frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

The Paranoid Guide to Running Copilot CLI in a Secure Docker Sandbox

https://gordonbeeming.com/blog/2025-10-03/taming-the-ai-my-paranoid-guide-to-running-copilot-cli-in-a-secure-docker-sandbox
18•pploug•6d ago

Comments

jaytaylor•2h ago
This is a really neat project .

At my company (StrongDM) we recently open-sourced a tool in this space called Leash: https://github.com/strongdm/leash

By default it runs in docker, and also includes an extra sophisticated macOS-native --darwin mode which goes beyond the capabilities and guarantees of the likes of sandbox-exe, bubblewrap, and in some ways docker. Leash provides visibility into and control over every command and network request attempted by the coder agent. Would appreciate any feedback, and will try to get in touch with the author (Gordon).

Now I'll definitely look into automatically supporting pass-through auth for at least gh cli in Leash - always looking for what folks will find useful.

corv•1h ago
Interesting! The sandboxing space definitely deserves more attention.

On the other side of the spectrum, we're working on a lightweight approach that augments user namespaces with libseccomp to filter syscalls via BPF.

https://github.com/corv89/shannot

codazoda•1h ago
I built a similar container when working on a CTF that didn’t exclude the use of AI tools.

https://github.com/codazoda/llm-jail

High-performance 2D graphics rendering on the CPU using sparse strips [pdf]

https://github.com/LaurenzV/master-thesis/blob/main/main.pdf
168•PaulHoule•6h ago•20 comments

Unexpected things that are people

https://bengoldhaber.substack.com/p/unexpected-things-that-are-people
493•lindowe•12h ago•238 comments

The 'Toy Story' You Remember

https://animationobsessive.substack.com/p/the-toy-story-you-remember
8•ani_obsessive•55m ago•0 comments

Unix v4 Tape Found

https://discuss.systems/@ricci/115504720054699983
246•greatquux•4d ago•34 comments

Toucan Wireless Split Keyboard with Touchpad

https://shop.beekeeb.com/products/toucan-wireless-piantor-wireless-split-keyboard-with-touchpad
49•tortilla•3h ago•35 comments

The lazy Git UI you didn't know you need

https://www.bwplotka.dev/2025/lazygit/
252•linhns•10h ago•106 comments

Writing your own BEAM

https://martin.janiczek.cz/2025/11/09/writing-your-own-beam.html
173•cbzbc•1d ago•44 comments

Time to start de-Appling

https://heatherburns.tech/2025/11/10/time-to-start-de-appling/
337•msangi•13h ago•235 comments

When Soviet-Made Cars Roamed Singapore Roads

https://remembersingapore.org/2025/10/30/soviet-made-cars-singapore-70s-to-90s/
9•sohkamyung•6d ago•0 comments

Spatial intelligence is AI’s next frontier

https://drfeifei.substack.com/p/from-words-to-worlds-spatial-intelligence
150•mkirchner•7h ago•72 comments

Dependent types and how to get rid of them

https://chadnauseam.com/coding/pltd/are-dependent-types-actually-erased
67•pie_flavor•1w ago•32 comments

DEC Mini – computer inspired by one of the loveliest retro computers of the 80s

https://decmini.tin.cat/
4•pabs3•47m ago•0 comments

Using Generative AI in Content Production

https://partnerhelp.netflixstudios.com/hc/en-us/articles/43393929218323-Using-Generative-AI-in-Co...
108•CaRDiaK•8h ago•79 comments

I hate screenshots of text

https://parkscomputing.com/page/i-hate-screenshots-of-text
172•paulmooreparks•2h ago•103 comments

The physics of news, rumors, and opinions

https://arxiv.org/abs/2510.15053
37•Anon84•6d ago•14 comments

Warren Buffett's final shareholder letter [pdf]

https://berkshirehathaway.com/news/nov1025.pdf
133•philip1209•3h ago•32 comments

The Paranoid Guide to Running Copilot CLI in a Secure Docker Sandbox

https://gordonbeeming.com/blog/2025-10-03/taming-the-ai-my-paranoid-guide-to-running-copilot-cli-...
18•pploug•6d ago•3 comments

Launch HN: Hypercubic (YC F25) – AI for COBOL and Mainframes

80•sai18•11h ago•49 comments

Omnilingual ASR: Advancing automatic speech recognition for 1600 languages

https://ai.meta.com/blog/omnilingual-asr-advancing-automatic-speech-recognition/?_fb_noscript=1
92•jean-•10h ago•17 comments

Head in the Zed Cloud

https://maxdeviant.com/posts/2025/head-in-the-zed-cloud/
82•todsacerdoti•13h ago•18 comments

How to create accessible PDFs from the start

https://typst.app/blog/2025/accessible-pdf/
26•leephillips•1w ago•0 comments

Linux in a Pixel Shader – A RISC-V Emulator for VRChat

https://blog.pimaker.at/texts/rvc1/
43•rbanffy•6h ago•12 comments

Building a high-performance ticketing system with TigerBeetle

https://renerocks.ai/blog/2025-11-02--tigerfans/
102•jorangreef•3d ago•17 comments

Zeroing in on Zero-Point Motion Inside a Crystal

https://physics.aps.org/articles/v18/178
36•lc0_stein•6h ago•6 comments

Error ABI

https://matklad.github.io/2025/11/09/error-ABI.html
78•todsacerdoti•1d ago•30 comments

Benchmarking leading AI agents against Google reCAPTCHA v2

https://research.roundtable.ai/captcha-benchmarking/
100•mdahardy•11h ago•75 comments

Memory Safety for Skeptics

https://queue.acm.org/detail.cfm?id=3773095
60•steveklabnik•9h ago•74 comments

What caused performance issues in my tiny RPG

https://jslegenddev.substack.com/p/what-caused-performance-issues-in
19•ibobev•4h ago•11 comments

Vibe Code Warning – A personal casestudy

https://github.com/jackdoe/pico2-swd-riscv
239•jackdoe•16h ago•173 comments

Pose Animator – An open source tool to bring SVG characters to life (2020)

https://blog.tensorflow.org/2020/05/pose-animator-open-source-tool-to-bring-svg-characters-to-lif...
149•jerlendds•6d ago•16 comments