frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Supporting the BEAM community with free CI/CD security audits

https://www.erlang-solutions.com/blog/supporting-the-beam-community-with-free-ci-cd-security-audits/
87•todsacerdoti•13h ago

Comments

lagniappe•13h ago
The title is "Supporting the BEAM Community with Free CI/CD Security Audits"

There is no need to editorialize the title.

dang•13h ago
(Submitted title was "Free security audits for Erlang and Elixir open source projects")
mananaysiempre•13h ago
Highlights (emphasis mine):

> Open source maintainers can request a free license by emailing safe@erlang-solutions.com and including a link to their [GitHub] repository. Once approved, we provide a SAFE license for one month or up to a year, depending on the project’s needs, at no cost.

The legalese[1] (is incoherent but apparently) does not pass the Curl test, that is, the maintainer of Curl—who gets money by providing commercial support for his completely FOSS project—wouldn’t be allowed to use this had it applied to him:

> You can only use SAFE for open-source software. Any commercial use is prohibited.

[1] https://www.erlang-solutions.com/policies/safe-for-open-sour...

justin66•11h ago
The point you're trying to make about Curl is more unclear than anything in that license.
mananaysiempre•10h ago
It’s a reference to a four-year-old discussion[1] in the Curl bug tracker about Travis CI introducing a similar prohibition on commercial activity in relation to open-source projects. The more general point is, fully open-source projects that earn money via support contracts are few and precious, and it’s a dick move to cut them off.

[1] https://github.com/curl/curl/issues/7150

victorbjorklund•12h ago
Is it just me or does the font look really stretched out on the site?
tiffanyh•12h ago
That's just the normal look of the font they are using (which I'm not a fan of either if that's what you're implying)

https://fonts.adobe.com/fonts/aktiv-grotesk-extended

Animats•11h ago
Took a while to find out what BEAM was. It's the run-time interpreter for Erlang.[1]

It's not in Acronym Finder. There are many hits for BEAM, but this isn't in the top 10.

[1] https://en.wikipedia.org/wiki/BEAM_(Erlang_virtual_machine)

cisrockandroll•11h ago
Congratulations
giancarlostoro•9h ago
Not just Erlang, but all the other languages like Elixir (powers Discord), Gleam and others.
citizenpaul•11h ago
I've seen BEAM mentioned several times on here in the last few months. Is there some sort of thing going on with erlang that I'm out of the loop on?
arcanemachiner•10h ago
Erlang/BEAM/Elixir stuff shows up on the front page of Hacker News pretty often, I'd say at least once per month.

Elixir was a HN darling a few years back. Publicity has somewhat waned since then.

To answer your question, I would say "no", that no particularly interesting things have emerged from that community lately. Just more stuff happened to make it to the front page. (That is not to say anything bad of the BEAM community, just that I see nothing particularly outstanding of late which would warrant such a claim.)

I would say the most recent newsworthy events would include:

- The Erlang `:ssh` module had a serious CVE that required an immediate upgrade for anyone using it.

- Gleam, a BEAM language with static typing, had a v1.0 release.

- Phoenix LiveView also reached v1.0.

- Elixir is making steady progress on the implementation of a static type system, using a novel "set theoretic" type system.

Overall, I would say that the ecosystem as a whole is progressing slowly but steadily.

Towaway69•6h ago
There is Erlang-Red[1] that is bring a visual flow based programming approach to Erlang.

That’s something new in the Erlang world.

[1] = https://github.com/gorenje/erlang-red

no_wizard•5h ago
Neat project, and I think erlang (or its offshoots, like elixir) are great candidates for this sort of thing.

That said, I take issue with this:

>is great for creating data flows that actually describe concurrent processing, it is just a shame the NodeJS is single threaded

Its not really true, there are `worker_threads`[0] as well as a cluster process module[1] for multi processing.

The nodejs runtime has really come a long way here. Though, it is true that by default, its single threaded, and one could argue, and I'd agree with it, that its much easier to do multi process / multi threaded work on the BEAM since it was built with this in mind from the get go.

Never the less, its not so true that NodeJS is limited to a single thread!

[0]: https://nodejs.org/api/worker_threads.html

[1]: https://nodejs.org/api/cluster.html

travisgriggs•5h ago
> is progressing slowly but steadily

This is one of the things that has made me like Elixir so much. Every time I update my Android or Apple apps with a few months in between, I have to figure out what things they've thrown in the language now.

The Elixir community seems to be less in search of "what's the hot programmer item that we have to have this week" and instead be more at peace with it's simple approach to computing, and just work off of that.

Slow and Steady is nice these days; better than Hot and Volatile.

zelphirkalt•10h ago
Whenever Erlang is the topic, BEAM is not far off. It is like Java and JVM.

Hardening mode for the compiler

https://discourse.llvm.org/t/rfc-hardening-mode-for-the-compiler/87660
65•vitaut•3h ago•3 comments

Cerebras Code

https://www.cerebras.ai/blog/introducing-cerebras-code
257•d3vr•7h ago•105 comments

Robert Wilson has died

https://www.theartnewspaper.com/2025/08/01/robert-wilson-playwright-director-artist-obituary
34•paulpauper•3h ago•8 comments

Coffeematic PC – A coffee maker computer that pumps hot coffee to the CPU

https://www.dougmacdowell.com/coffeematic-pc.html
152•dougdude3339•8h ago•36 comments

Weather Model based on ADS-B

https://obrhubr.org/adsb-weather-model
127•surprisetalk•2d ago•20 comments

JavaScript retro sound effects generator

https://github.grumdrig.com/jsfxr/
38•selvan•3d ago•8 comments

The Rickover Corpus: A digital archive of Admiral Rickover's speeches and memos

https://rickovercorpus.org/
42•stmw•5h ago•9 comments

At 17, Hannah Cairo solved a major math mystery

https://www.quantamagazine.org/at-17-hannah-cairo-solved-a-major-math-mystery-20250801/
274•baruchel•13h ago•127 comments

Ethersync: Peer-to-peer collaborative editing of local text files

https://github.com/ethersync/ethersync
93•blinry•3d ago•10 comments

I couldn't submit a PR, so I got hired and fixed it myself

https://www.skeptrune.com/posts/doing-the-little-things/
218•skeptrune•13h ago•131 comments

Ask HN: Who is hiring? (August 2025)

171•whoishiring•15h ago•199 comments

Native Sparse Attention

https://aclanthology.org/2025.acl-long.1126/
102•CalmStorm•10h ago•12 comments

Does the Bitter Lesson Have Limits?

https://www.dbreunig.com/2025/08/01/does-the-bitter-lesson-have-limits.html
116•dbreunig•9h ago•62 comments

The tradeoff between human and AI context

https://softwaredoug.com/blog/2025/07/30/layers-of-ai-coding
15•softwaredoug•2d ago•0 comments

Researchers map where solar energy delivers the biggest climate payoff

https://www.rutgers.edu/news/researchers-map-where-solar-energy-delivers-biggest-climate-payoff
78•rbanffy•9h ago•42 comments

Anthropic revokes OpenAI's access to Claude

https://www.wired.com/story/anthropic-revokes-openais-access-to-claude/
173•minimaxir•8h ago•55 comments

Yearly Organiser

https://neatnik.net/calendar/
7•anewhnaccount2•3d ago•1 comments

Launch HN: Societies.io (YC W25) – AI simulations of your target audience

86•p-sharpe•17h ago•47 comments

Self-Signed JWTs

https://www.selfref.com/self-signed-jwts
97•danscan•11h ago•56 comments

Show HN: Draw a fish and watch it swim with the others

https://drawafish.com
823•hallak•4d ago•212 comments

Show HN: Print the daily weather forecast on a thermal receipt printer

https://github.com/chr15m/print-weather
10•chr15m•2d ago•4 comments

Twentyseven 1.0

https://blog.poisson.chat/posts/2025-08-01-twentyseven.html
30•082349872349872•7h ago•3 comments

Ask HN: Who wants to be hired? (August 2025)

76•whoishiring•15h ago•182 comments

Ergonomic keyboarding with the Svalboard: a half-year retrospective

https://twey.io/hci/svalboard/
93•Twey•13h ago•46 comments

Replacing tmux in my dev workflow

https://bower.sh/you-might-not-need-tmux
249•elashri•20h ago•280 comments

Google shifts goo.gl policy: Inactive links deactivated, active links preserved

https://blog.google/technology/developers/googl-link-shortening-update/
211•shuuji3•12h ago•156 comments

Make Your Own Backup System – Part 2: Forging the FreeBSD Backup Stronghold

https://it-notes.dragas.net/2025/07/29/make-your-own-backup-system-part-2-forging-the-freebsd-backup-stronghold/
97•todsacerdoti•3d ago•3 comments

Peak Energy just shipped the US's first grid-scale sodium-ion battery

https://electrek.co/2025/07/30/peak-energy-us-first-grid-scale-sodium-ion-battery/
52•breve•3h ago•8 comments

Show HN: TraceRoot – Open-source agentic debugging for distributed services

https://github.com/traceroot-ai/traceroot
33•xinweihe•13h ago•8 comments

Deep Agents

https://blog.langchain.com/deep-agents/
114•saikatsg•10h ago•36 comments