Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ashishb
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
121.
▲
by
ashishb
9mo ago
> You’re looking at the number of dependents. The React package has no dependencies. Indeed. My apologies for misinterpreting the link that I posted. Consider "devDependencies" here https://github.com/facebook&#
122.
▲
by
ashishb
9mo ago
> auditing your dependencies is How do you do that practically? Do you read the source of every single package before doing a `brew update` or `npm update`? What if these sources include binary packages? The popular Javascript React fram
123.
▲
by
ashishb
9mo ago
> Exploit the Linux kernel underneath it (not the only way, just the obvious one). Docker is a security boundary but it is not suitable for "I'm running arbitrary code". Dockler is better for running arbitrary code compare
124.
▲
by
ashishb
9mo ago
> This is a well understood and well documented subject. Do your own research. Anything including GNU/Linux kernel can be broken with such security vulnerabilities. This is not a weakness in the design of containers. `npm install`,
125.
▲
by
ashishb
9mo ago
Show me how you will escape a docker sandbox.
126.
▲
by
ashishb
9mo ago
That should definitely improve. Right now, you are pretty much locked into the theme (and it's version) when you set up your website for the first time.
127.
▲
by
ashishb
9mo ago
Yeah. That's one flip side. Hugo-papermod, the most famous Hugo theme, doesn't support the latest 10 releases of Hugo. So, everyone using it is locked into using an old version (e.g. via Docker).
128.
▲
by
ashishb
9mo ago
Why not put the whole site behind CDN?
129.
▲
by
ashishb
9mo ago
> The swap bypassed our policy because the deny rule was bound to a specific file path, not the file itself or the workspace root. This policy is stupid. I mount the directory read inside the container to make it impossible to do it (ex
130.
▲
by
ashishb
9mo ago
> Has anyone given it a try? Yes, I don't think this will persist caches & configs outside of the current dir, for example, the global npm/yarn/uv/cargo cache or even Claude/Codex/Gemini code config. I e
131.
▲
by
ashishb
9mo ago
I had the same setup that I posted about a few months back[1], and then I migrated all of it into a single tool[2] for ease of use. 1 - https://news.ycombinator.com/item?id=45766478 2 - http://github.com/
132.
▲
by
ashishb
9mo ago
I run them inside a sandbox https://github.com/ashishb/amazing-sandbox
133.
▲
by
ashishb
10mo ago
> Even in a browser, a compromised JS payload can put your user's data and privacy at risk. True. In a backend, however, a compromised payload can put all of user's and your non-user data at risk.
134.
▲
by
ashishb
10mo ago
> In what way is it harder to write a library that exfiltrates credentials passed to it in those languages? It is not harder to write. It is more challenging to execute this attack stealthily. Due to the myriad behaviors of runtimes (bro
135.
▲
Amazing Sandbox (asb) – a Docker-based sandbox for running third-party code
(github.com)
1 points
by
ashishb
10mo ago
|
0 comments
136.
▲
by
ashishb
10mo ago
JavaScript fanatics will downvote me, but I will say again. JavaScript is meant to be run in an untrusted environment (think browser), and running it in any form of trusted environment increases the risk drastically [1] The language is too
137.
▲
by
ashishb
10mo ago
I don't even give it full disk access. I have written a tool to easily run the agents inside a container that mounts only the current directory.
138.
▲
by
ashishb
10mo ago
Generate the open API spec from the backend for internal applications. No need to update manually. Further, you can prevent breaking changes to the spec using oasdiff
139.
▲
by
ashishb
10mo ago
Same experience here. Post-honeymoon, I returned to REST+Open API https://ashishb.net/programming/openapi/
140.
▲
by
ashishb
10mo ago
Markdown is the final perfect form for every text (non-binary) content based system. Every product will eventually use markdown as their content store.
141.
▲
by
ashishb
10mo ago
Gitlab offers all three as well
142.
▲
by
ashishb
10mo ago
Are you sure you never cared about it? For example, how would you decide which FOSS vector database to use? Do you completely ignore GitHub Stars in the process?
143.
▲
The real lock-in in GitHub is not the code, but the stars
(ashishb.net)
6 points
by
ashishb
10mo ago
|
7 comments
144.
▲
by
ashishb
10mo ago
> You're mixing programming languages with software architecture. Programming languages do lead to certain software architectures. These are independent but not orthogonal issues.
145.
▲
by
ashishb
10mo ago
> You can still have separate codebases for server and client in JS/TS... Indeed, but unlike Go/Python (backend) and TS/JS (frontend), the separation is surmountable, and the push to "reuse" is high.
146.
▲
by
ashishb
10mo ago
> I can write an isomorphic web app in C or Rust or Go and run parts in the browser, what then? If you have a single codebase for Go-based code running in an untrusted browser (the "toilet") and a trusted backend (the "kit
147.
▲
by
ashishb
10mo ago
> This isn't a Javascript problem, this is a React problem. It happened with Next.js as well https://github.com/vercel/next.js/discussions/11106 > Say Python ran in the browser natively, and you re
148.
▲
by
ashishb
10mo ago
This happens in Next.js as well https://github.com/vercel/next.js/discussions/11106
149.
▲
by
ashishb
10mo ago
The JavaScript fanatics will downvote me for saying this, but I'll say this, "using a single JavaScript codebase on your client-side and server-side is like cooking food in your toilet, sooner or later, contamination is guaranteed
150.
▲
by
ashishb
10mo ago
> If you use deno you can consume dependencies much more securely How would Deno have prevented the RCE issue with React+Next.js?
More ›