•6h ago•22 comments

The Hidden Engineering of Liquid Dampers in Skyscrapers

https://practical.engineering/blog/2025/7/1/the-hidden-engineering-of-liquid-dampers-in-skyscrapers
16•chmaynard•2h ago•0 comments

Show HN: Jobs by Referral: Find jobs in your LinkedIn network

https://jobsbyreferral.com/
100•nicksergeant•9h ago•53 comments

The wanton destruction of a creative-tech era

https://blog.greg.technology/2025/06/30/fastly.html
18•gregsadetsky•3h ago•7 comments

Show HN: Arch-Router – 1.5B model for LLM routing by preferences, not benchmarks

33•adilhafeez•4h ago•8 comments

Sam Altman Slams Meta's AI Talent Poaching: 'Missionaries Will Beat Mercenaries'

https://www.wired.com/story/sam-altman-meta-ai-talent-poaching-spree-leaked-messages/
72•spenvo•3h ago•151 comments

1KB JavaScript Demoscene Challenge Just Launched

71•babakode•3h ago•13 comments

Slouching Towards Sensemaking

https://karanchawla.io/2025/06/29/sensemaking
11•karchaw•2d ago•0 comments

Show HN: I built the tool I wished existed for moving Stripe between countries

https://www.stripemove.com/
71•felphos•9h ago•36 comments

HN Slop: AI startup ideas generated from Hacker News

https://www.josh.ing/hn-slop
64•coloneltcb•6h ago•25 comments
Open in hackernews

I am not a supplier (2022)

https://www.softwaremaxims.com/blog/not-a-supplier
26•wofo•7h ago

Comments

stego-tech•7h ago
I’ve seen more and more visceral rejection of the notion of “software supply chain” by source contributors. They’re rightly calling out the hypocrisy of companies demanding they be complicit in the supply chain of a product, but not paid or compensated for their works on it.

There is no “software supply chain”, only products you didn’t pay for but still expect slave labor to support in perpetuity.

On the flip side, I’ve never known a project to reject work while being paid a livable wage to complete it. Funny, that.

reverendsteveii•4h ago
your insistence that people doing what they want on their own time and then disposing of the product as they see fit is "slave labor" undermines your otherwise valid point.
stego-tech•4h ago
Your deliberate misconstruing of my argument to support a point I wasn’t remotely making undermines your entire comment.

Expected or required labor that is not compensated is, well, slavery. Labor that is freely given without expectation of compensation or reward is volunteerism.

Trying to guilt open source projects into addressing security, regulatory, or feature concerns under some sort “digital supply chain” label without compensating them for their time or labor is a form of entitlement on the part of companies who could easily pay for the resources they consume or contribute the fixes themselves, but choose not to. Demanding said labor without compensation, with or without threat of consequences, is to demand the other party willfully submit to a form of enslavement or servitude.

I’m specifically talking about “digital supply chain” labels and logistics being applied to Open Source projects without their consent or compensation. You don’t get to magic up some excuse to not call the demand for free labor without compensation as anything other than what it actually is.

reverendsteveii•4h ago
when is labor required of FOSS? I always assumed that I was perfectly free to not write FOSS but I'd be interested to find out in what manner I can be compelled to do so. Keep in mind that asking, even asking forcefully or impolitely, is not compulsion. Compulsion is about what happens if the request is not fulfilled.
bee_rider•4h ago
Expected labor that is not compensated is not slavery. It could is rude to expect people to do labor for us for free, but there’s no compulsion behind it.

Required labor that is not compensated flirts with slavery.

Part of the danger of a software supply chain law is that, as a law, it can compel behavior. So, it is runs the risk of bumping stuff from the “expected” to “required” bucket.

> Demanding said labor without compensation, with or without threat of consequences, is to demand the other party willfully submit to a form of enslavement or servitude.

A demand without a threat of consequences is just a request. It could be a very rude request. But that’s all it is.

Conflating rude requests with compelled actions cheapens the impact of the latter, and obscures what is wrong about the former.

gnabgib•7h ago
Discussion in 2024 (121 points, 37 comments) https://news.ycombinator.com/item?id=39904234

2022 (389 points, 240 comments) https://news.ycombinator.com/item?id=34201368

bee_rider•6h ago
Is there much push anymore, behind the “open source software supply chain” concept? It seems like a very misguided and bad idea, but I actually wonder if the open source community actually managed to get that point through to policy makers? At least I haven’t heard anything about it lately (I’m not particularly listening, though).
zappb•5h ago
The EU has been working on regulations related to this over the past couple of years. Various OSS foundations have been tracking this like Apache, Linux, and Eclipse Foundations.
detaro•5h ago
Yes, and the regulations and guidelines coming out are looking good with regards to open-source, it seems they've gotten into the right places to be heard. (Basically they protect people just providing open-source from liability and force companies to have plans how they'll deal with their open dependencies)
lucasyvas•6h ago
Counter-argument to the author: If you publish a package you are a supplier full stop. If you don’t want to be considered a supplier, do not publish a built version of your software.

Allow someone else to build and publish it on your behalf (i.e. a separate distributor entity), then they become the supplier. They assume the risk - they can establish those business relationships.

This is how software distribution has worked in Linux forever. For example, it’s Debian’s or Red Hat’s problem to fix a bug in a library they ship and they can upstream it back to you if they want.

Do not publish your package, only provide the source. Publish it for only yourself privately if you wish to consume it. Promote it, provide build scripts… whatever. But don’t publish it.

bee_rider•6h ago
That seems like a totally artificial distinction. If somebody releases a compiled version of their project along with the source code, just to save their friends time, they aren’t any more responsible for it that they were for the source code.

The responsibility is entirely a matter of licensing and contracts. Most free software doesn’t accept any responsibility in the license, and isn’t sold, so there’s no implied warranty or anything like that.

lucasyvas•6h ago
It seems artificial at face value but the distribution model has existed for decades under the same conditions.

The argument is that we should split these two concerns explicitly to create a delineation of roles and responsibilities. We have a model for this but don’t adopt it elsewhere in the name of simplicity, but the outcome is more complex because you can’t point the finger at anyone.

It should work as you say, but it doesn’t and arguably never will. So I suggest we deliberately change everything to the distribution model to make it explicit. It then becomes clearer that the distributor is who you go to for support. If the author is the distributor, go to them. If it’s someone else, go to the entity that distributes it. If there is no distributor, it’s on you to build it and support it yourself.

It forces the build process onto the distributor which makes them best set up to deploy fixes, therefore it’s more clearly their responsibility. The shifting of where it builds actually goes a long way to solving this problem. If you are building and publishing it yourself, you are set up to fix the issue immediately which indicates you should fix it first and then upstream it.

bee_rider•6h ago
What form does has this responsibility taken for decades? I use Ubuntu currently, if Canonical broke my computer I’d fully expect to have no recourse…
lucasyvas•6h ago
If there’s a bug in SSH libraries that Canonical ships in Ubuntu, that is their distribution of that library even if they are not the primary authors. Canonical guarantees support for the software it ships, so they are obligated to fix it no matter what. Fixes are upstreamed to the primary author - the author never asked for their software to be included in that distribution so it’s not their problem to fix it for Ubuntu users.

This is a model that solves the problem the author is discussing.

samrus•6h ago
Where does Canonical say they guarantee support? They might for their paid program, but they dont for their free version. Which is the exact point the author made
lucasyvas•6h ago
Ubuntu literally has LTS releases where they guarantee fixes for security issues and the like for absolutely no charge.
bee_rider•6h ago
Are we talking about, like, legal liability or just a feeling of social obligation?

I think with software supply chain, we’re talking about the former, and I don’t think Canonical has any legal liability toward me (who hasn’t paid them anything; although because I expect nothing I didn’t read the license in detail). In terms of feelings of social obligation it is much more complex, of course.

lucasyvas•6h ago
Social obligations are inherently weak is the point I’m trying to make. Make it easy for active users of your software to distribute it and make it harder for free-loaders. The problem solves itself.
Aeolos•4h ago
Almost all open-source software comes with a version of the following license terms:

"THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE."

To use the software you have to accept the license, which means you explicitly confirm that they are not your supplier. Pretty clear cut, no?

Edit: EULA-loving companies don't want to accept the license terms for the _free_ software they themselves are using - the hypocrisy is nothing short of staggering.

gwbas1c•2h ago
At least Node.js and Rust distribute dependencies as source. NPM and Cargo automate adding and compiling dependencies.

But, to be quite blunt: I've put a few hobby packages up on Cargo and NPM just to see if other people like them. If you think I'm going to assume liability if someone hits a bug, then you're in for a rude awakening.

The source code is available for free for anyone who wants to use or modify it. If it doesn't meet someone's needs, they can fix it themselves or contact me and we can work out a mutually beneficial arrangement.

sblom•2h ago
I really love Rob Mensching's framing in Open Source Maintenance Fee[1]. "The _software_ is free. The _project_ (issue tracker, forums, release management, package repository, etc.) is not."

It doesn't solve the supplier problem, but it is a very clever way to square the "free software, but I'd like to cover my expenses" circle.

[1]: https://opensourcemaintenancefee.org/

hyperman1•1h ago
I feel there must be a middle ground here. It's similar to free food. Giving food to anyone does not entitle them to more food in the future. They are not entitled to complain free food is not up to their standards or demand changes.

But they are entitled to not being poisoned. Basic sanitation is still required. You should remove free food from the public once it's rotting.