Hacker News
Cloudflare R2 is now Generally Available (2022)
Article URL: https://blog.cloudflare.com/r2-ga/
Comments URL: https://news.ycombinator.com/item?id=48995068
Points: 1
# Comments: 1
The Download: Chinese AI divides the White House, and a record copyright payout
Show HN: QuantmLayer – kernel-enforced containment for AI coding agents
Article URL: https://github.com/quantmlayer/quantmlayer
Comments URL: https://news.ycombinator.com/item?id=48995058
Points: 1
# Comments: 0
Devin Outposts: Run Devin sessions on your own infra
Article URL: https://docs.devin.ai/cloud/outposts/overview
Comments URL: https://news.ycombinator.com/item?id=48995050
Points: 1
# Comments: 0
Canada's promises to capture carbon span almost 20 years, with little gains
Article URL: https://thenarwhal.ca/canada-carbon-capture-history/
Comments URL: https://news.ycombinator.com/item?id=48995035
Points: 1
# Comments: 0
Iran's IRGC claims attack on Amazon's main data hub in Bahrain
Article URL: https://www.euronews.com/2026/07/21/irans-irgc-claims-attack-on-amazons-main-data-hub-in-bahrain
Comments URL: https://news.ycombinator.com/item?id=48995033
Points: 1
# Comments: 0
Yubikey 5.8: Verified Authorization for the New Era of Identity and AI
Article URL: https://www.yubico.com/resource/whats-new-yubikey-5-8/
Comments URL: https://news.ycombinator.com/item?id=48995030
Points: 1
# Comments: 0
Text as Music
Article URL: https://www.jeravalue.com/en/text-music
Comments URL: https://news.ycombinator.com/item?id=48995017
Points: 1
# Comments: 0
Show HN: PMG, open source package firewall
Hi HN
I am the founder of SafeDep. We have been detecting malicious packages for a while. Coming from DevSecOps background, I always considered malicious package detection & protection to be a build stage problem. But I was wrong since the S1ngularity and early Shai-Hulud days.
In 2026, we pretty much started worrying more about our own dev machines than CI/CD environment. Depending only on threat intelligence data (OSV / SafeDep / Socket / any other source) to protect our own dev machines did not feel right. We wanted to build a multi-layered protection that can get 100% visibility of OSS packages coming in, and can protect against known and “hopefully” unknown threats. That’s how Package Manager Guard (PMG) started. Core idea was simple:
- Start a local proxy (localhost)
- Make sure supported package managers like npm, pnpm, pip etc. goes through it
- Use threat intelligence data to fail fast on known malicious packages
- Apply policies like dependency cooldown as additional guardrails
- Adopt a policy language like CEL to support custom policies (roadmap)
- Everything stays local with stackable policies and audit log
- Threat model - Protect “willing” developers against malicious open source packages
Note: PMG does not consider a malicious developer as part of its threat model. So no real effort has been put to “enforce”, rather the goal is reduced friction while being effective.
Then came across Anthropic’s SRT and suddenly realized that in-process OS-native sandboxing is a good solution for limiting blast radius against unknown threats, especially since package managers have predictable runtime behaviour that can be allowed via. a sandbox while denying larger user permissions. Adopted seatbealt on MacOS and Landlock + Seccomp BPF for Linux. Seccomp BPF with Go was a battle of its own due to lack of control on OS threads, but finally managed to get it working without major performance cost.
To summarize, PMG does not only depend’s on SafeDep’s ability to find malicious packages. It enforces dependency cooldown (useful if you are stuck with older npm/pnpm), sandbox to protect against malicious packages. Our near term goal is to support CEL as a policy language and improve tooling around sandbox rules to make adoption easier.
Any feedback is welcome.
Comments URL: https://news.ycombinator.com/item?id=48994997
Points: 1
# Comments: 0
Show HN: Cross-Harness self hosted registry and analytics for AI Agents
Article URL: https://github.com/Observal/Observal
Comments URL: https://news.ycombinator.com/item?id=48994984
Points: 6
# Comments: 0
Show HN: Polymm – the Polymarket market-making bot behind my $5k wallet
Article URL: https://github.com/kachence/polymm
Comments URL: https://news.ycombinator.com/item?id=48994970
Points: 2
# Comments: 1
Stop funding data governance, run it with agents instead
Article URL: https://futuregrade.substack.com/p/stop-funding-data-governance-start
Comments URL: https://news.ycombinator.com/item?id=48994967
Points: 2
# Comments: 0
Regular Expressions for Hcpcs Codes
Article URL: https://www.johndcook.com/blog/2026/07/17/regular-expressions-for-hcpcs-codes/
Comments URL: https://news.ycombinator.com/item?id=48994964
Points: 2
# Comments: 0
Locally everywhere does not imply everywhere
Article URL: https://www.johndcook.com/blog/2026/07/21/jacobian-conjecture/
Comments URL: https://news.ycombinator.com/item?id=48994960
Points: 1
# Comments: 0
Martin Picard's Mitochondrial Theory of Mind
Article URL: https://www.quantamagazine.org/martin-picards-mitochondrial-theory-of-mind-20260717/
Comments URL: https://news.ycombinator.com/item?id=48994958
Points: 1
# Comments: 0
University of Tennessee sues Anthropic over neural network technology
Show HN: Serve-avd – stream any Android emulator to the browser with one command
Article URL: https://github.com/hsandhu/serve-avd
Comments URL: https://news.ycombinator.com/item?id=48994340
Points: 1
# Comments: 0
55M unique email addresses affected in Suno data breach
Article URL: https://haveibeenpwned.com/Breach/Suno
Comments URL: https://news.ycombinator.com/item?id=48994326
Points: 1
# Comments: 0
GE Aerospace flies hybrid-electric propulsion above 30k feet
The Long Road to Bottomless Postgres: Neon, Pg_mooncake, Pg_tier, Pg_lake
Article URL: https://www.pgedge.com/blog/the-long-road-to-bottomless-postgres
Comments URL: https://news.ycombinator.com/item?id=48994307
Points: 1
# Comments: 0
