HNHacker News
TopNewBestAskShowJobs

prdonahue

949 karma · joined October 5, 2015

SVP, Head of Product @Chainguard_dev

Previously: VP, Product @Cloudflare; CPTO, Aurora Solar

DMs open on Twitter (@prdonahue)

submissionscomments
prdonahue··on Incident with Github.com
What are some good SaaS alternatives to GitHub for CI (that aren't GitLab)? Is anyone doing anything particularly novel in this space?
prdonahue··on Buyer cancels showing after Deflock shows two cameras utilized by the HOA
What would you have done if they said no?
prdonahue··on Ask HN: Who is hiring? (August 2026)
Chainguard | Product Manager, Scanner | REMOTE | Full-Time | https://www.chainguard.dev/

Chainguard is the trusted source for open source. We build hardened, minimal, continuously-updated images, libraries, and packages that eliminate vulnerabilities before they ship — used by teams at Anduril, Canva, OpenAI, Snap, and Snowflake, among others.

We're hiring a PM to own the malware and greyware scanning engine inside Chainguard Repository — the system that analyzes source code, build behavior, and maintainer activity across the open source packages flowing through our platform to catch compromised or malicious artifacts before they reach a customer's environment. You'd own the roadmap for detection coverage, scanner accuracy (precision/recall trade-offs are the daily grind), and how findings get surfaced to security teams and translated into policy enforcement. Close partnership with our detection engineering and threat research teams, and with customers who are increasingly asking "how do you know this package is safe?"

Good fit if you've done PM work on a detection, fraud, spam, or security scanning system before, are comfortable being hands-on with data and false-positive/false-negative trade-offs, and want to work on a problem that's getting more urgent as AI agents pull in more open source dependencies automatically.

JD to be posted imminently but email me if interested and I'll route appropriately: patrick@chainguard.dev

prdonahue··on I used Claude Code to get a second opinion on my MRI
They're used quite a bit for nerve entrapment—both in diagnosing and treating.
prdonahue··on Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
> Anyone know of a better way to protect yourself than setting a min release age on npm/pnpm/yarn/bun/uv (and anything else that supports it)?

Most of these attacks don't make it into the upstream source, so solutions[1] that build from source get you ~98% of the way there. If you can't get a from-source build vs. pulling directly from the registries, can reduce risk somewhat with a cooldown period.

For the long tail of stuff that makes it into GitHub, you need to do some combination of heuristics on the commits/maintainers and AI-driven analysis of the code change itself. Typically run that and then flag for human review.

[1] Here's the only one I know that builds everything from source: https://www.chainguard.dev/libraries

(Disclaimer: I work there.)

prdonahue··on Claude Code to be removed from Anthropic's Pro plan?
Hmm, we just bought my wife an annual subscription at the Pro tier, largely to use Claude Code. Wonder if she'd be grandfathered in or if we'll need to get a refund.
prdonahue··on Google restricting Google AI Pro/Ultra subscribers for using OpenClaw
Isn't this sort of repeated communication gaffe why they hired @OfficialLoganK?
prdonahue··on CURL's Daniel Stenberg: AI slop is DDoSing open source
Do any of the bug bounty programs let you filter by some scoring of the source reporter?

Seems like it’d be helpful to bury mass reporters in a de facto spam bucket (where “mass” is some absolute quantity of reports along with percent that are accepted).

prdonahue··on AI is killing B2B SaaS
I stopped reading the article because of it.
prdonahue··on Cloudflare outage on December 5, 2025
And you moved at a glacial pace compared to Cloudflare. There are tradeoffs.
prdonahue··on Ask HN: What alternatives to Docker Desktop are people using?
Nice, are you collaborating with developers at your company? Or is this more for personal use?
prdonahue··on Ask HN: Who is hiring? (December 2025)
Chainguard | Senior and Staff-level Product Managers and Engineers, and Engineering Managers | REMOTE (US/CAN)

We're building the safe, trusted source for open source. We created the secure Container Image market and we've recently expanded into VMs and Libraries for popular language ecosystems such as JavaScript, Python, and Java.

We're hiring quite a few PMs and engineers for our Containers and Libraries products, amongst other roles. Check out the listings here https://www.chainguard.dev/careers and if you're a highly-technical PM that wants to SHIP email me directly at patrick at chainguard dot dev.

prdonahue··on crates.io: Malicious crates faster_log and async_println
It's the same principle as a company blocking access to domains registered in the past 30 days. Doing so eliminates a huge percent of phishing/malware as these domains are typically identified and taken down otherwise blocked in that window.

In this particular case, the bogus libraries had been out there for months. But if in addition to a delay, you mirror just the most common subset of packages with some opinionated selection criteria and build directly from source, you eliminate most of these attacks. (The same is true across whatever language ecosystems, including JS as you mention npm, etc.)

Is this 100% infallible? No, but security is a risk reduction game.

prdonahue··on crates.io: Malicious crates faster_log and async_println
We're taking a very different[1] approach at Chainguard.

Essentially: building the world from GitHub repos on SLSA L2 hardened infra and delivering directly to our customers to bypass the registry threat vector (which is where vast, vast majority of attacks occur—we'll be blogging about this soon with more data).

[1] https://www.chainguard.dev/unchained/announcing-chainguard-l...

prdonahue··on Oracle attempt to hide cybersecurity incident from customers?
Yeah, they've clearly been given some minimal company line and aren't deviating from it. Not going to win any trust.
prdonahue··on Oracle attempt to hide cybersecurity incident from customers?
We're primarily an AWS shop but some Oracle BDR assigned to cover us recently reached out on LinkedIn.

I asked for an incident report and received this terse response:

> There has been no breach of Oracle Cloud. The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data.

prdonahue··on Next.js version 15.2.3 has been released to address a security vulnerability
Vibe security.
prdonahue··on OpenAI Audio Models
Do you have any affiliation with Elevenlabs?
prdonahue··on Six day and IP address certificate options in 2025
This was a fun conversation.

I remember calling Clint and Jeremy at DigiCert and asking: "hey we have this cool IP address—what are the odds you guys can issue a certificate for it?"

I'm not sure if they had to dust off some code or process to do it, but they got it done really quickly once the demonstration of control was handled.

prdonahue··on Satellite powered estimation of global solar potential
Was that paired with a battery? Under NEM3 (and reduced net metering rate), it doesn't make sense to install PV in California without a battery.
prdonahue··on Show HN: Jelly – A simpler shared inbox for small teams
What do you think is a fair price? (It seems quite reasonable to me.)
prdonahue··on Notion's mid-life crisis
Notion was clearly made by people who do not use or understand keyboard shortcuts; you can't even properly select text without using the mouse.

It's been somewhat maddening switching from Confluence.

prdonahue··on Can solar costs keep shrinking?
I did a system earlier this year with My Generation Energy, coincidentally while I was interviewing for the CPO role at Aurora Solar (where I am now).

Highly recommend MGE if you’re in the Cape Cod area. Not sure how far off Cape they’ll go if not.

prdonahue··on Cloudflare Introduces Automatic SSL/TLS
You’re misunderstanding. LE went GA in April 2016 and Cloudflare is talking about ~2 years prior to that (where they used GlobalSign and Comodo, not LE).
prdonahue··on Ask HN: Do you have home solar?
I do, feel free to DM on Twitter. Just pull an 18 kW system in a few months ago and it’s been great.

(Full disclosure: I’m in the solar industry, but on the software side. Recently left Cloudflare to join Aurora Solar as CPO.)

prdonahue··on Chimpanzees 'self-medicate' with healing plants
And some have pro-inflammatory properties.
prdonahue··on US home sale fees set to fall after real estate group settles lawsuits
The problem is, like with financial advisors, it’s nearly impossible to reliably discern the good agents from the bad. And most are bad as the market is flooded with charlatans who market themselves relentlessly.

If you disagree, what’s a reliable way to identify the great agents?

prdonahue··on Walmart, Delta, and Starbucks are using AI to monitor employee messages
If Delta's "AI" support they force you through (even as Diamond Medallion) before you can chat with a representative is an indication of their competency, this monitoring is doomed.
prdonahue··on Ford EV Drivers Will Get Free Tesla Supercharger Adapters
I’m not sure they’d be doing this if Ford EVs were flying off the lot (they’re not).
prdonahue··on Oreo Cookie Treatment Lowers LDL Cholesterol More Than High-Intensity Statins
Curious why you are considering dropping the statin? Are you having side effects, e.g., muscle soreness, or is ezetimibe alone enough to push your ApoB below 60 mg/dL?
Page 1 of 9Next →