frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

GitLab scan finds 17,000 secrets in public repos, leading to $9000+ in bounties

https://trufflesecurity.com/blog/scanning-5-6-million-public-gitlab-repositories-for-secrets
10•adrianwaj•2h ago

Comments

vatsachak•27m ago
9000 in bounties for 17,000 secrets?

You could make as much in a month creating those vulnerabilities

3eb7988a1663•27m ago
The post keeps saying "verified secrets" - how are they verified? Did the author attempt to login to each service? Or does verified just means that it looks like a valid token?
jsiepkes•17m ago
> Each Lambda invocation executed a simple TruffleHog scan command with concurrency set to 1000. This setup allowed me to complete the scan of 5,600,000 repositories in just over 24 hours.

Gitlab must have been thrilled about a bot cloning 5.6 million repo's in 24 hours. That doesn't really sound responsible to me.

treyd•3m ago
That's 64 clones per second. That's quite a lot but it seems like something that a forge operating at the scale of GitHub can handle, especially if they were --depth=1 (which might have missed some secrets if someone was lazy about clearing their git history).

Pocketbase – open-source realtime back end in 1 file

https://pocketbase.io/
69•modinfo•2h ago•18 comments

TigerStyle: Coding philosophy focused on safety, performance, dev experience

https://tigerstyle.dev/
17•nateb2022•1h ago•4 comments

How Charles M Schulz created Charlie Brown and Snoopy (2024)

https://www.bbc.com/culture/article/20241205-how-charles-m-schulz-created-charlie-brown-and-snoopy
109•1659447091•6h ago•41 comments

Same-day upstream Linux support for Snapdragon 8 Elite Gen 5

https://www.qualcomm.com/developer/blog/2025/10/same-day-snapdragon-8-elite-gen-5-upstream-linux-...
375•mfilion•13h ago•179 comments

Vsora Jotunn-8 5nm European inference chip

https://vsora.com/products/jotunn-8/
60•rdg42•6h ago•13 comments

250MWh 'Sand Battery' to start construction in Finland

https://www.energy-storage.news/250mwh-sand-battery-to-start-construction-in-finland-for-both-hea...
208•doener•7h ago•95 comments

Physicists drive antihydrogen breakthrough at CERN

https://phys.org/news/2025-11-physicists-antihydrogen-breakthrough-cern-technique.html
163•naves•5d ago•45 comments

China's BEV Trucks and the End of Diesel's Dominance

https://cleantechnica.com/2025/11/26/chinas-bev-trucks-and-the-end-of-diesels-dominance/
63•xbmcuser•2h ago•29 comments

A programmer-friendly I/O abstraction over io_uring and kqueue (2022)

https://tigerbeetle.com/blog/2022-11-23-a-friendly-abstraction-over-iouring-and-kqueue/
60•enz•7h ago•19 comments

Quake Engine Indicators

https://fabiensanglard.net/quake_indicators/index.html
224•liquid_x•3d ago•48 comments

Maxduino Review: Tape Cassette Emulator for Multiple Retro Computers

https://retrogamecoders.com/maxduino-review/
29•ibobev•3d ago•0 comments

Feedback doesn't scale

https://another.rodeo/feedback/
144•ohjeez•1d ago•53 comments

Memories of .us

https://computer.rip/2025-11-11-dot-us.html
144•sabas_ge•1d ago•48 comments

Migrating to Positron, a next-generation data science IDE for Python and R

https://posit.co/blog/positron-migration-guides
9•ionychal•2h ago•4 comments

GitLab discovers widespread NPM supply chain attack

https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/
94•OuterVale•14h ago•36 comments

Experimenting with Robin Hood Hashing

https://twdev.blog/2025/11/robin_hood/
8•signa11•4d ago•1 comments

Indie, alone, and figuring it out

https://danijelavrzan.com/posts/2025/11/indie-dev/
57•wallflower•4d ago•7 comments

Tell HN: Happy Thanksgiving

646•prodigycorp•1d ago•160 comments

Installing Java in 2025, and Version Managers

https://blog.hakanserce.com/post/version_managers/
7•hakanserce•3d ago•2 comments

Implementing Bluetooth LE Audio and Auracast on Linux Systems

https://www.collabora.com/news-and-blog/blog/2025/11/24/implementing-bluetooth-le-audio-and-aurac...
8•losgehts•3d ago•0 comments

Giving the Jakks Atari Paddle a Spin

https://nicole.express/2025/paddle-me-atari.html
25•ingve•4d ago•0 comments

Underrated reasons to be thankful V

https://dynomight.net/thanks-5/
170•numeri•9h ago•76 comments

DeepSeekMath-V2: Towards Self-Verifiable Mathematical Reasoning [pdf]

https://github.com/deepseek-ai/DeepSeek-Math-V2/blob/main/DeepSeekMath_V2.pdf
170•fspeech•10h ago•36 comments

DIY NAS: 2026 Edition

https://blog.briancmoses.com/2025/11/diy-nas-2026-edition.html
416•sashk•1d ago•267 comments

TPUs vs. GPUs and why Google is positioned to win AI race in the long term

https://www.uncoveralpha.com/p/the-chip-made-for-the-ai-inference
326•vegasbrianc•16h ago•240 comments

Bird flu viruses are resistant to fever, making them a major threat to humans

https://medicalxpress.com/news/2025-11-bird-flu-viruses-resistant-fever.html
96•bikenaga•6h ago•79 comments

ML-KEM Mythbusting

https://keymaterial.net/2025/11/27/ml-kem-mythbusting/
17•durumcrustulum•6h ago•3 comments

Overlord: AI accountability that watches over you

https://overlord.app/
6•joshmit•4h ago•6 comments

Mixpanel Security Breach

https://mixpanel.com/blog/sms-security-incident/
226•jaredwiener•23h ago•108 comments

Coq: The World's Best Macro Assembler? (2013) [pdf]

https://nickbenton.name/coqasm.pdf
153•addaon•1d ago•67 comments