Hacker News

Show HN: Hexagonal Game of Life Explorer

Hacker News - Tue, 07/21/2026 - 1:04pm

I've been working on this Game of Life Explorer Webapp for a couple of years now (later with LLM assistance). It's a browser-based simulator for hexagonal cellular automata where you can design, clone, mutate and evolve rulesets. I'm using Rust/WASM, WebGL2 and Web Workers to get the highest possible performance despite running on a Web browser. I put a lot of effort and time into fleshing out the functionality to make it as easy and enjoyable to use as possible. Granted it takes a special kind of curiosity to enjoy playing around with Cellular Automata.

The features I enjoy the most:

- Constraining Rulesets to Rotational Symmetry

- Cloning and Mutating Rulesets

- Coloring Cells based on the Rule that caused their current state

Intentional limitations:

- Hexagonal Grid with a maximum size of 576x666 toroidally wrapped

- binary states

- neighbourhood distance of 1

Everything is 100% open-source, I really appreciate feedback.

Comments URL: https://news.ycombinator.com/item?id=48995088

Points: 1

# Comments: 0

Categories: Hacker News

A private enterprise AI gateway

Hacker News - Tue, 07/21/2026 - 1:03pm

Article URL: https://github.com/astaxie/TokenHub

Comments URL: https://news.ycombinator.com/item?id=48995071

Points: 1

# Comments: 0

Categories: Hacker News

Text as Music

Hacker News - Tue, 07/21/2026 - 12:59pm
Categories: Hacker News

Show HN: PMG, open source package firewall

Hacker News - Tue, 07/21/2026 - 12:58pm

Hi HN

I am the founder of SafeDep. We have been detecting malicious packages for a while. Coming from DevSecOps background, I always considered malicious package detection & protection to be a build stage problem. But I was wrong since the S1ngularity and early Shai-Hulud days.

In 2026, we pretty much started worrying more about our own dev machines than CI/CD environment. Depending only on threat intelligence data (OSV / SafeDep / Socket / any other source) to protect our own dev machines did not feel right. We wanted to build a multi-layered protection that can get 100% visibility of OSS packages coming in, and can protect against known and “hopefully” unknown threats. That’s how Package Manager Guard (PMG) started. Core idea was simple:

- Start a local proxy (localhost)

- Make sure supported package managers like npm, pnpm, pip etc. goes through it

- Use threat intelligence data to fail fast on known malicious packages

- Apply policies like dependency cooldown as additional guardrails

- Adopt a policy language like CEL to support custom policies (roadmap)

- Everything stays local with stackable policies and audit log

- Threat model - Protect “willing” developers against malicious open source packages

Note: PMG does not consider a malicious developer as part of its threat model. So no real effort has been put to “enforce”, rather the goal is reduced friction while being effective.

Then came across Anthropic’s SRT and suddenly realized that in-process OS-native sandboxing is a good solution for limiting blast radius against unknown threats, especially since package managers have predictable runtime behaviour that can be allowed via. a sandbox while denying larger user permissions. Adopted seatbealt on MacOS and Landlock + Seccomp BPF for Linux. Seccomp BPF with Go was a battle of its own due to lack of control on OS threads, but finally managed to get it working without major performance cost.

To summarize, PMG does not only depend’s on SafeDep’s ability to find malicious packages. It enforces dependency cooldown (useful if you are stuck with older npm/pnpm), sandbox to protect against malicious packages. Our near term goal is to support CEL as a policy language and improve tooling around sandbox rules to make adoption easier.

Any feedback is welcome.

Comments URL: https://news.ycombinator.com/item?id=48994997

Points: 1

# Comments: 0

Categories: Hacker News

Pages