Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Jeff – Jev-compatible 0.8B decision models, trained at home, ~30 ms (github.com/firelex)
    136comments
  2. U.S. Strategic Petroleum Reserve Falls to Lowest Level Since 1982 (oilprice.com)
    33comments
  3. Pirating the Pirates (mubi.com)
    235comments
  4. 1996 chat room simulator connected to Win95 and System 7 web desktops (lolchat.rip)
    28comments
  5. MicroLLM Lab – Try 7 tiny LLM's in the browser (stateofutopia.com)
    66comments
  6. 12,000-year-old Göbeklitepe burials explain scattered bones (archaeologymag.com)
    25comments
  7. Tank Body Problem (jimsitu.com)
    7comments
  8. California farmers are struggling to sell grapes as demand for wine drops (kqed.org)
    231comments
  9. Scientists solve 1840s space weather mystery (arstechnica.com)
    39comments
  10. Sonnet 5.5 (anthropic.com)
    432comments
  11. ESP32S3 cluster running 1.58-bit (BitNet) Language model (github.com/low-zi-hong)
    5comments
  12. Hijacking the PS5's RTMP stream (yashgarg.dev)
    67comments
  13. World Labs Is Joining AMD (worldlabs.ai)
    83comments
  14. How to win a beer with high-dimensional statistics (jamiesimon.io)
    3comments
  15. Kids turned low-traffic NPR Spotify comments into a secret group chat (thisamericanlife.org)
    188comments
  16. The Art Forger Who Became a National Hero (priceonomics.com)
    2comments
  17. What is the best shape of a city? Modelling effect of urban form on distance (sagepub.com)
    11comments
  18. Bluegraph – Explore NOAA buoy data, rebuilt in 3D from measured spectra (bluegraph.io)
    2comments
  19. Does Reddit have an astroturfing problem? What the data suggests (petervijeh.com)
    166comments
  20. Updated Google Maps shows destruction of the city of Rafah (twitter.com/aliabunimah)
    155comments
  21. It's Time to Investigate the AI Labs (calnewport.com)
    132comments
  22. Nvidia wants to put a watchdog chip next to every AI agent (cnbc.com)
    154comments
  23. Show HN: HN.watch – Videos of all Hacker News posts (hn.watch)
    84comments
  24. What reversing, modernising old games tells us about the economic impact of AI (isfine.org)
    30comments
  25. Cf: The Agentic CLI for the Cloudflare API (cloudflare.com)
    56comments
  26. Behold the pawpaw (cbc.ca)
    23comments
  27. Show HN: Destroy Any Website with Stickman (spritefusion.com)
    28comments
  28. Blend and Haul: Fertilizer Blending Simulator (wedgworth.com)
    2comments
  29. Coding is not solved (alexewerlof.com)
    457comments
  30. Profit Margins of the Largest Companies (visualcapitalist.com)
    —discuss

Aura – Python source code auditing and static analysis on a large scale (2022)

148 pointsby 3y agogithub.com
13 comments
3y agoHN ↗

Unfortunately, there hasn't been a release since 2021, Similarly no commits to the branches master, or dev in the past ~14 months.

3y agoHN ↗

Hello, author of Aura here. The project is in fact active! But in a different branch called "ambience". Which is a very big refactor into transforming Aura (which is now designed to be run locally as tui) into server/web application. It would allow to automatically monitor and audit all used python packages in an organization by using an http reverse proxy to intercept python package installations. It's taking me currently long time to finish that big refactor as I am currently the only active developer there so apologies if the project seems to be abandoned, I'm just hesitating to merge the changes from ambience branch into main (which is what people see) as the new refactor is not stable yet as compared to master & dev as that was tested and tuned on the whole PyPI.

Very early alpha version is available here: https://ambience.sourcecode.ai if someone is interested in checking it out.

3y agoHN ↗

Will a command-line tool still be provided too?

3y agoHN ↗

I second this question. While server versions are nice, I need command line, local-only versions to use for my code review as I can’t pass code and dependencies to third parties.

3y agoHN ↗

Yes, command line version will be always available, this is just an additional mode built on top of it, it's using in fact the same API interface as CLI version to spawn scans and parses out the JSON output format into persistent DB with some postprocessing to be more suitable for web app.

3y agoHN ↗

SARIF is implemented as a separate output format and is supported. the "json" one contains more information such as taint traces (even unconfirmed ones that haven't reached sinks), anomaly tags, static behaviour etc... main json format is intended to capture as much data as possible so it can be analyzed later as the original intention is to hunt for malware, anomalies and doing research in general on top of the whole PyPI repository. I found SARIF to be more "practical" or actionable in terms of what needs to be done in fixing the source code or vulnerabilities found vs research oriented such as "this piece of code is doing network communication". Due to this differences it was added as a separate format which is a subset and reformatted (to the SARIF standard) "json" output format

3y agoHN ↗

very helpful comment, you might want to add that to the readme or a pinned issue

3y agoHN ↗

Thank you for the suggestion, that is indeed a good idea. I will modify the README to include some explanation about the current status and why the main & dev branches may seem to be stale

3y agoHN ↗

I haven't used pulp so I am not sure but yes in theory. Several schemes are currently supported via URIs (pypi://, git://, http(s):// etc...) so if the destination to scan can be formatted as one of the already supported URI schemes then you can already scan it. URI providers are also using plugin architecture so adding a new one for better integration with pulp (such as autodiscovering packages) should be trivial. Thank you for the suggestion, the pulp project looks interesting and I would definitely check it out!

3y agoHN ↗

Gitea can also (scan and build and test and) host python packages [1], conda packages [2], container images, etc.

[1] https://docs.gitea.io/en-us/usage/packages/pypi/

[2] https://docs.gitea.io/en-us/usage/packages/conda/

https:// URLs probably already solve for scanning Python packages hosted by Gitea and/or Pulp with Aura.

From https://news.ycombinator.com/item?id=33563857 :

Additional lists of static analysis, dynamic analysis, SAST, DAST, and other source code analysis tools: https://news.ycombinator.com/item?id=24511280 https://analysis-tools.dev/tools?languages=python