HNHacker News
TopNewBestAskShowJobs

lijunhao

577 karma · joined February 26, 2024

submissionscomments
lijunhao··on In one command use 500 open source tools
Thank you.

1. In its early development, `x-cmd` was designed to integrate its modules directly into the shell's namespace. This approach meant that common commands, such as `ping`, could potentially be overridden to run `x ping`, leading to conflicts and behavior. 2. Recognizing these potential issues, we decided to retain the `x` prefix for all `x-cmd` commands. This ensures clarity and prevents namespace pollution. The `x` is intentionally short and acts as a dedicated namespace for `x-cmd`'s features.

I think this will provide a kind of flexibility for our users. Users could try something new or interesting using x-cmd script. But if these sripts fail, users could alway return to the mature original command and finish the tasks.

Future versions of `x-cmd` will introduce a comprehensive cross-shell shortcut configuration system, empowering users to easily manage their personalized command shortcuts.

lijunhao··on In one command use 500 open source tools
1. X-CMD is a shell library. `install` and `pkg` are just one module in this shell library. X-CMD also uses shell scripting to enhance interaction with `pixi` and `asdf`, these work are also encapsulated into an invidual module.

2. All X-CMD code is hosted on the `main` branch. You can find direct links to each module's source code by browsing the modules section on our website: https://x-cmd.com/mod/env.

3. As a team based in China, we are continuously working to improve our English documentation. Our current priority is to first refine the Chinese documentation, which will then serve as the foundation for more accurate and comprehensive English translations.

4. All of the packages managed by x-cmd team, we collect them from developer official sources. Not maintained by third party contributors.

lijunhao··on Is anyone using the Gemini protocol (not Google's Gemini)
I'm curious if anyone is actively using it, and want to know more about use cases and advantage. Thank you.
lijunhao··on NextTrace: An open source visual route tracking CLI tool
nexttrace provide the geolocation information of IP in the output.

BTW, the author also enhance the nali project (nali-nt) to add geolocation information to mtr output.

mtr -n4 tj.189.cn | ./nali-nt_linux_amd64

https://github.com/nxtrace/nali

lijunhao··on NextTrace: An open source visual route tracking CLI tool
I understand your concern and have consulted with the author.

When using the Nextrace API for IP geolocation, Nextrace performs Proof-of-Work (PoW) authentication first. Therefore, the website counts only these authentication requests.

Consequently, the statistics do not include requests using other IP APIs.

lijunhao··on Show HN: Ping visualization in terminal with heatmap and barchart
Cross-platform shell scripts that enhance the `ping` command with visual output for Windows, macOS, and Linux.
lijunhao··on Network Lab in Container
Awesome ~

It seems containerlab use https://github.com/vrnetlab/vrnetlab, which is also a network lab based upon container technology.

I am wondering the diff between containerlab and vrnetlab ~

lijunhao··on Show HN: Fzf and Rg
I am not very familiar with rg. This is only an experiment. We will provide a shorter subcmd for --fzfapp later.
lijunhao··on All CVE Data in GitHub
cve v4: https://github.com/CVEProject/cvelist

cve v5: https://github.com/CVEProject/cvelistV5

lijunhao··on * Fzf + Man Tldr [video]
( man + tldr ) * fzf
lijunhao··on CVEDetails API
CVEs by vendor, product, version, CPE

CVE details

CVE information in NVD json format (e.g if you already have existing code which supports NVD json format)

CVSS scores for CVEs, including scores both from NVD and other sources

EPSS history for CVEs

Emerging CVEs

Data mentioning CVEs

Full-text search in CVE data

Open source vulnerabilities

Open source packages

Open source vulnerability details in OSSF format

Generic data listing and details: All data types in our database (e.g CVEs, OSV, web pages, advisories etc) in a common internal format Tags for any data entry

IP address search

Domain facets: Attack surface summary for your domain

Domain IP list: IP addresses attributed to your domain

IP CPE list: CPEs, products, discovered on a given list of IP addresses

Vendor, product, version search

Product information

lijunhao··on ICPP: Running C++ anywhere like a script
This is awesome.

I am wondering whether the linux version can run on alpine.

lijunhao··on Noto font: high-quality fonts for over 150 writing systems
Noto is a collection of high-quality fonts with multiple weights and widths in sans, serif, mono, and other styles. The Noto fonts are perfect for harmonious, aesthetic, and typographically correct global communication, in more than 1,000 languages and over 150 writing systems.

"Noto" means "I write, I mark, I note" in Latin. The name is also short for "no tofu", as the project aims to eliminate 'tofu': blank rectangles shown when no font is available for your text.

lijunhao··on Is Codeberg.org financially sustainable relying on member fees? Any precedents?
Thank you for sharing this information. I am also applying for membership and am eager to see Codeberg succeed.

However, I am concerned about the long-term sustainability of Codeberg, especially if it plans to support CI (which is resource-intensive) and attract a significantly larger user base.

Similarweb statistics indicate a substantial difference in traffic between Codeberg and GitHub. While Codeberg has approximately 2 million page views (700.8K visits * 2.78 pages/visits) per month, GitHub boasts over 2.7 billion (462.4M visits * 6 pages/visits). This translates to Codeberg having roughly 0.1% of GitHub's traffic.

If Codeberg aims to reach even 10% of GitHub's traffic, the operational costs would likely increase by a factor of 100 or much more ( almost certain ). Has Codeberg internally addressed this scalability challenge and outlined strategies for managing such growth? What are Codeberg's long-term goals in terms of user base and features, and how do they plan to balance these aspirations with sustainability?

Thank you.

lijunhao··on Is Codeberg.org financially sustainable relying on member fees? Any precedents?
Can Codeberg.org achieve long-term financial sustainability relying solely on member fees?

Are there any successful precedents for this model ?

lijunhao··on Decompress Anything with "X Uz"
X-CMD design philosophy is all about freedom to choose.

Take genact as example (see: https://www.x-cmd.com/install/genact).

1. X-cmd aggregates all known installation methods, sourced from the community and official documentation ( including apt, dnf, ... curl), and presents them in an interactive list.

2. It is the decision for the user to CHOOSE the installation method that best suits the situation. Whether it's apt, dnf, or any other method, x-cmd always puts user in control.

As a former operation engineer, I often encountered situations where installing a simple tool, like jq, on a client's server required unnecessary sudo privileges. Even worse, some software installations demanded extensive dependency upgrades, potentially destabilizing the entire system. To address this, I developed x-cmd/pkg, a tool management system that prioritizes portable tools.

This approach eliminates the need for the unecessary privileged access and minimizes the impact on the original system.

X-cmd also offers other methods for installing portable software from the community: like asdf, cosmo. It is all user's decision.

About the LLM, there won't be a code to eval without user's confirmation. X-CMD won't be a powerful framework like Langchain; it's just a simple command-line interface (CLI) that uses CURL.

Large language models (LLMs) may be used to generate commands, but no code will be executed without explicit user confirmation. User safety and control are top priorities.

We prioritize transparency by open-sourcing our code and providing best-effort documentation and demo.

When operating in the field, you're not executing opaque binary code, but rather human-readable POSIX shell scripts. This allows you to fully understand the actions being performed when necessary.

lijunhao··on CVE-2024-38355: socket.io Vulnerability
command to query CVE-2024-38355 in x-cmd shodan CLI

$ x shodan cve CVE-2024-38355

This is the result:

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. This issue is fixed by commit `15af22fc22` which has been included in `socket.io@4.6.2` (released in May 2023). The fix was backported in the 2.x branch as well with commit `d30630ba10`. Users are advised to upgrade. Users unable to upgrade may attach a listener for the "error" event to catch these errors.

lijunhao··on Decompress Anything with "X Uz"
silver bullet to defuse tar bomb: https://xkcd.com/1168/
lijunhao··on Good Joke – RFC 9564 – Faster Than Light Speed Protocol
I initially took it very seriously, which makes the joke even funnier in retrospect.
lijunhao··on UUIDv7 in 20 Languages
Thank you.

Now I am adding uuid-v7 to x-cmd as a feature.

lijunhao··on Show HN: Wikipedia in Terminal, with LLM
I am implementing a client to search Wikipedia using curl. Currently it can only download the extracts of the wikipage page.

However, it is still the finest source to feed LLM in terminal.

lijunhao··on European Alternatives
https://european-alternatives.eu/product/hetzner
lijunhao··on European Alternatives
https://european-alternatives.eu/about

---

Conditions for a listing

All the products and services listed on European Alternatives meet the following criteria:

The company is based in an EU, EEA, EFTA, or DCFTA member country.

If the company has a parent or holding company, this company is also based in an EU, EEA, EFTA, or DCFTA member state.

For hosting providers: It is not allowed that a hosting provider is simply a sub-hosting provider of a company that is not based in an EU or EFTA member country. Example: Hosting provider that just configures servers on AWS.

lijunhao··on European Alternatives
A list of search engines I haven't known before:

https://european-alternatives.eu/category/search-engines

lijunhao··on Ask HN: Terminal Only Code Env?
x-cmd contains a lot of modern shell and binary tools in terminal.

You can check it out. There is a lot of demos in the official website.

lijunhao··on SQLite-vss deprecated and its sucessor SQLite-vec
Thanks for the additional information.

I almost integrate sqlite-vss in x-cmd as default embedding service. Now I can do nothing but waiting for sqlite-vec.

lijunhao··on PaddleOCR: Multilingual OCR toolkits based on PaddlePaddle
There is English version of the document provided by the official.

https://github.com/PaddlePaddle/PaddleOCR/blob/main/README_e...

lijunhao··on Jornali – Build a memory wall for your startup
https://www.jornali.com/walls/near

Interesting project. I always want to build something like that.

lijunhao··on Bun vs. Node Benchmark – no one cares about speed as much as your CI does
While I appreciate Bun, I believe it could benefit from enhanced security and runtime monitoring capabilities.

Deno excels in these areas, offering a robust set of features that Bun and node could potentially adopt.

lijunhao··on Ask HN: Why my post labled FLAGGED and how to prevent it?
I think it would be more reasonable to judge whether it is promotion according to its content, quality, purpose, instead of domain name.

I totally agree one should get flagged if one posts the same product or application for the same use case again and again. But in my situation, they are different tools for different use cases.

I don't think this demo would get flagged if it was uploaded and presented in the https://asciinema.org or https://github.com .

I don't go against hackernews flagging system. It brings ORDER.

Sincere thanks to everyone for reviewing the cases.

Page 1 of 2Next →