frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

We should all be using dependency cooldowns

https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
12•todsacerdoti•2h ago

Comments

elevation•1h ago
You could do a lot of this with CI if you scheduled a job to fetch the most recent packages once a month and record a manifest with the current versions, then, if no security issues are reported before the end of the cooldown period, run integration tests against the new manifest. If no tests fail, automatically merge this update into the project.

For projects with hundreds or thousands of active dependencies, the feed of security issues would be a real fire hose. You’d want to use an LLM to filter the security lists for relevance before bringing them to the attention of a developer.

It would be more efficient to centralize this capability as a service so that 5000 companies aren’t all paying for an LLM to analyze the same security reports. Perhaps it would be enough for someone to run a service like cooldown.pypi.org that served only the most vetted packages to everyone.

jayd16•12m ago
Doesn't this mean you're leaving yourself open to known vulnerabilities during that "cool down" time?
Havoc•11m ago
> we should all

Except if everyone does it chance of malicious things being spotted in source also drops by virtue of less eyeballs

Still helps though in cases where maintainer spot it etc

jcalvinowens•4m ago
I hate this. Delaying real bugfixes to achieve some nebulous poorly defined security benefit is just bad engineering.

FAWK: LLMs can write a language interpreter

https://martin.janiczek.cz/2025/11/21/fawk-llms-can-write-a-language-interpreter.html
148•todsacerdoti•6h ago•122 comments

Show HN: Wealthfolio 2.0- Open source investment tracker. Now Mobile and Docker

https://wealthfolio.app/?v=2.0
18•a-fadil•16m ago•2 comments

Olmo 3: Charting a path through the model flow to lead open-source AI

https://allenai.org/blog/olmo3
283•mseri•10h ago•77 comments

Making a Small RPG

https://jslegenddev.substack.com/p/making-a-small-rpg
52•ibobev•3h ago•16 comments

Building a Minimal Viable Armv7 Emulator from Scratch

https://xnacly.me/posts/2025/building-a-minimal-viable-armv7-emulator/
45•xnacly•3h ago•8 comments

It's hard to build an oscillator

https://lcamtuf.substack.com/p/its-hard-to-build-an-oscillator
159•chmaynard•9h ago•60 comments

Scientists now know that bees can process time, a first in insects

https://www.cnn.com/2025/11/12/science/bees-visual-stimulus-study-scli-intl
125•Brajeshwar•6d ago•53 comments

Nano Banana Pro

https://blog.google/technology/ai/nano-banana-pro/
1173•meetpateltech•1d ago•641 comments

My Favorite Math Problem

https://bytesauna.com/post/my-favorite-math-problem
22•mapehe•4d ago•10 comments

I converted a rotary phone into a meeting handset

https://www.stavros.io/posts/i-converted-a-rotary-phone-into-a-meeting-handset/
106•todsacerdoti•1w ago•52 comments

We should all be using dependency cooldowns

https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
13•todsacerdoti•2h ago•5 comments

Android and iPhone users can now share files, starting with the Pixel 10

https://blog.google/products/android/quick-share-airdrop/
786•abraham•23h ago•478 comments

Open Source and Local Code Mode MCP in Deno Sandboxes

https://portofcontext.com
59•pmkelly4444•1w ago•22 comments

XBMC 4.0 for the Original Xbox

https://www.xbox-scene.info/articles/announcing-xbmc-40-for-the-original-xbox-r64/
5•zdw•1h ago•1 comments

Roundtable (YC S23) Is Hiring Two Sales Development Representatives (SDRs)

https://www.ycombinator.com/companies/roundtable/jobs/irJTEsg-sales-development-representative
1•timshell•4h ago

WebAssembly from the Ground Up

https://wasmgroundup.com/
207•gurjeet•6d ago•46 comments

FEX-emu – Run x86 applications on ARM64 Linux devices

https://fex-emu.com/
248•open-paren•1w ago•102 comments

EXIF orientation info in PNGs isn't used for image-orientation: from-image

https://bugzilla.mozilla.org/show_bug.cgi?id=1627423
61•justin-reeves•3h ago•54 comments

Ancient Roman Glass Reveals a Hidden "Language"

https://nautil.us/ancient-roman-glass-reveals-a-hidden-language-1247932/
23•DrierCycle•6d ago•1 comments

How a French judge was digitally cut off by the USA

https://www.heise.de/en/news/How-a-French-judge-was-digitally-cut-off-by-the-USA-11087561.html
158•i-con•4h ago•160 comments

Over-regulation is doubling the cost

https://rein.pk/over-regulation-is-doubling-the-cost
291•bilsbie•17h ago•547 comments

Show HN: 32V TENS device from built from scratch under $100

https://littlemountainman.github.io/2025/11/17/tens/
53•autonomydriver•4d ago•11 comments

New OS aims to provide (some) compatibility with macOS

https://github.com/ravynsoft/ravynos
291•kasajian•20h ago•137 comments

The Qtile Window Manager: A Python-Powered Tiling Experience

https://tech.stonecharioteer.com/posts/2025/qtile-window-manager/
44•stonecharioteer•9h ago•17 comments

Is C++26 getting destructive move semantics?

https://stackoverflow.com/questions/79817124/is-c26-getting-destructive-move-semantics
16•signa11•1h ago•14 comments

Show HN: Search London StreetView panoramas by text

https://london.publicinsights.uk
7•dfworks•22h ago•7 comments

The New AI Consciousness Paper – By Scott Alexander

https://www.astralcodexten.com/p/the-new-ai-consciousness-paper
5•rbanffy•25m ago•0 comments

Hilbert space: Treating functions as vectors

https://eli.thegreenplace.net/2025/hilbert-space-treating-functions-as-vectors/
115•signa11•1w ago•44 comments

Data-at-Rest Encryption in DuckDB

https://duckdb.org/2025/11/19/encryption-in-duckdb
209•chmaynard•21h ago•24 comments

Okta's NextJS-0auth troubles

https://joshua.hu/ai-slop-okta-nextjs-0auth-security-vulnerability
349•ramimac•3d ago•135 comments