Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
orkj
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
Closing Composer's Download Fallback Paths in Private Packagist
(blog.packagist.com)
2 points
by
orkj
4mo ago
|
0 comments
2.
▲
Malicious Checkmarx Artifacts Found in Official KICS Docker Repo and Code Ext
(socket.dev)
3 points
by
orkj
5mo ago
|
0 comments
3.
▲
React2Shell (CVE-2025-55182/CVE-2025-66478)
(react2shell.com)
12 points
by
orkj
10mo ago
|
3 comments
4.
▲
by
orkj
10mo ago
From the reporter of the React vulnerablility, Lachlan Davidson
5.
▲
by
orkj
10mo ago
very interesting to read. However, if I am reading this correctly, your PoC falls in the category described here: https://react2shell.com/ > Anything that requires the developer to have explicitly exposed dangerous funct
6.
▲
by
orkj
1y ago
> what is an auth description? They are probably referring to the text in the basic auth "pop-up" which is usually set like WWW-Authenticate: Basic realm="my text"
7.
▲
by
orkj
1y ago
Did you see this one? https://www.casio.com/europe/watches/casio/vintage/product.A...
8.
▲
by
orkj
1y ago
This sounds like a great idea for a feature for the OP. Cool feature to kickstart the database. Take a photo. Something something AI. 150 rows filled in
9.
▲
by
orkj
1y ago
Seems like general good advice, but for me it was simply a matter of `atuin import auto`. The initial response was similar (as in, here is no history, where is my history, this is useless). Then I read this page where it said to import, whi
10.
▲
by
orkj
2y ago
The description of the repo is "A compendium of absurd "open-source" licenses." Which I think is relevant to change the title to (the addition of the word "absurd" specifically. The word "bad" is also
11.
▲
by
orkj
2y ago
Tangentially related: I have been having a ton of fun programming for the sensor watch lately: https://www.sensorwatch.net/ Granted it's far from as smart as pebble, but that battery life... ♥
12.
▲
WooCommerce collects your sensitive information without asking for consent
(twitter.com)
4 points
by
orkj
2y ago
|
0 comments
13.
▲
by
orkj
2y ago
Built https://violinist.io , a PHP / composer update service in 2017 and it passed that figure probably something like 2021?
14.
▲
by
orkj
2y ago
Does something like this exist for my phone, android specifically? Any good recommendations?
15.
▲
by
orkj
2y ago
It's mentioned in one of the first references in this article: https://boehs.org/node/everything-i-know-about-the-xz-backdo... IRC activity
16.
▲
by
orkj
3y ago
This made me think of http://prose.io which I remember was a thing 10 years ago. Pleasantly surprised it still is a website, not sure if it still works. But I remember the basic idea being similar, except Jekyll only.
17.
▲
by
orkj
3y ago
If you are using some of the library packages (i.e nodejs / ubuntu / golang), you can resort to using ECR Public: https://www.docker.com/blog/news-from-aws-reinvent-docker-of... To quote the example in the ar
18.
▲
by
orkj
3y ago
$ docker pull public.ecr.aws/docker/library/golang
19.
▲
by
orkj
3y ago
@technics256 But also not as a reply, so it's more visible: I have had luck with using Amazon ECR Public https://www.docker.com/blog/news-from-aws-reinvent-docker-of... To quote the example in the article: You can
20.
▲
by
orkj
3y ago
Replying to myself. I guess I read that a bit too quickly: > In Node.js, the answer involves a WebSocket to TCP socket proxy, Asyncify, and patching deep PHP internals like php_select. It's complex, but there's a reward. The No
21.
▲
by
orkj
3y ago
I did know of those, I'm just assuming its going to cause some sort of problem with network calls and sockets and what not (they mention this specifically as part of the caveats)
22.
▲
by
orkj
3y ago
Genuinely curious: does this mean you can run WordPress as a cloudflare worker (ignoring database for now)? https://developers.cloudflare.com/workers/runtime-apis/webas...
23.
▲
DNS DriveBy: Stealthy GPS Tracking Using Open Wi-Fi
(hackster.io)
12 points
by
orkj
4y ago
|
1 comments
24.
▲
by
orkj
4y ago
> There's another thing that really split the community, many want automatic security updates to Drupal core, but the Drupal core devs have taken a hard stance against this. That might have been true at some point, but certainly is
25.
▲
by
orkj
4y ago
It's in the FAQ in the readme, which links to this issue: https://github.com/go-gitea/gitea/issues/1029 Basically... They're working on it
26.
▲
by
orkj
4y ago
I feel it's relevant to mention this post is from 2014 (reference: how I interpreted the archive at https://danluu.com/ )
27.
▲
by
orkj
4y ago
For those not familiar, there is a "useless use of cat" ( https://porkmail.org/era/unix/award ) which I have a feeling this title is referring to
28.
▲
by
orkj
4y ago
> And lastly, if you're reading this, Daniel Coffmane #1687979, whoever you really are: Well played. I went to read the comments here to see if Daniel somehow acknowledged this
29.
▲
Munich State Court Finds Use of Google Fonts in Violation of GDPR
(twitter.com)
6 points
by
orkj
5y ago
|
0 comments
30.
▲
by
orkj
5y ago
Having so many issues. Cloning repos, setting up containers for the actions. Downloading packages with the API, logging in to the container service. Just, everything really. Totally killing my efficiency today, I am sure I have retried doze
More ›