Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. San Francisco Onion Futures Company(onionfutures.com ↗)
    41comments
  2. Android 17 is the first since 3.x to add new APIs without releasing to the AOSP(grapheneos.social ↗)
    359comments
  3. Human brain is two separate organs, Stanford Medicine-led research finds(stanford.edu ↗)
    2comments
  4. Typesafe-computer-use drives a Mac toward a goal for 1/50th of a cent per step(github.com/awlevin ↗)
    10comments
  5. SDCC – Small Device C Compiler(sourceforge.net ↗)
    13comments
  6. Science Is Open Software(jepedersen.dk ↗)
    24comments
  7. Cloudflare Quick Tunnels(cloudflare.com ↗)
    272comments
  8. How OpenAI Used Its Own LLMs to Design Its Jalapeño Chip(ieee.org ↗)
    74comments
  9. NASA-IBM Lunar Foundation open-Source Geospatial AI Model(usra.edu ↗)
    discuss
  10. Why building a Rust LSP is hard(rust-glancer.github.io ↗)
    18comments
  11. Saving another 100TB of RAM(cloudflare.com ↗)
    59comments
  12. How to Write with an LLM(sockpuppet.org ↗)
    311comments
  13. Goroutine Leak Profiles(go.dev ↗)
    2comments
  14. You can run Git on object storage if you re-make packfiles(tigrisdata.com ↗)
    3comments
  15. The first new cat species discovered in 100 years(nationalgeographic.com ↗)
    89comments
  16. Xcode 27.1 Beta Release Notes(developer.apple.com ↗)
    87comments
  17. Show HN: Cactus Needle 3: 8-29MB automation models can match DeepSeek V4 Flash(cactuscompute.com ↗)
    83comments
  18. OpenJev(openjev.com ↗)
    256comments
  19. Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug(ledger.com ↗)
    64comments
  20. The Farnese letter(simonklee.dk ↗)
    6comments
  21. Cache-to-Cache: Direct Semantic Communication Between LLMs (2025)(arxiv.org ↗)
    12comments
  22. Minimal Phone 2(minimalcompany.com ↗)
    207comments
  23. Cyclomatic Complexity in C#(ndepend.com ↗)
    17comments
  24. Claude Code now reads AGENTS.md if there is no Claude.md(claude.com ↗)
    217comments
  25. Inside ZCode: Silently uploading your Git history to the cloud(ferstar.org ↗)
    97comments
  26. LispBM is a concurrent Lisp for microcontrollers with message passing(lispbm.com ↗)
    3comments
  27. Warez: The Infrastructure and Aesthetics of Piracy (2021)(archive.org ↗)
    44comments
  28. Alibaba open-sources AI model that can detect cancer and nearly 150 conditions(scmp.com ↗)
    11comments
  29. How SpaceX streamlined the Raptor engine(construction-physics.com ↗)
    68comments
  30. The Implications of Linguistic Illegibility for LLM Security(arxiv.org ↗)
    26comments

Popular GitHub Action tj-actions/changed-files is compromised

282 pointsby 1y agosemgrep.dev
4 comments
1y agoHN ↗

We've recently released open-source tools that would have easily prevented this, before anything runs or added to any pipeline:

1. The maintainers could have used PRevent to immediately alert and block any PR containing malicious code, or easily configured it for detection in case of a direct push: https://github.com/apiiro/PRevent

2. Users could have used our malicious code detection ruleset to immediately detect and block it when scanning updates in all relevant CI/CD stages: https://github.com/apiiro/malicious-code-ruleset

3. For a better understanding of the detection, the malicious code falls precisely into the patterns presented in our research: https://apiiro.com/blog/guard-your-codebase-practical-steps-...