source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
SATURDAY, SEPTEMBER 26, 2026
X 主题热门3527Hacker News3469CNBC67YahooFinance58aihot54Verge529to5Mac43IGN42MacRumors40Kotaku35Engadget28TechCrunch269to5Google24NintendoLife21AndroidAuthority20Eurogamer18Guardian18ArsTechnica16Wccftech14BusinessInsider13FoxBusiness13Investor'sBusinessDaily13Polygon13PushSquare13TechPowerUp13Fortune12USAToday12Gematsu11Gizmodo11VideoGamesChronicle10CNN9NintendoEverything9NPR9CBS8CNET8MotleyFool8GSMArena8Mashable8NBC8SeekingAlpha8AndroidPolice7BleepingComputer7Notebookcheck7PureXbox7VideoCardz7WarhammerCommunity7ABC6bgr6Fox6AlJazeera5AppleInsider5CoinDesk5DroidLife5GamesIndustry.biz5HollywoodReporter5NewYorkPost5PetaPixel5PokeBeach5Tom'sGuide5Yahoo5AndroidCentral4GameInformer4InsiderGaming4PlayStationLifeStyle4SlashGear4TechSpot4Conversation4Hacker4WIRED4Aftermath3BellofLostSouls3Deadline3Electrek3EventHubs3Futurism3GAMINGbible3GearPatrol3Hackaday3HuffPost3Lifehacker3Motor13XBOXWire3PCMag3RockPaperShotgun3SamMobile3SouthChinaMorningPost3UploadVR3WhatHi-Fi?3WindowsCentral3WSB-TV3404Media26abcPhiladelphia2ABC7LosAngeles2AndroidHeadlines2AZFamily2Benzinga2ChromeUnboxed2DCRainmaker2HouseDigest2Jalopnik2MyNintendo2Nature2CrudeOilPricesToday2Pokemon2RoadtoVR2RPGSite2SFGATE2SimsCommunity2TimeExtension2TODAY2TweakTown2Variety224/7WallSt.180Level1ageofempires1Alternet1Anthropic1Apple1ArizonaSports1BostonGlobe1BusinessTimes1BuzzFeed1Yahoo!FinanceCanada1CarandDriver1CarBuzz1cbn1CineD1ClaimDepot1ColoradoSun1Skin.ClubCommunity1consequence1CreativeBloq1YahooCreators1ChristianScienceMonitor1Currently1DailyKos1DaringFireball1DarkHorizons1Decrypt1Deseret1Designboom1Dezeen1DigitalCameraWorld1DirtonDirt1Draftsim1DSOGaming1GameGPU1erictopol.substack1ForexFactory1franchisetimes1Futurity1GameRant1GameWorldObserver1GeekWire1GeekyGadgets1Global1GosuGamers1Gothamist1Hackster.io1HoustonChronicle1iLovetheUpperWestSide1InsideEVs1InterestingEngineering1investor.costco1Invezz1iPhoneinCanada1KCRA1MacObserver1Magic:Gathering1MakeUseOf1Mashed1MLive1MortgageDaily1Motorsport1MP1st1mtgrocks1NBC5Chicago1BloombergLaw1Newsweek1NintendoWire1NYT1OneMileataTime1OregonPublicBroadcasting1OregonLive1PersonaCentral1Phoronix1PickupTruck+SUVTalk1politico.eu1Psyche1qz1Realtor1Road&Track1Salon1ScienceDaily1SeattleRed1SeattleTimes1Semafor1SanFranciscoChronicle1YahooFinanceSingapore1SimpleFlying1GhostHowls1Slate1SlippedDisc1SlowBoring1SoraNews241SpaceNews1statnews1YahooTech1the5krunner1DailyBeast1DailyMeal1Drive1Hindu1Intercept1Register1Times1TimesofIndia1TMZ1TopGear1YahooFinanceUK1PCMagUK1Vulture1WCVB1WFMZ1WHYY1WKYT1YGOrganization1
  1. 001Hacker NewsSEP · 25English

    Perch: Semantic Code Linting with Jev

    Perch is a semantic code linting tool that uses Jev to analyze code for defects. Users can install it via npm, configure it with a TypeSafe API key, and run scans to identify issues like wrong order, inverted conditions, and off-by-one errors with severity levels and confidence scores.

    By Lakeday-Org
  2. 002Hacker NewsSEP · 25English

    Shipledger – verify that release notes match what shipped

    Shipledger is a tool that verifies release notes match actual git commits. It compares manually-written release notes against local git history without generating notes or calling GitHub. The demo shows a passing check for v0.2.0 and a failing check for v0.3.0 due to a missing commit reference.

    By Kacxx
  3. 003Hacker NewsSEP · 24English

    Vibe Coding Production Kit – a production workflow for AI coding agents

    Vibe Coding Production Kit (VCP) is a model-agnostic CLI and operating system for AI-assisted software development that structures vague coding workflows into repeatable engineering lifecycles with specifications, architecture, verification, security, and safe updates. It works with multiple coding agents including Claude Code and GitHub Copilot, requiring Node.js 22+ with no runtime dependencies.

    By Moeeryani
  4. 004Hacker NewsSEP · 24English

    Issue Graph

    issue-graph is a CLI tool that traces linked GitHub issues and pull requests to help developers find related work, competing changes, and unresolved follow-ups before starting work. It supports various output formats including terminal, Markdown, JSON, and interactive HTML exploration, with history tracking and agent integration capabilities.

    By Vercel-Labs
  5. 005Hacker NewsSEP · 24English

    Show HN: Depglobe – A 3D globe of the people behind your repo's dependencies

    Depglobe is a browser-based tool that visualizes the maintainers of a software repository's dependencies on an interactive 3D globe. It supports multiple package managers including npm, PyPI, Go, and Cargo, requiring no authentication token.

    By drk1rd
  6. 006Hacker NewsSEP · 21English

    Why Does an NPM Math Library Need an Encrypted Loader?

    A malicious npm package impersonating mathjs contains an encrypted remote access implant that activates when a specific equation is solved. The loader uses the matrix data as a decryption key to reveal and execute a payload that accepts attacker commands via chat services and blockchain networks. Similar implants were found in two other copycat packages on npm.

    By SafeDep Team
  7. 007Hacker NewsSEP · 21English

    Jev-Leftpad

    Jev-Leftpad is an npm package that left-pads strings using an AI model (Jev) via TypeSafe's API instead of JavaScript's built-in padStart(). It supports padding up to 10 spaces, requires Node.js 20+, and is intended as a humorous demonstration rather than production code.

    By fka
  8. 008Hacker NewsSEP · 20English

    Malicious NPM packages evade install-script defenses at runtime

    A malicious npm campaign distributing the 'indexed-btree' package and nine related libraries bypasses GitHub's 2026 supply chain defenses by hiding malware in runtime code execution rather than installation scripts. The malware collects system information and uses Ethereum smart contracts for command-and-control, with the campaign achieving millions of downloads across affected packages.

    By Bill Toulas
  9. 009Hacker NewsSEP · 20English

    Show HN: Openmsg, agent-to-agent talk while they run, Claude<>Codex<>OpenCode

    Openmsg is a tool enabling inter-agent communication between different AI coding platforms (Claude, Codex, OpenCode) running simultaneously on one or multiple machines. Version 0.2 supports secure end-to-end encrypted messaging between two people across machines, with cryptographic identity verification and fine-grained access controls ensuring agents only receive authorized messages within their projects.

    By Marciob
  10. 010Hacker NewsSEP · 20English

    TanStack supply-chain attack exposed ~170 private CrowdSec repos

    TanStack supply-chain attack in May 2026 compromised an NPM package repository, leading to unauthorized access of approximately 170 private CrowdSec GitHub repositories by a BreachForum member on May 22nd. CrowdSec discovered and responded to the incident starting September 16th with credential rotation and forensic investigation, finding that while private code was exposed, the primary risk concerned any embedded credentials that required immediate deprecation.

    By fourfire