nowfound

Alternatives

Products that do what GitHub does

Enterprise-grade CI DAST for your APIs. Free. Open source.

  1. 1

    Discover, Scan, and Secure every API at scale

    2025

  2. 2

    World's most intelligent web app & API security scan tool

    2024

  3. 3
    ZeroBlur266

    Blur sensitive information and share screen with confidence

    2021

  4. 4

    A free React/NodeJS SaaS template for quick idea execution

    2023

  5. 5

    Fully managed web application scanning & risk detection

    2020

  6. 6CA

    Hey Hacker News! Launching gptengineer.app into beta today. It's like Claude Artifacts, but: - you can edit the code in your fav IDE (two-way github sync) - installs npm packages - automatically picks up build and runtime errors and fixes them - very fast, built with rust The full stack capabilities are built on supabase (prefer to not have to handle auth + user data at this point so this is owned by the user) The seed for this project was an open source experiment, posted about that previously here: https://news.ycombinator.com/item?id=36422730 Would love feedback if you give…

    2024 · gptengineer.app

  7. 7SZ

    We're launching SecureBuild: https://securebuild.com — a new way for open source projects and maintainers to earn revenue by partnering with and endorsing our Zero-CVE container images of their project. We’ve spent the last decade at Replicated (https://news.ycombinator.com/item?id=9841243) helping commercial and open source software vendors securely distribute their apps to enterprise environments. During that time, we saw firsthand how hard it is for maintainers to fund their work, and how increasingly demanding enterprises have become when it comes to demonstrable…

    2025 · securebuild.com

  8. 8
    0xAudit110

    The security layer for AI agents to scan, fix verify via MCP

    Feb 2026

  9. 9OT

    hey guys, wanted to show one of my side projects i just made public. the idea is basically another osint tool for pentesters and bug bounty hunters. it watches certificate transparency logs and checks newly-seen domains for exposed stuff like .env files, open .git dirs, config files, db dumps and so on, and puts whatever it finds into a searchable db. you just search a domain (or part of one) and see what's exposed. it's read-only and free. one thing i've been thinking about adding is a way to register for certain keywords and get notified when something new shows up for that search. would…

    Jul 2026 · search.cerast-intelligence.com

  10. 10BO

    Hi HN, we’re the co-founders of Bearer, and today we launch an open-source alternative to code security solutions such as Snyk Code, SonarQube, or Checkmarx. Essentially, we help security & engineering teams to discover, filter and prioritize security risks and vulnerabilities in their codebase, with a unique approach through sensitive data (PII, PD, PHI). Our website is at https://www.bearer.com and our GitHub is here: https://github.com/bearer/bearer We are not originally Security experts but have been software developers and engineering leaders for over 15…

    2023

  11. 11

    Real-time AI cheating detection for technical interviews

    May 2026 · zeroassist.in

  12. 12MN

    This is an educational reference implementation showing how to build reasonably secure, standards-compliant authentication from first principles on Cloudflare Workers. Stack: Hono, Turso (libSQL), PBKDF2-SHA384 + normalization + common-password checks, JWT access + refresh tokens with revocation support, HTTP-only SameSite cookies, device tracking. It's deliberately minimal — no OAuth, no passkeys, no magic links, no rate limiting — because the goal is clarity and auditability. I wrote it mainly to deeply understand edge-runtime auth constraints and to have a clean Apache-2.0 example that…

    Feb 2026 · github.com

  13. 13

    Safeguard & Self-Heal your Software Supply Chain (Zero Days)

    27d ago · safeguard.sh

  14. 14NI
  15. 15IB

    I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…

    2025 · github.com

  16. 16

    Hosted vuln scanning with client-ready reports

    Jul 2026 · vulnscanners.com

  17. 17

    Instant form alerts via Push, Slack & LINE—no more spam

    Jan 2026

  18. 18

    Not just another scanner - Real OWASP and NIST insights

    Mar 2026

  19. 19

    Affordable security scans for startup founders

    Feb 2026

  20. 20SS
  21. 21

    Secret scanning for shipped-too-fast websites

    Jan 2026

  22. 22

    Find web vulnerabilities before hackers do.

    Jul 2026 · shieldome.com

  23. 23

    Modern API monitoring for indie hackers & small teams

    Feb 2026

  24. 24TS

    Hi HN, I’m Guillaume, the cofounder of Bearer, an Open Source SAST solution. After launching a few weeks ago here on Hacker News with support for Ruby and JavaScript stacks, I’m happy to report we’ve just released a new version (v1.2) with TypeScript support! In terms of code coverage, we use the same rules already implemented for vanilla JavaScript, but as usual, you can build your own. The rules list is here: https://docs.bearer.com/reference/rules/ It’s a first version for TS, but we believe that thanks to the pre-existing JavaScript support it should already…

    2023

Ranked by how close each launch is in meaning, then by votes. Refine with a description →