Hacker Newsnew | past | comments | ask | show | jobs | submit | witnessme's commentslogin

Cracked at "I need to contribute my own beating so this horse is really dead"

2025 was the year when we saw extreme impact of supply chain attack. npm did something last month to counter this by retiring old auth tokens in favor of a new authentication method they call trusted publishing, it uses OIDC to authenticate automated publishing via CI. but it seems like a rushed decision. poor coordination and incomplete docs. result: many package publishers are stuck and not able to release the updates to their package. It's not been two weeks and we already see almost 2k issues on github, the number will rise exponentially.

* Search results on github : https://github.com/search?q=npm+trusted+publishing&type=issu...

* the case in point: https://github.com/gitcommitshow/resilient-llm/issues/39

* Docs issue : https://github.com/npm/cli/issues/8884

* The bug : https://github.com/npm/cli/issues/8730


Going to try this one soon. Great work OP.

This is a novel idea. Somewhere between the extremes of being useful vs being an overkill. More towards overkill because of its dependency on a new app/browser that needs to be installed. But I'm looking forward to more development on this idea, making it a production-ready automation.


Noted. I can see it on the link you shared. Earlier, I did check until the last page (90+ items) and did not find it. I then checked couple of more times thinking I made mistake. I see that you're using /shownew, I used /show link.


The same feeling non-native English speakers have battling native English speaker bias


A simple word2vec embedding with continuous bag of words (CBOW) training is enough and beats all other complex solutions at rhe performance as well as cost

Reference: https://blog.invidelabs.com/how-invide-analyzes-deep-work/


> 2020


Claude team has been killing it with the new impressive releases since last week. And this one looks most promising.


Why is featured as #1 on the frontpage. I get it, nice piece of satire and a bit controversial. But it is not productive at all.


If you'll look at the Guidelines for HN linked at the bottom of the page, you'll note that whether a submission is productive is not a criterion.

You could perhaps make an argument that among the flood of AI-related submissions, this one doesn't particularly move the needle on intellectual curiosity. Although satire is generally a good way to allow for some reflection on a serious topic, and I don't recall seeing AI-related satire here in a while.


because at this point we need a little bit of comedy in our lives to keep ourselves sane.


It's a Sunday.


Does Decode project overlaps with Solid project (Sir Tim Berners Lee's project with similar objective)?

P.S. Thanks for sharing Decode, it looks good, I will be diving deeper into it this weekend. TIA.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: