frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Open Source Security at Astral

https://astral.sh/blog/open-source-security-at-astral
85•vinhnx•2h ago

Comments

darkamaul•50m ago
With the recent incidents affecting Trivy and litellm, I find it extremely useful to have a guide on what to do to secure your release process.

The advices here are really solid and actionable, and I would suggest any team to read them, and implement them if possible.

The scary part with supply chain security is that we are only as secure as our dependencies, and if the platform you’re using has non secure defaults, the efforts to secure the full chain are that much higher.

sevg•29m ago
FYI it was actually William Woodruff (the article author) and his team at Trail of Bits that worked with PyPI to implement Trusted Publishing.
ChrisArchitect•19m ago
Earlier submission from author: https://news.ycombinator.com/item?id=47691466
raphinou•18m ago
One (amongst other) big problem with current software supply chain is that a lot of tools and dependencies are downloaded (eg from GitHub releases) without any validation that it was published by the expected author. That's why I'm working on an open source, auditable, accountless, self hostable, multi sig file authentication solution. The multi sig approach can protect against axios-like breaches. If this is of interest to you, take a look at https://asfaload.com/
darkamaul•9m ago
I’m maybe not understanding here, but isn’t it the point of release attestations (to authenticate that the release was produced by the authors)?

[0] https://docs.github.com/en/actions/how-tos/secure-your-work/...

LittleSnitch for Linux

https://obdev.at/products/littlesnitch-linux/index.html
457•pluc•5h ago•146 comments

Open Source Security at Astral

https://astral.sh/blog/open-source-security-at-astral
88•vinhnx•2h ago•6 comments

I ported Mac OS X to the Nintendo Wii

https://bryankeller.github.io/2026/04/08/porting-mac-os-x-nintendo-wii.html
1439•blkhp19•14h ago•245 comments

The Importance of Being Idle

https://theamericanscholar.org/the-importance-of-being-idle/
114•Caiero•2d ago•24 comments

USB for Software Developers: An introduction to writing userspace USB drivers

https://werwolv.net/posts/usb_for_sw_devs/
256•WerWolv•11h ago•31 comments

Understanding the Kalman filter with a simple radar example

https://kalmanfilter.net
299•alex_be•13h ago•38 comments

Six (and a half) intuitions for KL divergence

https://www.perfectlynormal.co.uk/blog-kl-divergence
57•jxmorris12•1d ago•4 comments

They're made out of meat (1991)

http://www.terrybisson.com/theyre-made-out-of-meat-2/
484•surprisetalk•19h ago•138 comments

Muse Spark: Scaling towards personal superintelligence

https://ai.meta.com/blog/introducing-muse-spark-msl/?_fb_noscript=1
318•chabons•14h ago•319 comments

Who is Satoshi Nakamoto? My quest to unmask Bitcoin's creator

https://www.nytimes.com/2026/04/08/business/bitcoin-satoshi-nakamoto-identity-adam-back.html
412•jfirebaugh•1d ago•395 comments

ML promises to be profoundly weird

https://aphyr.com/posts/411-the-future-of-everything-is-lies-i-guess
454•pabs3•17h ago•463 comments

Git commands I run before reading any code

https://piechowski.io/post/git-commands-before-reading-code/
1942•grepsedawk•21h ago•406 comments

Map Gesture Controls - Control maps with your hands

https://sanderdesnaijer.github.io/map-gesture-controls/
20•hebelehubele•4d ago•2 comments

MegaTrain: Full Precision Training of 100B+ Parameter LLMs on a Single GPU

https://arxiv.org/abs/2604.05091
285•chrsw•18h ago•51 comments

Expanding Swift's IDE Support

https://swift.org/blog/expanding-swift-ide-support/
103•frizlab•11h ago•44 comments

I imported the full Linux kernel git history into pgit

https://oseifert.ch/blog/linux-kernel-pgit
99•ImGajeed76•3d ago•13 comments

Show HN: A (marginally) useful x86-64 ELF executable in 301 bytes

https://github.com/meribold/btry
22•meribold•2d ago•6 comments

Haunted Paper Toys

http://ravensblight.com/papertoys.html
3•exvi•2d ago•0 comments

Understanding Traceroute

https://tech.stonecharioteer.com/posts/2026/traceroute/
115•stonecharioteer•3d ago•19 comments

Ask HN: Any interesting niche hobbies?

320•e-topy•3d ago•456 comments

John Deere to pay $99M in right-to-repair settlement

https://www.thedrive.com/news/john-deere-to-pay-99-million-in-monumental-right-to-repair-settlement
264•CharlesW•9h ago•67 comments

What does it mean to “write like you talk”?

https://arjunpanickssery.substack.com/p/what-does-it-mean-to-write-like-you
64•surprisetalk•2d ago•59 comments

Show HN: Is Hormuz open yet?

https://www.ishormuzopenyet.com/
346•anonfunction•8h ago•141 comments

Show HN: Orange Juice – Small UX improvements that make HN easier to read

http://oj-hn.com/
107•latchkey•12h ago•128 comments

I've been waiting over a month for Anthropic to respond to my billing issue

https://nickvecchioni.github.io/thoughts/2026/04/08/anthropic-support-doesnt-exist/
333•nickvec•12h ago•156 comments

Newly created Polymarket accounts win big on well-timed Iran ceasefire bets

https://www.theguardian.com/business/2026/apr/08/polymarket-trump-us-iran-ceasefire
108•mitchbob•5h ago•81 comments

Teardown of unreleased LG Rollable shows why rollable phones aren't a thing

https://arstechnica.com/gadgets/2026/04/teardown-of-unreleased-lg-rollable-shows-why-rollable-pho...
94•DamnInteresting•1d ago•40 comments

Claude Managed Agents Overview

https://platform.claude.com/docs/en/managed-agents/overview
15•NicoJuicy•6h ago•5 comments

Audio Reactive LED Strips Are Diabolically Hard

https://scottlawsonbc.com/post/audio-led
213•surprisetalk•1d ago•61 comments

US cities are axing Flock Safety surveillance technology

https://www.cnet.com/home/security/when-flock-comes-to-town-why-cities-are-axing-the-controversia...
684•giuliomagnifico•17h ago•396 comments