nowfound

Alternatives

Products that do what GitHub does

https://github.com/zakariazakia15-jpg/EagleEye

  1. 1

    A useful app for GitHub Notifications

    2017

  2. 2

    Run Claude, Codex & Copilot directly in GitHub & VS Code

    Feb 2026 · github.blog

  3. 3
    Scope91

    Customizable birdeye's view of your Github project

    2017

  4. 4

    Secure your JavaScript supply chain – block malware packages

    2022

  5. 5

    Real-time AI cheating detection for technical interviews

    May 2026 · zeroassist.in

  6. 6BB

    This is a simple single-file python program that can find basic XSS (cross-site scripting) vulnerabilities in a target url. Most XSS discovery tools use a payload refelection strategy in which payloads are injected in url parameters and the GET response is inspected for places where the payload content is reflected. This is a very low precision XSS detection strategy because most reflection does not support execution. This program uses a different approach, and instead opens the target url in a browser, tests alert(...) payloads directly in the browser context, and listens for an alert being…

    2024 · github.com

  7. 7PS

    Hey HN, it's Farrukh and Umar. We're building listen.dev–a tool for proactive security monitoring in GitHub Actions to secure software releases from supply chain threats. Why we built this: As friends and collaborators for over a decade, we've been working on various startup ideas in dev tools and infrastructure. In 2017, while building an ML ops toolkit on Kubernetes, we got hacked. During a pilot with a fintech customer, our cluster became victim to a crypto-jacking attack. As it turned out, a dependency in our container base image contained malware (a Monero miner) which triggered inside…

    2024

  8. 8IB

    I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…

    2025 · github.com

  9. 9AM

    I made an open source, MIT license Typescript library based on some of the latest research that generates prompt injection attacks. It is a super minimal/lightweight and designed to be super easy to use. Keen to hear your thoughts and please be responsible and only pen test systems where you have permission to pen test!

    2025 · prompt-injector.blueprintlab.io

  10. 10KD

    I built this after seeing multiple teams accidentally ship API keys in their frontend code. The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone. KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT…

    Nov 2025 · github.com

  11. 11

    A security scanner for Github Actions that doesn't $uck

    Mar 2026

  12. 12
    OurBase24

    AI finds the bug. You ship the fix.

    Jun 2026 · ourbase.ai

  13. 13

    Tiny, offline prompt-injection scanner for CI pipelines

    Apr 2026 · github.com

  14. 14
    grekt5

    The open artifact manager for AI tools

    Feb 2026 · grekt.com

  15. 15

    Open-source malware scanner and runtime guard for AI agents

    Jul 2026 · panguard.ai

  16. 16GA
  17. 17IM
  18. 18
    OpzyAI7

    Finds what your AI-built app leaks — your editor fixes it

    Jul 2026 · opzyai.com

  19. 19

    Automated GitHub Pull Request Security Scanner

    Jun 2026

  20. 20VN

    If you are worried about the recent Lazarus group software supply chain attack, you should consider having guard rails that is more than conventional SCA. `vet` detects the package (version) published in the report as malware. Try out vet, its free and open source: https://github.com/safedep/vet More details on the attack: https://www.nodejs-security.com/blog/north-korea-malware-on-...

    2023 · github.com

  21. 21

    Make AI-built code reviewable before it ships

    20d ago · gitghost.ai

  22. 22KI

    Hey HN, As an AppSec engineer, I’ve spent a lot of time running and tunning open-source security scanners like Trivy, Semgrep, Gitleaks and Dojo. What I have found is that running them is easy, reviewing the results, not so much. Each tool outputs different JSON, false positives pile up, and CI either becomes noisy or blocks everything. So I built Kekkai (formerly Hokage), a small open-source CLI that wraps these scanners and focuses specifically on human triage. Kekkai runs the scanners in isolated Docker containers, normalizes their outputs into a single format, and provides an interactive…

    Feb 2026

  23. 23

    Free open-source web scanner with an AI fix advisor

    Jul 2026 · bugbounty-arsenal.net

  24. 24OS

    We built an open-source library of 125 GTM (go-to-market) skills that plug into AI coding agents like Claude Code, Codex, and Cursor. With these skills an AI agent can automatically: - Find ICP leads from conference speakers, LinkedIn activity, or job boards - Generate personalized cold email sequences - Monitor competitor blogs, pricing pages, and hiring signals - Generate programmatic SEO pages from keyword lists - Track where your brand appears in ChatGPT, Perplexity, and Claude answers --- How skills work Each skill is a structured markdown file containing instructions, scripts, and tool…

    Mar 2026 · github.com

Ranked by how close each launch is in meaning, then by votes. Refine with a description →