Hacker News

Latest

Why more American seniors are getting high

2025-12-12 @ 16:56:31Points: 18Comments: 26

America's Betting Craze Has Spread to Its News Networks

2025-12-12 @ 16:43:04Points: 51Comments: 75

Senator endorses discredited book that claims chemical treats autism, cancer

2025-12-12 @ 16:37:04Points: 30Comments: 5

Epic celebrates "the end of the Apple Tax" after court win in iOS payments case

2025-12-12 @ 16:04:16Points: 66Comments: 36

Framework Raises DDR5 Memory Prices by 50% for DIY Laptops

2025-12-12 @ 15:58:10Points: 55Comments: 35

Berlin Approves New Expansion of Police Surveillance Powers

2025-12-12 @ 15:29:46Points: 68Comments: 35

CM0 – a new Raspberry Pi you can't buy

2025-12-12 @ 15:19:19Points: 22Comments: 1

BpfJailer: eBPF Mandatory Access Control [pdf]

2025-12-12 @ 14:20:20Points: 29Comments: 3

SQLite JSON at Full Index Speed Using Generated Columns

2025-12-12 @ 13:25:19Points: 163Comments: 58

Fedora: Open-source repository for long-term digital preservation

2025-12-12 @ 13:23:31Points: 60Comments: 35

The Tor Project is switching to Rust

2025-12-12 @ 12:35:57Points: 251Comments: 167

Koralm Railway

2025-12-12 @ 10:50:22Points: 270Comments: 154

Training LLMs for Honesty via Confessions

2025-12-12 @ 10:37:51Points: 38Comments: 25

Guarding My Git Forge Against AI Scrapers

2025-12-12 @ 07:51:04Points: 111Comments: 74

The tiniest yet real telescope I've built

2025-12-12 @ 07:35:49Points: 205Comments: 55

Google de-indexed Bear Blog and I don't know why

2025-12-12 @ 01:20:05Points: 336Comments: 141

CRISPR fungus: Protein-packed, sustainable, and tastes like meat

2025-12-12 @ 00:59:46Points: 258Comments: 186

Nokia N900 Necromancy

2025-12-12 @ 00:04:29Points: 425Comments: 166

Show HN: Autofix Bot – Hybrid static analysis and AI code review agent

2025-12-11 @ 21:24:34Points: 25Comments: 7

AI coding agents have made code generation nearly free, and they’ve shifted the bottleneck to code review. Static-only analysis with a fixed set of checkers isn’t enough. LLM-only review has several limitations: non-deterministic across runs, low recall on security issues, expensive at scale, and a tendency to get ‘distracted’.

We spent the last 6 years building a deterministic, static-analysis-only code review product. Earlier this year, we started thinking about this problem from the ground up and realized that static analysis solves key blind spots of LLM-only reviews. Over the past six months, we built a new ‘hybrid’ agent loop that uses static analysis and frontier AI agents together to outperform both static-only and LLM-only tools in finding and fixing code quality and security issues. Today, we’re opening it up publicly.

Here’s how the hybrid architecture works:

- Static pass: 5,000+ deterministic checkers (code quality, security, performance) establish a high-precision baseline. A sub-agent suppresses context-specific false positives.

- AI review: The agent reviews code with static findings as anchors. Has access to AST, data-flow graphs, control-flow, import graphs as tools, not just grep and usual shell commands.

- Remediation: Sub-agents generate fixes. Static harness validates all edits before emitting a clean git patch.

Static solves key LLM problems: non-determinism across runs, low recall on security issues (LLMs get distracted by style), and cost (static narrowing reduces prompt size and tool calls).

On the OpenSSF CVE Benchmark [1] (200+ real JS/TS vulnerabilities), we hit 81.2% accuracy and 80.0% F1; vs Cursor Bugbot (74.5% accuracy, 77.42% F1), Claude Code (71.5% accuracy, 62.99% F1), CodeRabbit (59.4% accuracy, 36.19% F1), and Semgrep CE (56.9% accuracy, 38.26% F1). On secrets detection, 92.8% F1; vs Gitleaks (75.6%), detect-secrets (64.1%), and TruffleHog (41.2%). We use our open-source classification model for this. [2]

Full methodology and how we evaluated each tool: https://autofix.bot/benchmarks

You can use Autofix Bot interactively on any repository using our TUI, as a plugin in Claude Code, or with our MCP on any compatible AI client (like OpenAI Codex).[3] We’re specifically building for AI coding agent-first workflows, so you can ask your agent to run Autofix Bot on every checkpoint autonomously.

Give us a shot today: https://autofix.bot. We’d love to hear any feedback!

---

[1] https://github.com/ossf-cve-benchmark/ossf-cve-benchmark

[2] https://huggingface.co/deepsource/Narada-3.2-3B-v1

[3] https://autofix.bot/manual/#terminal-ui

Denial of service and source code exposure in React Server Components

2025-12-11 @ 20:46:46Points: 323Comments: 203

An SVG is all you need

2025-12-11 @ 19:25:14Points: 313Comments: 130

Rivian Unveils Custom Silicon, R2 Lidar Roadmap, and Universal Hands Free

2025-12-11 @ 18:17:19Points: 363Comments: 520

Programmers and software developers lost the plot on naming their tools

2025-12-11 @ 18:06:42Points: 384Comments: 485

GPT-5.2

2025-12-11 @ 18:04:47Points: 1127Comments: 991

From text to token: How tokenization pipelines work

2025-12-11 @ 14:45:49Points: 77Comments: 8

Show HN: Tripwire: A new anti evil maid defense

2025-12-11 @ 09:46:56Points: 49Comments: 30

https://github.com/guardianproject/haven), then Tripwire fills in the void for a robust anti evil maid solution after Haven went dormant.

The GitHub repo describes both the concept and the setup process in great details. For a quick overview, read up to the demo video.

There is also a presentation of Tripwire available on the Counter Surveil podcast: https://www.youtube.com/watch?v=s-wPrOTm5qo

Microservices Should Form a Polytree

2025-12-08 @ 07:24:49Points: 35Comments: 33

He set out to walk around the world. After 27 years, his quest is nearly over

2025-12-07 @ 16:26:45Points: 196Comments: 160

4 billion if statements (2023)

2025-12-06 @ 15:34:26Points: 389Comments: 119

Octo: A Chip8 IDE

2025-12-06 @ 11:17:58Points: 54Comments: 7

Archives

2025

2024

2023

2022