Alternatives
Products that do what CDK Insights does
Catch security issues in your AWS CDK before deployment
- 1

- 2KD
I built this after seeing multiple teams accidentally ship API keys in their frontend code. The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone. KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT…
Nov 2025 · github.com
- 3LA
2020 · github.com
- 4

Ask your cloud anything without breaking prod. Read-only.
Jul 2026 · github.com
- 5

- 6MA
Hey HN I've been using ECS for a while now and found it annoying having to log into the console everytime I use Lens for Kubernetes but couldnt find an equivalent for ECS so i built one! The project is open source as well https://github.com/utibeabasi6/mercek
Jun 2026 · mercek.dev
- 7

- 8

- 9SC
2021 · github.com
- 10SS
Nov 2025 · smart.mcpshark.sh
- 11AI
Hi HN, I’m one of the co-founders of a startup named Metrist and today we released a free, no login required, “real” status page for AWS service health. I know we aren’t the first to do this, but I think we take a unique approach and we are excited about what we can do with this, and our full product, going forward. As a company, Metrist exists to test and monitor the functionality, performance, and availability of the web’s most built upon cloud products. For this status page, we are running functional tests against 15 of the most popular AWS services, from 5 North American regions, as…
2022 · metrist.io
- 12

- 13IB
I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…
2025 · github.com
- 14
- 15

- 16

A security scanner for Github Actions that doesn't $uck
Mar 2026
- 17
- 18VL
I built a CLI that detects patterns AI coding tools leave behind: empty catch blocks, hardcoded secrets, as any everywhere, comments that restate the code, god functions, SQL concatenation. 24 rules across JS/TS and Python. Zero config, runs offline, regex-based so it's fast. npx @yuvrajangadsingh/vibecheck . Also ships as a GitHub Action for inline PR annotations and standalone binaries (no Node required). Why: CodeRabbit found AI-generated PRs have 1.7x more issues than human PRs. Veracode says 45% of AI code samples have security vulnerabilities. "Vibe coding" is everywhere now…
Mar 2026 · github.com
- 19WA
Hey HN, I'm Jarod. Spent 2 years at SendGrid watching developers struggle with email infrastructure. Built Wraps to fix the SES setup problem. One command or package (CDK & Pulumi) deploys production email infra to your AWS account: `npx @wraps.dev/cli email init` ~30 seconds to configure SES, DKIM/SPF, event tracking, and sandbox exit. You own everything—we just provide the tooling. Key decisions: - BYOC: Deploys to your AWS, you pay AWS directly for sending - Zero credentials stored: OIDC federation only - Open source CLI/SDK: MIT licensed, free forever - No lock-in: Send…
Jan 2026 · wraps.dev
- 20

- 21

- 22IA
2020 · github.com
- 23
- 24

Ranked by how close each launch is in meaning, then by votes. Refine with a description →