HNHacker News
TopNewBestAskShowJobs

m4r71n

395 karma · joined December 11, 2013

submissionscomments
m4r71n··on Kenji/Serious Eats – 30-Min Pressure Cooker Pho Ga
In a similar vein, Chris Young has a fantastic video on making world class chicken stock in 60 minutes using a pressure cooker: https://youtube.com/watch?v=3k20zFlbFfE.
m4r71n··on PyTorch Lightning project quarantined by PyPI
Malicious versions are 2.6.2 and 2.6.3: https://socket.dev/blog/lightning-pypi-package-compromised
m4r71n··on Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
https://cooldowns.dev/#javascript-ecosystem ;-)
m4r71n··on Show HN: A context-aware permission guard for Claude Code
The entire permissions system feels like it's ripe for a DSL of some kind. Looking at the context implementation in src/nah/context.py and the way it hardcodes a ton of assumptions makes me think it will just be a maintenance nightmare to account for _all_ possible contexts and known commands. It would be nice to be able to express that __pycache__/ is not an important directory and can be deleted at will without having to encode that specific directory name (not that this projects hardcodes it, it's just an example to get to the point).
m4r71n··on Markdown CLI viewer with VI keybindings
The screenshot you added uses a transparent terminal where you can see your Discord chat in the background. You might want to remove that ;-)
m4r71n··on Agent Skills
That is being discussed in https://github.com/agentskills/agentskills/issues/15.
m4r71n··on Designing agentic loops
Ha, well look at that, not even a day later: https://fossa.com/blog/fossabot-dependency-upgrade-ai-agent/
m4r71n··on Designing agentic loops
I can imagine an agentic loop that updates dependencies à la Dependabot/Renovate-style by going through the changelog of a new version, reviewing new code changes, and evaluating whether it's worth it to upgrade (or even dangerous to do so, either from stability or security point of view). Too often these tools are used to blindly respin builds with the latest and greatest versions, which is what gets most people in trouble when their NPM deps become malicious.
m4r71n··on Kagi News
How would the LLM provider get any information about your reading habits from the app? The LLM is used _before_ the news content is served to you, the reader.
m4r71n··on The Theatre of Pull Requests and Code Review
I actually find the relevant PR/MR discussion a lot more useful than the commit messages themselves. So any git blame is just to get a commit hash and look that up in GitLab/GitHub to see the entire change set and any comments around it. It makes me wish those comments were bundled with the merge commit somehow and could easily be accessed in the terminal where I'm viewing the git history.
m4r71n··on Chrome's New AI Features
Not quite the same thing. Google's features seem to give the model the ability to control the browser, not just act upon the text within a given web page.
m4r71n··on Chrome's New AI Features
I tend to agree. If this was built as a true browser enhancement, it would allow you to select the model of your choice or even plug it into a locally running LLM. This being exclusive to Gemini just juices up their usage numbers to make their investments more justifiable. I wonder if Firefox will ever introduce any similar features.
m4r71n··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
Since so many vendors discovered these packages seemingly independently, you'd think that they would share those mechanisms with NPM itself so that those packages would never be published in the first place. But I guess that removes their ability to sell an "early alert" mechanism through their offerings...
m4r71n··on LLM Visualization
Karpathy walks through this visualization in https://www.youtube.com/watch?v=7xTGNNLPyMI, well worth a watch!
m4r71n··on PYX: The next step in Python packaging
What does GPU-aware mean in terms of a registry? Will `uv` inspect my local GPU spec and decide what the best set of packages would be to pull from Pyx?

Since this is a private, paid-for registry aimed at corporate clients, will there be an option to expose those registries externally as a public instance, but paid for by the company? That is, can I as a vendor pay for a Pyx registry for my own set of packages, and then provide that registry as an entrypoint for my customers?

m4r71n··on Claude Sonnet 4 now supports 1M tokens of context
How does this work under the hood? Does it build an in-memory vector database of the input sources and runs queries on top of that data to supplement the context window?
m4r71n··on Intermittent fasting strategies and their effects on body weight
Alternate day fasting normally means you eat up to 500 calories on your fasting day, but then eat more than usual on normal days. So on average if you eat 500 one day and 2500 another, that is no different than eating a restricted diet of 1500 every day. The finding here is that the former results in slightly more weight loss than the latter. That restrictions in calorie intake will result in weight loss is a given.
m4r71n··on Uv: Running a script with dependencies
Just better visibility into the dependencies that come with the script (exactly for things like vulnerability scanning that you mention). It's also easier for reproducibility in someone else's environment when I can give them the exact list of dependencies instead of having them resolve it themselves using the inline declarations. Explicit is better than implicit :-)
m4r71n··on Uv: Running a script with dependencies
Oh nice, I was already a happy user of the uv-specific shebang with in-script dependencies, but the `uv lock --script example.py` command to create a lock file that is specific to one script takes it to another level! Amazing how this feels so natural and yet only appeared after 20+ years of Python packaging.
m4r71n··on Understanding the PURL Specification (Package URL)
You can use the `oci` package type for non-Docker images (or any OCI artifacts for that matter).
m4r71n··on Ask HN: What is the best LLM for consumer grade hardware?
What is everyone using their local LLMs for primarily? Unless you have a beefy machine, you'll never approach the level of quality of proprietary models like Gemini or Claude, but I'm guessing these smaller models still have their use cases, just not sure what those are.
m4r71n··on CVE program faces swift end after DHS fails to renew contract
The title of this article is simply false. The CVE Program is a separate entity from MITRE and is most definitely not ending. The CVE Program has been acquiring assets from MITRE for years now. That is why the main site shifted from cve.mitre.org to cve.org. MITRE has always simply been the workhorse of the program, and now that is being shifted to others (CVE foundation, which has global representation).
m4r71n··on Busy Status Bar
Is the busy bar's 72x16 LED matrix for sale anywhere with the muted look that one could build something comparable?
m4r71n··on Busy Status Bar
This looks great! I've considered building a simple device with an LED matrix that looks similar to this, but could never figure out what gives the LEDs the muted look. All of the devices mentioned here (Tidbyt Gen2, Lamarca, Ulanzi, even the busy.bar) have it. Is the back-pannel just an LED matrix with a custom acrylic in front of it? How do they ensure the light from individual LEDs doesn't bleed into its neighbor?
m4r71n··on The end of the Red Hat security-announcements list
The RSS feed is open to public, so is the errata page on the Portal (https://access.redhat.com/errata-search/). Subscribing to email notifications requires some sort of account, just like the mailing list did.
m4r71n··on Trumpkin’s Notes on Building a Sauna
That's a common experience for sauna beginners. You may feel as if you're not getting enough air, that the hot air is difficult to breathe in, and your heart rate goes up dramatically. But! That's something you get used to fairly quickly, go 10-20 times for four 10-15 and I promise you'll feel much more relaxed once the body gets used to the hot environment.

I moved from Europe to southeast of US and (dry) saunas are pretty much unheard of here. I miss them very much! It was very relaxing to go for two hours once a week, especially in the winter when it was snowy outside and you could plunge into an icy lake right after coming out of the sauna.

m4r71n··on Python: Overlooked core functionalities
I would not recommend the default arguments hack. Any decent linter or IDE will flag that as an error and complain about the default argument being mutable (in fact, mutable default arguments are the target of many beginner-level interview questions). It's much easier to decorate a function with `functools.cache` to achieve the same result.
m4r71n··on Keeping Open Source Open
More work that has little effect on the actual upstream ecosystem beyond giving out something for free that 20k people at Red Hat are literally paid for. Ubuntu is not a clone of Debian, they extend it, tweak it, provide the code back to the community. What is the specific parts of the work that Rocky does that benefits the open-source community? What improvements has the community benefited from through your "work"?
m4r71n··on Keeping Open Source Open
> "Consequently, we now have to gather the source code from multiple sources, including CentOS Stream, pristine upstream packages, and RHEL SRPMs."

Oh no! How dare they make us do the work?

It feels tiring to hear these arguments that they must be provided with everything bundled neatly with no questions asked and no contributions to the actual upstreams.

m4r71n··on A response to the git.centos.org changes
So what's stopping Alma/Rocky from just "taking that same stuff other people wrote" and not bothering with RHEL at all?
Page 1 of 3Next →