frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

16 Best Practices for Reducing Dependabot Noise

https://nesbitt.io/2026/01/10/16-best-practices-for-reducing-dependabot-noise.html
15•zdw•5d ago

Comments

anishgupta•5d ago
Had fun reading this, pretty well written. >Consolidate into a monorepo lol this sounds like as if you make a dog tired by playing with it so it sleeps which you're gone :'D

>Contextualize the actual risk This is not as easy as it seems, for example reflection cases where runtime behavior affects a package usage. example: const lib = require(process.env.PARSER) lib.parse(userInput) could use a safe parser in production or a vulnerable one in another environment, but from a code level perspective there's no certainity which package is actually used

doodlesdev•1h ago

   > Modern languages like Zig, Gleam, and Roc offer genuine productivity benefits and attract top talent. As a bonus, their ecosystems are young enough that security tooling has not caught up yet. Dependabot will add support eventually, but until then you get the best of both worlds: a modern stack and a quiet PR queue.
How the hell is that actually a good thing? You might as well just use another language and disable Dependabot security updates if that's what you're looking for. Dependabot security updates aren't a liability, they're an asset in a world where developers use hundreds of dependencies daily, where every few months one of them is going to have a XSS or RCE vulnerability that has to be patched ASAP.

   > And if you are really concerned about a dependency’s security, you can always rewrite it yourself in Rust over a weekend.
That's not how it works. Honestly, this blog post gets me really worried about this developer's projects and clients.

   > Remove lockfiles from version control
What the fuck.
williamjackson•1h ago
Thank you for expressing my thoughts as well. The article seems to be full of contradictory “advice”.

Use a dependency cooldown, okay … but don’t commit your lockfile so you are always running the latest transitive deps? That’s nuts.

equinumerous•1h ago
The "> Remove lockfiles from version control" got me as well.

> Reproducible builds sound nice in theory, but velocity matters more than determinism. Think of it as chaos engineering for your dependency tree.

Reproducible builds are nice in practice, too. :) In the Node.js ecosystem, if you have enough dependencies, even obeying semver your dependencies will break your code. Pinning to specific versions is critical.

wirelesspotat•1h ago
I'm pretty sure the article is joking

> If the vulnerability were critical, someone would have merged it by now.

> GitHub Copilot can automatically suggest fixes for security vulnerabilities. Instead of updating to a patched version, let AI generate a workaround in your own code.

lanyard-textile•1h ago
I started to reevaluate the seriousness of this advice with the going to jail prompt. I probably should have caught on sooner :)
yunwal•5m ago
How did you reach "Set open-pull-requests-limit to zero" and not recognize this as satire?
torton•1h ago
Excellent troll post. I've had a good chuckle.
williamjackson•1h ago

    At sufficient scale, Dependabot’s analysis will time out before completing, effectively rate-limiting the number of PRs it can generate. This natural throttling prevents notification fatigue while maintaining the appearance of active security tooling.
Am I being trolled?
lanyard-textile•1h ago
Denial: "These dependabot MRs aren't even fixing real security issues, these do not exist in the wild."

Bargaining: "Okay we'll fix them but we'll do it on a schedule, so that it doesn't interrupt sprints."

Anger: "Okay let's just yoink the package lock file how about that?"

Depression: [skip ci]

Acceptance: "So apparently copilot can do this..."

Earth is warming faster. Scientists are closing in on why

https://www.economist.com/science-and-technology/2024/12/16/earth-is-warming-faster-scientists-ar...
52•andsoitis•1h ago•11 comments

ASCII characters are not pixels: a deep dive into ASCII rendering

https://alexharri.com/blog/ascii-rendering
514•alexharri•7h ago•63 comments

We Put Claude Code in Rollercoaster Tycoon

https://labs.ramp.com/rct
173•iamwil•5d ago•86 comments

2025 was the third hottest year on record

https://www.economist.com/science-and-technology/2026/01/14/2025-was-the-third-hottest-year-on-re...
84•andsoitis•1h ago•54 comments

Why There's No Single Best Way to Store Information

https://www.quantamagazine.org/why-theres-no-single-best-way-to-store-information-20260116/
29•7777777phil•2h ago•7 comments

Show HN: What if your menu bar was a keyboard-controlled command center?

https://extrabar.app/
25•pugdogdev•1h ago•9 comments

Counterfactual evaluation for recommendation systems

https://eugeneyan.com/writing/counterfactual-evaluation/
25•kurinikku•13h ago•0 comments

An Elizabethan mansion's secrets for staying warm

https://www.bbc.com/future/article/20260116-an-elizabethan-mansions-secrets-for-staying-warm
25•Tachyooon•1h ago•34 comments

The 600-year-old origins of the word 'hello'

https://www.bbc.com/culture/article/20260113-hello-hiya-aloha-what-our-greetings-reveal
75•1659447091•6h ago•38 comments

The Dilbert Afterlife

https://www.astralcodexten.com/p/the-dilbert-afterlife
313•rendall•1d ago•199 comments

East Germany balloon escape

https://en.wikipedia.org/wiki/East_Germany_balloon_escape
630•robertvc•1d ago•266 comments

M8SBC-486 (Homebrew 486 computer)

https://maniek86.xyz/projects/m8sbc_486.php
17•rasz•5d ago•1 comments

ClickHouse acquires Langfuse

https://langfuse.com/blog/joining-clickhouse
161•tin7in•9h ago•70 comments

Map To Poster – Create Art of your favourite city

https://github.com/originalankur/maptoposter
153•originalankur•8h ago•49 comments

16 Best Practices for Reducing Dependabot Noise

https://nesbitt.io/2026/01/10/16-best-practices-for-reducing-dependabot-noise.html
15•zdw•5d ago•10 comments

Show HN: Streaming gigabyte medical images from S3 without downloading them

https://github.com/PABannier/WSIStreamer
108•el_pa_b•10h ago•39 comments

The Resonant Computing Manifesto

https://resonantcomputing.org/
21•sinak•2h ago•5 comments

The Olivetti Company – By Bradford Morgan White

https://www.abortretry.fail/p/the-olivetti-company
6•rbanffy•6d ago•2 comments

US electricity demand surged in 2025 – solar handled 61% of it

https://electrek.co/2026/01/16/us-electricity-demand-surged-in-2025-solar-handled-61-percent/
269•doener•8h ago•239 comments

Cloudflare acquires Astro

https://astro.build/blog/joining-cloudflare/
909•todotask2•1d ago•378 comments

The 'untouchable hacker god' behind Finland's biggest crime

https://www.theguardian.com/technology/2026/jan/17/vastaamo-hack-finland-therapy-notes
113•c420•11h ago•112 comments

Cursor's latest “browser experiment” implied success without evidence

https://embedding-shapes.github.io/cursor-implied-success-without-evidence/
658•embedding-shape•1d ago•287 comments

High-Level Is the Goal

https://bvisness.me/high-level/
214•tobr•2d ago•102 comments

6-Day and IP Address Certificates Are Generally Available

https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability
459•jaas•1d ago•252 comments

Italy investigates Activision Blizzard for pushing in-game purchases

https://techcrunch.com/2026/01/16/italy-investigates-activision-blizzard-for-pushing-in-game-purc...
76•7777777phil•5h ago•30 comments

Show HN: I built a tool to assist AI agents to know when a PR is good to go

https://dsifry.github.io/goodtogo/
11•dsifry•8h ago•9 comments

FLUX.2 [Klein]: Towards Interactive Visual Intelligence

https://bfl.ai/blog/flux2-klein-towards-interactive-visual-intelligence
198•GaggiX•19h ago•54 comments

PCs refuse to shut down after Microsoft patch

https://www.theregister.com/2026/01/16/patch_tuesday_secure_launch_bug_no_shutdown/
168•smurda•7h ago•187 comments

Architecture for Disposable Systems

https://tuananh.net/2026/01/15/architecture-for-disposable-systems/
46•tuananh•7h ago•26 comments

LLM Structured Outputs Handbook

https://nanonets.com/cookbooks/structured-llm-outputs
331•vitaelabitur•2d ago•57 comments