<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: yuvrajangads</title><link>https://news.ycombinator.com/user?id=yuvrajangads</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 06 Oct 2026 03:15:49 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=yuvrajangads" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by yuvrajangads in "Show HN: 7 years of code, nothing to show on GitHub – so I built this"]]></title><description><![CDATA[
<p>i had the same problem and built something similar but with a different approach. greens (<a href="https://github.com/yuvrajangadsingh/greens" rel="nofollow">https://github.com/yuvrajangadsingh/greens</a>) is a CLI that runs locally on your machine. it mirrors commit activity from your private/work repos to a personal repo via a cron job. no tokens shared with any third party, no web app, no account.<p>the tradeoff vs your approach is it only works going forward (can't backfill years of history), but nothing ever leaves your machine.<p>to answer your honest question #1: yes, this is a real problem. i posted about it on linkedin and the response was way bigger than i expected. lots of devs working at companies where all their output is invisible on their public profile.</p>
]]></description><pubDate>Thu, 09 Apr 2026 13:21:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=47703405</link><dc:creator>yuvrajangads</dc:creator><comments>https://news.ycombinator.com/item?id=47703405</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47703405</guid></item><item><title><![CDATA[New comment by yuvrajangads in "Show HN: Vibecheck – lint for AI-generated code smells (JS/TS/Python)"]]></title><description><![CDATA[
<p>fair point on regex being brittle for edge cases. it works well for the obvious patterns (empty catches, bare excepts, hardcoded secrets) but yeah it wont catch everything.<p>for vibe coding sessions thats actually the main use case i had in mind. run it after a generation pass to catch the low-hanging stuff before it gets committed. zero config so you can just pipe it in.</p>
]]></description><pubDate>Thu, 19 Mar 2026 11:16:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=47437520</link><dc:creator>yuvrajangads</dc:creator><comments>https://news.ycombinator.com/item?id=47437520</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47437520</guid></item><item><title><![CDATA[New comment by yuvrajangads in "Show HN: Vibecheck – lint for AI-generated code smells (JS/TS/Python)"]]></title><description><![CDATA[
<p>yeah that makes sense. regex catches the surface-level stuff fast, but logic bugs and spec drift need something smarter. the AI layer on top of deterministic checks is a good approach.<p>vibecheck is intentionally the dumb fast pass, sounds like caliper handles the deeper analysis. will check it out.</p>
]]></description><pubDate>Thu, 19 Mar 2026 11:15:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=47437517</link><dc:creator>yuvrajangads</dc:creator><comments>https://news.ycombinator.com/item?id=47437517</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47437517</guid></item><item><title><![CDATA[New comment by yuvrajangads in "Show HN: Vemb – embed text, images, audio, video and PDFs from the terminal"]]></title><description><![CDATA[
<p>I kept writing the same boilerplate to call embedding APIs from scripts. Wanted something like httpie but for embeddings.<p>vemb wraps Gemini Embedding 2, which is the first model that natively embeds text, images, audio, video, and PDFs into the same vector space. Free API key from Google AI Studio.<p>One command: `vemb text "query"` gives you a vector. `vemb search ./docs "find similar"` searches a directory with caching. `vemb similar a.jpg b.jpg` gives you cosine similarity.<p>The multimodal part is the differentiator: you can search a folder of images using a text query, or compare a PDF to an audio file. Same embedding space, no transcription step.<p>Would love feedback on what output formats or integrations would be most useful.</p>
]]></description><pubDate>Thu, 19 Mar 2026 11:05:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47437429</link><dc:creator>yuvrajangads</dc:creator><comments>https://news.ycombinator.com/item?id=47437429</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47437429</guid></item><item><title><![CDATA[Show HN: Vemb – embed text, images, audio, video and PDFs from the terminal]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/yuvrajangadsingh/vemb">https://github.com/yuvrajangadsingh/vemb</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47437427">https://news.ycombinator.com/item?id=47437427</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Thu, 19 Mar 2026 11:04:51 +0000</pubDate><link>https://github.com/yuvrajangadsingh/vemb</link><dc:creator>yuvrajangads</dc:creator><comments>https://news.ycombinator.com/item?id=47437427</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47437427</guid></item><item><title><![CDATA[Show HN: Vibecheck – lint for AI-generated code smells (JS/TS/Python)]]></title><description><![CDATA[
<p>I built a CLI that detects patterns AI coding tools leave behind: empty catch blocks, hardcoded secrets, as any everywhere, comments that restate the code, god functions, SQL concatenation.<p>24 rules across JS/TS and Python. Zero config, runs offline, regex-based so it's fast.<p><pre><code>  npx @yuvrajangadsingh/vibecheck .
</code></pre>
Also ships as a GitHub Action for inline PR annotations and standalone binaries (no Node required).<p>Why: CodeRabbit found AI-generated PRs have 1.7x more issues than human PRs. Veracode says 45% of AI code samples have security vulnerabilities. "Vibe coding" is everywhere now but nobody's linting for the patterns it produces.<p>This isn't a replacement for ESLint. It catches things ESLint doesn't look for, like catch blocks that only console.error without rethrowing, bare except: pass in Python, or mutable default arguments.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47398197">https://news.ycombinator.com/item?id=47398197</a></p>
<p>Points: 7</p>
<p># Comments: 4</p>
]]></description><pubDate>Mon, 16 Mar 2026 12:42:02 +0000</pubDate><link>https://github.com/yuvrajangadsingh/vibecheck</link><dc:creator>yuvrajangads</dc:creator><comments>https://news.ycombinator.com/item?id=47398197</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47398197</guid></item><item><title><![CDATA[New comment by yuvrajangads in "WebMCP is available for early preview"]]></title><description><![CDATA[
<p>Fair point about web fetch already being a trust boundary. The difference I see is that web fetch returns data, but WebMCP tools can define actions. A tool called "add_to_cart" is a lot more dangerous than fetching a product page. The agent trusts the tool's name and description to decide whether to call it, and that metadata comes from the site.<p>But yeah, if you're already letting agents browse freely, the incremental risk might be smaller than I'm imagining.</p>
]]></description><pubDate>Mon, 02 Mar 2026 14:37:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=47218492</link><dc:creator>yuvrajangads</dc:creator><comments>https://news.ycombinator.com/item?id=47218492</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47218492</guid></item><item><title><![CDATA[New comment by yuvrajangads in "Show HN: Commitdog – Git on steroids CLI (pure Go, ~3MB binary)"]]></title><description><![CDATA[
<p>Nice, similar energy to lazygit but as a single binary. The AI commit message generation is useful but I'd want a way to set a template or convention (conventional commits, etc.) so it doesn't just freestyle every time.<p>One thing: piping the install through curl | sh makes some people nervous. Might be worth adding a homebrew tap or at least a checksum for the binary.</p>
]]></description><pubDate>Mon, 02 Mar 2026 14:22:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47218296</link><dc:creator>yuvrajangads</dc:creator><comments>https://news.ycombinator.com/item?id=47218296</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47218296</guid></item><item><title><![CDATA[New comment by yuvrajangads in "WebMCP is available for early preview"]]></title><description><![CDATA[
<p>I've been using MCP with Claude Code for a while now (Google Maps, Swiggy, Figma servers) and the local tool-use model works well because I control both sides. I pick which servers to trust, I see every tool call, and I can deny anything sketchy.<p>WebMCP flips that. The website exposes the tools and the browser decides what to call. The security model gets a lot harder when you're trusting random sites to define their own tool interfaces honestly. A malicious site could expose tools that look helpful but exfiltrate context from the agent's session.<p>Curious how they plan to sandbox this. The local MCP model works because trust is explicit. Not sure how that translates to the open web.</p>
]]></description><pubDate>Mon, 02 Mar 2026 12:32:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=47217190</link><dc:creator>yuvrajangads</dc:creator><comments>https://news.ycombinator.com/item?id=47217190</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47217190</guid></item><item><title><![CDATA[New comment by yuvrajangads in "If AI writes code, should the session be part of the commit?"]]></title><description><![CDATA[
<p>The session itself is mostly noise. Half of it is the model going down wrong paths, backtracking, and trying again. Storing that alongside the commit is like saving your browser history next to your finished code.<p>What actually helps is a good commit message explaining the intent. If an AI wrote the code, the interesting part isn't the transcript, it's why you asked for it and what constraints you gave it. A one-paragraph description of the goal and approach is worth more than a 200-message session log.<p>I think the real question isn't about storing sessions, it's about whether we're writing worse commit messages because we assume the AI context is "somewhere."</p>
]]></description><pubDate>Mon, 02 Mar 2026 12:20:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=47217075</link><dc:creator>yuvrajangads</dc:creator><comments>https://news.ycombinator.com/item?id=47217075</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47217075</guid></item><item><title><![CDATA[Show HN: Greens – mirror private GitHub activity to your public graph]]></title><description><![CDATA[
<p>I built greens because most of my day-job work is in private org repos, so my public GitHub graph looked inactive.<p>The tool runs locally, scans repos you choose in read-only mode, extracts commit timestamps for your author email, and creates empty commits with those timestamps in a public mirror repo. No source code, diffs, or filenames are copied.<p>If `gh` is configured, it can also mirror PR/review/issue activity. It's a bash CLI, installable via Homebrew (`brew install yuvrajangadsingh/greens/greens`).<p>I know some people view this as graph-gaming, fair point. My intent is not to imply public OSS output, only to make private work volume visible. Also worth noting: check your company policy before using it.<p>Feedback welcome, especially on edge cases or failure modes.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47214682">https://news.ycombinator.com/item?id=47214682</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 02 Mar 2026 06:56:35 +0000</pubDate><link>https://github.com/yuvrajangadsingh/greens</link><dc:creator>yuvrajangads</dc:creator><comments>https://news.ycombinator.com/item?id=47214682</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47214682</guid></item><item><title><![CDATA[Show HN: Mirror private work contributions to your GitHub profile]]></title><description><![CDATA[
<p>I work on private repos all day but my GitHub profile showed empty squares. Built a tool to fix it.<p>Mirrors commit timestamps (not code) to a public repo. Also tracks PRs, reviews, issues via GitHub API.<p>5 min setup, runs daily via cron/launchd.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46896456">https://news.ycombinator.com/item?id=46896456</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 05 Feb 2026 06:39:13 +0000</pubDate><link>https://github.com/yuvrajangadsingh/private-work-contributions-mirror</link><dc:creator>yuvrajangads</dc:creator><comments>https://news.ycombinator.com/item?id=46896456</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46896456</guid></item></channel></rss>