Skip to main content
Live Feed

Engineering &
Security Wire

Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.

30
ENG
0
SEC
0
AI
6513
TOTAL
Sun, Apr 19, 2026
30
4921ENG

Defense in Depth: A Practical Guide to Python Supply Chain Security

Layer your defenses and don’t trust any single control. Use Ruff with security rules to catch bugs in your code before they ship. Pin all your dependencies with cryptographic hashes using uv lock or uv pip compile --generate-hashes so nobody can swap out packages on you. Run pip-audit in CI to catch known CVEs before they hit production. Generate SBOMs with CycloneDX so when the next Ultralytics-style compromise drops, you can answer “are we affected?” in minutes instead of days. If you’re publishing packages, ditch the long-lived API tokens and switch to Trusted Publishing with OIDC. This generates attestations automatically via Sigstore, linking your packages back to source repos. Organizations running internal mirrors can add a 7-day delay to let the community be your canary - but only if you’ve got the infrastructure to maintain it. Nothing here is perfect. Hash pinning stops tampering but won’t save you from a malicious package you installed on day one. Scanning finds known CVEs b

Lobstersbernat.techApr 19
4922ENG

Stupid RCU Tricks: Corner-Case RCU Implementations

Comments

Lobsterspeople.kernel.orgApr 19
4923ENG

C++26: Reflection, Memory Safety, Contracts, and a New Async Model

Article URL: https://www.infoq.com/news/2026/04/cpp-26-reflection-safety-async/ Comments URL: https://news.ycombinator.com/item?id=47827603 Points: 27 # Comments: 2

Hacker Newsinfoq.comApr 19
4924ENG

Stop trying to engineer your way out of listening to people

144 points, 49 comments on Hacker News

Hacker Newsashley.rolfmore.comApr 19
4925ENG

A. J. Ayer – ‘What I Saw When I Was Dead’ (1988)

https://web.archive.org/web/20190724072148/https://www.philo... https://archive.ph/is0by Comments URL: https://news.ycombinator.com/item?id=47827215 Points: 62 # Comments: 75

Hacker Newsphilosopher.euApr 19
4926ENG

corpus: self-hosted listenbrainz and last.fm frontend

Works as a self-hosted proxy that fetches listening history from either Last.fm or MusicBrainz, adds metadata from MusicBrainz (falling back to Last.fm and Discogs) and caches cover images to an S3 bucket. Everything is stored in DuckDB (each user has their own database) and it's been humming along quite well even for larger profiles (200k scrobbles). I always worry that these services can disappear without a warning and with them also amazingly extensive listening histories. I used LLMs quite a lot as I was learning about Purescript and Elm on the fly on the weekends and this is one of the projects I have been thinking about for a long time since other alternatives just seemed a bit lackluster. Comments

Lobstersgithub.comApr 19
4927ENG

I wrote a CHIP-8 emulator in my own programming language

36 points, 10 comments on Hacker News

Hacker Newsgithub.comApr 19
4928ENG

10 years ago, someone wrote a test for Servo that included an expiry in 2026

120 points, 75 comments on Hacker News

Hacker Newsmastodon.socialApr 19
4929ENG

Scientific datasets are riddled with copy-paste errors

24 points, 1 comments on Hacker News

Hacker Newssciencedetective.orgApr 19
4930ENG

Six Levels of Dark Mode

38 points, 10 comments on Hacker News

Hacker Newscssence.comApr 19
4931ENG

Introducing Glyph Protocol for Terminals

Comments

Lobstersrapha.landApr 19
4932ENG

Show HN: Faceoff – A terminal UI for following NHL games

Faceoff is a TUI app written in Python to follow live NHL games and browse standings and stats. I got the inspiration from Playball, a similar TUI app for MLB games that was featured on HN. The app was mostly vibe-coded with Claude Code, but not one-shot. I added features and fixed bugs by using it, as I spent way too much time in the terminal over the last few months. Try it out with `uvx faceoff` (requires uv). Comments URL: https://news.ycombinator.com/item?id=47826104 Points: 15 # Comments: 3

Hacker Newsvincentgregoire.comApr 19
4933ENG

The Bromine Chokepoint

138 points, 70 comments on Hacker News

Hacker Newswarontherocks.comApr 19
4934ENG

Hot Wiring the Lisp Machine

Comments

Lobstersscheatkode.comApr 19
4935ENG

543 Hours: What happens when AI runs while you sleep

5 points, 0 comments on Hacker News

Hacker Newsmichael.roth.rocksApr 19
4936ENG

Turtle WoW classic server announces shutdown after Blizzard wins injunction

Article URL: https://www.pcgamer.com/games/world-of-warcraft/turtle-wow-classic-server-announces-shutdown-after-blizzard-wins-injunction/ Comments URL: https://news.ycombinator.com/item?id=47825160 Points: 74 # Comments: 51

Hacker Newspcgamer.comApr 19
4937ENG

What we once had (at the height of the XMPP era of the Internet) (2023)

Comments

Lobsterskirsle.netApr 19
4938ENG

Vercel Says Internal Systems Hit in Breach

Article URL: https://decipher.sc/2026/04/19/vercel-says-internal-systems-hit-in-breach/ Comments URL: https://news.ycombinator.com/item?id=47824976 Points: 263 # Comments: 46

Hacker Newsdecipher.scApr 19
4939ENG

Vercel April 2026 security incident

some context: https://nitter.net/DiffeKey/status/2045813085408051670 Comments

Lobstersvercel.comApr 19
4940ENG

Notion leaks email addresses of all editors of any public page

Article URL: https://twitter.com/weezerOSINT/status/2045849358462222720 Comments URL: https://news.ycombinator.com/item?id=47824945 Points: 164 # Comments: 42

Hacker Newstwitter.comApr 19
4941ENG

5x5 Pixel font for tiny screens

117 points, 31 comments on Hacker News

Hacker Newsmaurycyz.comApr 19
4942ENG

Notes from the SF Peptide Scene

Article URL: https://12gramsofcarbon.com/p/notes-from-the-sf-peptide-scene Comments URL: https://news.ycombinator.com/item?id=47824681 Points: 90 # Comments: 68

Hacker News12gramsofcarbon.comApr 19
4943ENG

postmarketOS Conference

Comments

Lobsterspostmarketos.orgApr 19
4944ENG

When moving fast, talking is the first thing to break

Article URL: https://daverupert.com/2026/04/more-talk-less-grok/ Comments URL: https://news.ycombinator.com/item?id=47824611 Points: 70 # Comments: 32

Hacker Newsdaverupert.comApr 19
4945ENG

Matt Mullenweg Overrules Core Committers; Puts Akismet on WP 7's Connector List

Article URL: https://www.therepository.email/matt-mullenweg-overrules-core-committers-to-put-akismet-on-wordpress-7-0s-connectors-screen Comments URL: https://news.ycombinator.com/item?id=47824531 Points: 48 # Comments: 37

Hacker Newstherepository.emailApr 19
4946ENG

waves & particles

Comments

Lobsterstaylor.townApr 19
4947ENG

Vercel April 2026 security incident

498 points, 298 comments on Hacker News

Hacker Newsbleepingcomputer.comApr 19
4948ENG

Plexus P/20 Emulator

8 points, 0 comments on Hacker News

Hacker Newsspritetm.github.ioApr 19
4949ENG

Contact Lens Uses Microfluidics to Monitor and Treat Glaucoma

63 points, 2 comments on Hacker News

Hacker Newsspectrum.ieee.orgApr 19
4950ENG

Show HN: Prompt-to-Excalidraw demo with Gemma 4 E2B in the browser (3.1GB)

Article URL: https://teamchong.github.io/turboquant-wasm/draw.html Comments URL: https://news.ycombinator.com/item?id=47823460 Points: 56 # Comments: 24

Hacker Newsteamchong.github.ioApr 19

Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles