<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: niros_valtos</title><link>https://news.ycombinator.com/user?id=niros_valtos</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 05 Jun 2026 22:34:03 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=niros_valtos" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by niros_valtos in "Anthropic's open-source framework for AI-powered vulnerability discovery"]]></title><description><![CDATA[
<p>I think that the cost of Opus is already prohibitively expensive, so not sure how that would compare to Mythos.
Check this calculator- it shows that a company with 100 devs can hit ~2.5M cost on tokens annually, which is wild!
<a href="https://ai-cost-calculator.arnica.io" rel="nofollow">https://ai-cost-calculator.arnica.io</a></p>
]]></description><pubDate>Fri, 05 Jun 2026 01:02:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=48406750</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=48406750</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48406750</guid></item><item><title><![CDATA[New comment by niros_valtos in "Open source project contains hidden instruction for "AI" agents: delete my code"]]></title><description><![CDATA[
<p>This is the supply chain problem climbing up a layer. We spent a decade learning not to pipe random scripts into a shell, and now agents will happily read a repo's files as instructions. Better detection of malicious comments will not fix it. An agent reading a file should never treat the contents as commands, the same lesson SQL injection taught, relearned for LLMs.</p>
]]></description><pubDate>Tue, 02 Jun 2026 14:36:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=48370848</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=48370848</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48370848</guid></item><item><title><![CDATA[New comment by niros_valtos in "Vibe Coding Is Not Engineering"]]></title><description><![CDATA[
<p>The line I'd draw is accountability: who owns it in prod at 3am. Vibe coding is fine for throwaway and prototypes, and it becomes a problem when the prototype quietly turns into the system and nobody can explain how it works.
Don't get me wrong, there is a room for production systems coded completely with AI, it just needs to be more thoughtful in the way it is done.</p>
]]></description><pubDate>Sun, 31 May 2026 17:59:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48347969</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=48347969</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48347969</guid></item><item><title><![CDATA[New comment by niros_valtos in "Ask HN: How is your org managing PR review load as AI multiplies code output?"]]></title><description><![CDATA[
<p>We hit this too, and what helped wasn't more reviewers. We pushed the trivial checks (style, obvious bugs, secret and other deterministic scanning) onto automation so humans only look at intent and design, and the trap to avoid is letting AI both write and "review" the code, since you want the review signal independent of what generated it.
There is another way we are experimenting these days too - building a gauge of how much a human in the loop is needed based on our confidence on the changes AI analyzes.</p>
]]></description><pubDate>Sun, 31 May 2026 17:54:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48347922</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=48347922</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48347922</guid></item><item><title><![CDATA[New comment by niros_valtos in "Making frontier cybersecurity capabilities available to defenders"]]></title><description><![CDATA[
<p>Definitely not a surprise they ship it. This is manageable for a small subset of repos scanned once. 
Reality is that code changes frequently and such rescans are expensive especially with thinking models. You can open a PR too, but then there are other missing workflows as rebasing when there are conflicts, finding the devs with the right expertise to review/test the fix, etc. 
bottom line - I see it is an interesting research tool but not more than that.</p>
]]></description><pubDate>Sat, 21 Feb 2026 01:21:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47096421</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=47096421</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47096421</guid></item><item><title><![CDATA[Opengrep – A Fork of Semgrep]]></title><description><![CDATA[
<p>Article URL: <a href="https://pulse.latio.tech/p/announcing-opengrep">https://pulse.latio.tech/p/announcing-opengrep</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42804916">https://news.ycombinator.com/item?id=42804916</a></p>
<p>Points: 13</p>
<p># Comments: 3</p>
]]></description><pubDate>Thu, 23 Jan 2025 15:25:09 +0000</pubDate><link>https://pulse.latio.tech/p/announcing-opengrep</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=42804916</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42804916</guid></item><item><title><![CDATA[Show HN: Semgrep rule to identify malicious Python code]]></title><description><![CDATA[
<p>Article URL: <a href="https://gist.github.com/nir-valtman/a4f743dc0570b68ab20743b2123b65ac">https://gist.github.com/nir-valtman/a4f743dc0570b68ab20743b2123b65ac</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=39628526">https://news.ycombinator.com/item?id=39628526</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 07 Mar 2024 12:58:40 +0000</pubDate><link>https://gist.github.com/nir-valtman/a4f743dc0570b68ab20743b2123b65ac</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=39628526</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39628526</guid></item><item><title><![CDATA[Show HN: Semgrep Rule That Identifies GitHub Repo Confusion Attack IOCs]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.arnica.io/blog/malicious-code-campaign-on-github-repos">https://www.arnica.io/blog/malicious-code-campaign-on-github-repos</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=39624094">https://news.ycombinator.com/item?id=39624094</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 07 Mar 2024 01:35:10 +0000</pubDate><link>https://www.arnica.io/blog/malicious-code-campaign-on-github-repos</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=39624094</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39624094</guid></item><item><title><![CDATA[Cellular Outage Caused by Cyber Attack? Speculations on Social Media]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.ibtimes.sg/cyber-attack-causes-major-cellular-outage-speculations-social-media-t-verizon-t-mobile-users-73556">https://www.ibtimes.sg/cyber-attack-causes-major-cellular-outage-speculations-social-media-t-verizon-t-mobile-users-73556</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=39467480">https://news.ycombinator.com/item?id=39467480</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 22 Feb 2024 14:23:43 +0000</pubDate><link>https://www.ibtimes.sg/cyber-attack-causes-major-cellular-outage-speculations-social-media-t-verizon-t-mobile-users-73556</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=39467480</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39467480</guid></item><item><title><![CDATA[New comment by niros_valtos in "Ask HN: Create PR from GitHub Desktop?"]]></title><description><![CDATA[
<p>Download the GitHub CLI. Run ‘ gh pr create’. Good luck!</p>
]]></description><pubDate>Tue, 13 Feb 2024 01:30:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=39353185</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=39353185</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39353185</guid></item><item><title><![CDATA[New comment by niros_valtos in "Show HN: Loz – Automate Git Commit Messages with LLM"]]></title><description><![CDATA[
<p>This is great!
Github Copilot used to summarize our PRs - I think it can work perfectly as a Github workflow to add comments to newly opened PRs. 
Can be a nice experiment to use multiple models and compare the comments to determine what works better.</p>
]]></description><pubDate>Sun, 11 Feb 2024 17:15:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=39336485</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=39336485</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39336485</guid></item><item><title><![CDATA[The Guide to Building an Efficient CI/CD Pipeline]]></title><description><![CDATA[
<p>Article URL: <a href="https://nioyatech.com/ci-cd-pipeline-a-comprehensive-guide/">https://nioyatech.com/ci-cd-pipeline-a-comprehensive-guide/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=37556103">https://news.ycombinator.com/item?id=37556103</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 18 Sep 2023 13:50:27 +0000</pubDate><link>https://nioyatech.com/ci-cd-pipeline-a-comprehensive-guide/</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=37556103</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37556103</guid></item><item><title><![CDATA[New comment by niros_valtos in "Sourcegraph got hacked so we built a Sourcegraph token validator"]]></title><description><![CDATA[
<p>The risk severity determination is interesting! If the token of the current user has a site admin permission, the risk is higher.</p>
]]></description><pubDate>Mon, 04 Sep 2023 22:50:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=37385915</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=37385915</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37385915</guid></item><item><title><![CDATA[GitHub sends my hardcoded secrets to providers when Secret Scanning is disabled]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/orgs/community/discussions/55126">https://github.com/orgs/community/discussions/55126</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=35896880">https://news.ycombinator.com/item?id=35896880</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 11 May 2023 03:10:22 +0000</pubDate><link>https://github.com/orgs/community/discussions/55126</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=35896880</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35896880</guid></item><item><title><![CDATA[Trying to identify spoofing in GitHub? May the 4th (or 5th) be with you]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.arnica.io/blog/trying-to-identify-spoofing-in-github-may-the-4th-be-with-you">https://www.arnica.io/blog/trying-to-identify-spoofing-in-github-may-the-4th-be-with-you</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=35829474">https://news.ycombinator.com/item?id=35829474</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 05 May 2023 14:12:12 +0000</pubDate><link>https://www.arnica.io/blog/trying-to-identify-spoofing-in-github-may-the-4th-be-with-you</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=35829474</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35829474</guid></item><item><title><![CDATA[What Is Pippelineless Security?]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.arnica.io/blog/what-is-pipelineless-security">https://www.arnica.io/blog/what-is-pipelineless-security</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=34881739">https://news.ycombinator.com/item?id=34881739</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 21 Feb 2023 14:45:46 +0000</pubDate><link>https://www.arnica.io/blog/what-is-pipelineless-security</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=34881739</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34881739</guid></item><item><title><![CDATA[Show HN: GitGoat v2 is released – fake commits with real vulnerable code]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/arnica-ext/GitGoat/releases/tag/v2.0.0">https://github.com/arnica-ext/GitGoat/releases/tag/v2.0.0</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=34666489">https://news.ycombinator.com/item?id=34666489</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 05 Feb 2023 17:02:51 +0000</pubDate><link>https://github.com/arnica-ext/GitGoat/releases/tag/v2.0.0</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=34666489</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34666489</guid></item><item><title><![CDATA[GitHub finally introduced fine-grained personal access tokens]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.blog/changelog/2022-10-18-introducing-fine-grained-personal-access-tokens/">https://github.blog/changelog/2022-10-18-introducing-fine-grained-personal-access-tokens/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=33249740">https://news.ycombinator.com/item?id=33249740</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 18 Oct 2022 16:17:41 +0000</pubDate><link>https://github.blog/changelog/2022-10-18-introducing-fine-grained-personal-access-tokens/</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=33249740</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33249740</guid></item><item><title><![CDATA[Hardening software development environments 101]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.arnica.io/blog/hardening-software-development-environments-101">https://www.arnica.io/blog/hardening-software-development-environments-101</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=32937591">https://news.ycombinator.com/item?id=32937591</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 22 Sep 2022 11:50:55 +0000</pubDate><link>https://www.arnica.io/blog/hardening-software-development-environments-101</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=32937591</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32937591</guid></item><item><title><![CDATA[NSA's software supply chain security recommendations need some refinement]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.arnica.io/blog/four-takeaways-from-the-nsas-software-supply-chain-security-recommendations">https://www.arnica.io/blog/four-takeaways-from-the-nsas-software-supply-chain-security-recommendations</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=32824524">https://news.ycombinator.com/item?id=32824524</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 13 Sep 2022 14:12:47 +0000</pubDate><link>https://www.arnica.io/blog/four-takeaways-from-the-nsas-software-supply-chain-security-recommendations</link><dc:creator>niros_valtos</dc:creator><comments>https://news.ycombinator.com/item?id=32824524</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32824524</guid></item></channel></rss>