<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: arianvanp</title><link>https://news.ycombinator.com/user?id=arianvanp</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 15 Apr 2026 04:33:21 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=arianvanp" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by arianvanp in "jj – the CLI for Jujutsu"]]></title><description><![CDATA[
<p>You can disable the auto staging of new files since recently which removed the main grype for me</p>
]]></description><pubDate>Tue, 14 Apr 2026 12:44:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=47764937</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47764937</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47764937</guid></item><item><title><![CDATA[New comment by arianvanp in "Open Source Security at Astral"]]></title><description><![CDATA[
<p>The problem is nobody checks.<p>All the axios releases had attestations except for the compromised one. npm installed it anyway.</p>
]]></description><pubDate>Thu, 09 Apr 2026 06:29:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=47699996</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47699996</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47699996</guid></item><item><title><![CDATA[New comment by arianvanp in "Delve removed from Y Combinator"]]></title><description><![CDATA[
<p>If you care about this stuff you need to in-house auditing and do your own audits with people who care. Then get certified by an external auditor for the paper.<p>You can start very lightweight with doing spec driven development with the help of AI if you're at a size where you can't afford that. It's better than nothing.<p>But the important part is you, as a company, should inherently care.<p>If you rely on an auditor feedback loop to get compliant you've already lost.</p>
]]></description><pubDate>Sat, 04 Apr 2026 06:54:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=47636560</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47636560</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47636560</guid></item><item><title><![CDATA[New comment by arianvanp in "VHDL's Crown Jewel"]]></title><description><![CDATA[
<p>Sounds like reachability problem in Petri nets to me?</p>
]]></description><pubDate>Mon, 30 Mar 2026 06:40:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=47571139</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47571139</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47571139</guid></item><item><title><![CDATA[New comment by arianvanp in "ICAO issued new power bank restriction on flight"]]></title><description><![CDATA[
<p>E cigarettes work by shorting the battery releasing a lot of instantenous heat. Their safety controller firmware are often of ... Dubious quality. It can happen quite often that the cigarette doesn't stop shorting the battery and catch fire as a result.<p>Making fire is literally their function unlike a laptop.<p>Combine that with basically unregulated and semi illegal supply chain and it becomes a recipe for disaster</p>
]]></description><pubDate>Sun, 29 Mar 2026 08:46:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=47561433</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47561433</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47561433</guid></item><item><title><![CDATA[New comment by arianvanp in "Why I love NixOS"]]></title><description><![CDATA[
<p>Arch Linux also has a long history of people writing their own package specs (AUR) and is relatively simple too of course.<p>Let me put it differently. The documentation of NixOS treats package maintainers and users as kind of equal.<p>This has benefits and downsides. Benefit is that everyone is treated as a power user. Downside is that power users are horrible at writing docs and this philosophy is my main theory why NixOS docs are so .... Bad<p>Fedora (and RHEL) end user and developer docs are written for quite different audiences</p>
]]></description><pubDate>Mon, 23 Mar 2026 07:47:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=47486477</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47486477</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47486477</guid></item><item><title><![CDATA[New comment by arianvanp in "Why I love NixOS"]]></title><description><![CDATA[
<p>A snapshot of your build folder. Not even the sources. This is my other problem with mainstream Distros. Extending them is completely opaque. NixOS is source based and anything and everything can be updated by the user. Need some patch from kernel ML? 1 line of code. Need a Bugfix in your IDE that hasn't landed in a release? 1 line of code.<p>There is no distinction between package maintainers and end users. They have the same  power.<p>In the meantime i dont expect Debian users to ever write a package themselves or to modify one.<p>In nixOS you do it all the time</p>
]]></description><pubDate>Mon, 23 Mar 2026 07:07:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=47486293</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47486293</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47486293</guid></item><item><title><![CDATA[New comment by arianvanp in "Why I love NixOS"]]></title><description><![CDATA[
<p>I've been trying to get nixd LSP to work with Claude Code but I got stuck as they gatekeep it behind their "plugin" system and you can't just configure it in settings.json to point to a nix store path like mcps :(</p>
]]></description><pubDate>Mon, 23 Mar 2026 07:02:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=47486258</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47486258</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47486258</guid></item><item><title><![CDATA[New comment by arianvanp in "Afroman found not liable in defamation case"]]></title><description><![CDATA[
<p>I think you're confusing gender and sexual orientation. He's calling her a lesbian</p>
]]></description><pubDate>Thu, 19 Mar 2026 12:53:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=47438551</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47438551</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47438551</guid></item><item><title><![CDATA[New comment by arianvanp in "Show HN: OneCLI – Vault for AI Agents in Rust"]]></title><description><![CDATA[
<p>Also doesn't this mean I have to reconfigure all my tools to use HTTP and then when I forget to enable this it will fall back to getting MITM'd by the Internet? Fails open in the most insecure method ever</p>
]]></description><pubDate>Fri, 13 Mar 2026 09:08:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=47362126</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47362126</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47362126</guid></item><item><title><![CDATA[New comment by arianvanp in "Show HN: OneCLI – Vault for AI Agents in Rust"]]></title><description><![CDATA[
<p>But it hasn't been built exclusively for that use case. It's literally the same.</p>
]]></description><pubDate>Fri, 13 Mar 2026 09:07:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=47362117</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47362117</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47362117</guid></item><item><title><![CDATA[New comment by arianvanp in "Agent Safehouse – macOS-native sandboxing for local agents"]]></title><description><![CDATA[
<p>That and that the built in sandbox in Claude Code is bad (read only access to everything by default) and tightly coupled (cant modify it or swap it out).</p>
]]></description><pubDate>Sun, 08 Mar 2026 21:10:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47301510</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47301510</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47301510</guid></item><item><title><![CDATA[New comment by arianvanp in "Agent Safehouse – macOS-native sandboxing for local agents"]]></title><description><![CDATA[
<p>That is also Linux VM on MacOS. They're not MacOS containers..
So it's completely pointless / useless for MacOS or iOS development</p>
]]></description><pubDate>Sun, 08 Mar 2026 21:09:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=47301496</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47301496</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47301496</guid></item><item><title><![CDATA[New comment by arianvanp in "Claude Code escapes its own denylist and sandbox"]]></title><description><![CDATA[
<p>I opened an issue about this on day 1 of the release:<p><a href="https://github.com/anthropic-experimental/sandbox-runtime/issues/2" rel="nofollow">https://github.com/anthropic-experimental/sandbox-runtime/is...</a><p>I ended up making my own sandbox wrapper instead <a href="https://GitHub.com/arianvp/landlock-nix" rel="nofollow">https://GitHub.com/arianvp/landlock-nix</a></p>
]]></description><pubDate>Tue, 03 Mar 2026 22:57:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47240303</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47240303</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47240303</guid></item><item><title><![CDATA[New comment by arianvanp in "GitHub having issues [resolved]"]]></title><description><![CDATA[
<p>Doesn't post-receive block the push operation and get cancelled when you cancel the push?</p>
]]></description><pubDate>Tue, 03 Mar 2026 22:00:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47239664</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47239664</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47239664</guid></item><item><title><![CDATA[New comment by arianvanp in "MacBook Pro with M5 Pro and M5 Max"]]></title><description><![CDATA[
<p>Closing Tabs in Safari till takes more than a second though. And if you hold Cmd-W to close all of them it just completely locks up and crashes. Still not fixed since the release of Safari 26.<p>Literally unusable</p>
]]></description><pubDate>Tue, 03 Mar 2026 14:20:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=47232744</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47232744</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47232744</guid></item><item><title><![CDATA[New comment by arianvanp in "Don't trust AI agents"]]></title><description><![CDATA[
<p>Literally every email client on the planet has supported `mailto:` URIs since basically the existence of the world wide web.<p>Just generate a mailto Uri with the body set to the draft.</p>
]]></description><pubDate>Sat, 28 Feb 2026 15:18:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=47196297</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47196297</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47196297</guid></item><item><title><![CDATA[New comment by arianvanp in "Turn Dependabot off"]]></title><description><![CDATA[
<p>At this point your steps are so simple id skip GitHub actions security tyre fire altogether. Just run the go commands whilst listening on GitHub webhooks and updating checks with the GitHub checks API.<p>GitHub actions is the biggest security risk in this whole setup.<p>Honestly not that complicated.</p>
]]></description><pubDate>Sat, 21 Feb 2026 00:52:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=47096221</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47096221</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47096221</guid></item><item><title><![CDATA[New comment by arianvanp in "Web Components: The Framework-Free Renaissance"]]></title><description><![CDATA[
<p>Say you want to have a custom button element. You cant give it a `type=submit` whilst you can set that on <input> and <button><p>Also if you have a face that wraps a button of type submit. The submit doesn't propagate due to shadow dom</p>
]]></description><pubDate>Fri, 20 Feb 2026 14:40:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=47088594</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47088594</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47088594</guid></item><item><title><![CDATA[New comment by arianvanp in "Web Components: The Framework-Free Renaissance"]]></title><description><![CDATA[
<p>I tried Web Components to create a `<passkey>` element to allow Passkey support in forms without having to write javascript as an end-user.<p>I ran into <a href="https://github.com/WICG/webcomponents/issues/814" rel="nofollow">https://github.com/WICG/webcomponents/issues/814</a><p>As long as this is not fixed I can't take Web Components seriously.</p>
]]></description><pubDate>Fri, 20 Feb 2026 11:30:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=47086661</link><dc:creator>arianvanp</dc:creator><comments>https://news.ycombinator.com/item?id=47086661</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47086661</guid></item></channel></rss>