Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. San Francisco Onion Futures Company(onionfutures.com ↗)
    26comments
  2. Android 17 is the first since 3.x to add new APIs without releasing to the AOSP(grapheneos.social ↗)
    343comments
  3. SDCC – Small Device C Compiler(sourceforge.net ↗)
    9comments
  4. Science Is Open Software(jepedersen.dk ↗)
    17comments
  5. Typesafe-computer-use drives a Mac toward a goal for 1/50th of a cent per step(github.com/awlevin ↗)
    5comments
  6. Cloudflare Quick Tunnels(cloudflare.com ↗)
    271comments
  7. How OpenAI Used Its Own LLMs to Design Its Jalapeño Chip(ieee.org ↗)
    71comments
  8. Saving another 100TB of RAM(cloudflare.com ↗)
    58comments
  9. Why building a Rust LSP is hard(rust-glancer.github.io ↗)
    13comments
  10. How to Write with an LLM(sockpuppet.org ↗)
    306comments
  11. NASA-IBM Lunar Foundation open-Source Geospatial AI Model(usra.edu ↗)
    discuss
  12. Xcode 27.1 Beta Release Notes(developer.apple.com ↗)
    75comments
  13. Harm Laundering in GPT Models: Gender Discrimination Transformed Rather Than(arxiv.org ↗)
    discuss
  14. Goroutine Leak Profiles(go.dev ↗)
    1comments
  15. The first new cat species discovered in 100 years(nationalgeographic.com ↗)
    86comments
  16. Show HN: Cactus Needle 3: 8-29MB automation models can match DeepSeek V4 Flash(cactuscompute.com ↗)
    82comments
  17. Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug(ledger.com ↗)
    61comments
  18. OpenJev(openjev.com ↗)
    251comments
  19. The Farnese letter(simonklee.dk ↗)
    6comments
  20. You can run Git on object storage if you re-make packfiles(tigrisdata.com ↗)
    discuss
  21. Cache-to-Cache: Direct Semantic Communication Between LLMs (2025)(arxiv.org ↗)
    12comments
  22. Minimal Phone 2(minimalcompany.com ↗)
    200comments
  23. LispBM is a concurrent Lisp for microcontrollers with message passing(lispbm.com ↗)
    3comments
  24. Cyclomatic Complexity in C#(ndepend.com ↗)
    16comments
  25. Claude Code now reads AGENTS.md if there is no Claude.md(claude.com ↗)
    212comments
  26. Show HN: LiveWorld – Every 24/7 YouTube live camera on one globe(liveworld.info ↗)
    32comments
  27. Inside ZCode: Silently uploading your Git history to the cloud(ferstar.org ↗)
    96comments
  28. Warez: The Infrastructure and Aesthetics of Piracy (2021)(archive.org ↗)
    41comments
  29. Alibaba open-sources AI model that can detect cancer and nearly 150 conditions(scmp.com ↗)
    10comments
  30. How SpaceX streamlined the Raptor engine(construction-physics.com ↗)
    64comments

Popular GitHub Action tj-actions/changed-files is compromised

282 pointsby 1y agosemgrep.dev
4 comments
1y agoHN ↗

We've recently released open-source tools that would have easily prevented this, before anything runs or added to any pipeline:

1. The maintainers could have used PRevent to immediately alert and block any PR containing malicious code, or easily configured it for detection in case of a direct push: https://github.com/apiiro/PRevent

2. Users could have used our malicious code detection ruleset to immediately detect and block it when scanning updates in all relevant CI/CD stages: https://github.com/apiiro/malicious-code-ruleset

3. For a better understanding of the detection, the malicious code falls precisely into the patterns presented in our research: https://apiiro.com/blog/guard-your-codebase-practical-steps-...