nowfound

Alternatives

Products that do what SBOMHub does

Track vulnerabilities across all your software projects

  1. 1
    Dash0 554

    Your OpenTelemetry native observability tool

    2024

  2. 2
    Opengrep340

    The open source code security engine

    2025

  3. 3
    superlog500

    Make your product bug-free

    Jun 2026 · superlog.sh

  4. 4

    Fix bugs faster with open source, AI native observability

    2025

  5. 5

    An open source security scanner for Visual Studio Code

    2020

  6. 6SS

    Excited to share the project I've been working on for the past 7 months! We've seen nearly weekly attacks against the open source software supply chain. I saw the seeds of this trend start in the mid 2015s as an open source maintainer and I've watched it only get worse over the years. I finally decided to try to solve this problem. Socket is taking an entirely new approach to one of the hardest problems in security in a stagnant part of the industry that has historically been obsessed with just reporting on known vulnerabilities. Unlike other scanning tools, Socket actually analyzes the…

    2022 · socket.dev

  7. 7

    Find vulnerabilities in open-source code.

    2016

  8. 8SZ

    We're launching SecureBuild: https://securebuild.com — a new way for open source projects and maintainers to earn revenue by partnering with and endorsing our Zero-CVE container images of their project. We’ve spent the last decade at Replicated (https://news.ycombinator.com/item?id=9841243) helping commercial and open source software vendors securely distribute their apps to enterprise environments. During that time, we saw firsthand how hard it is for maintainers to fund their work, and how increasingly demanding enterprises have become when it comes to demonstrable…

    2025 · securebuild.com

  9. 9
    FOSSA184

    Effortlessly track & comply with open source licenses

    2017

  10. 10

    hey guys, wanted to show one of my side projects i just made public. the idea is basically another osint tool for pentesters and bug bounty hunters. it watches certificate transparency logs and checks newly-seen domains for exposed stuff like .env files, open .git dirs, config files, db dumps and so on, and puts whatever it finds into a searchable db. you just search a domain (or part of one) and see what's exposed. it's read-only and free. one thing i've been thinking about adding is a way to register for certain keywords and get notified when something new shows up for that search. would…

    Jul 2026 · search.cerast-intelligence.com

  11. 11

    Free open-source connectors for data analysts

    2025

  12. 12

    Free IDE extension to ship secure vibe coded projects

    2025

  13. 13BO

    Hi HN, we’re the co-founders of Bearer, and today we launch an open-source alternative to code security solutions such as Snyk Code, SonarQube, or Checkmarx. Essentially, we help security & engineering teams to discover, filter and prioritize security risks and vulnerabilities in their codebase, with a unique approach through sensitive data (PII, PD, PHI). Our website is at https://www.bearer.com and our GitHub is here: https://github.com/bearer/bearer We are not originally Security experts but have been software developers and engineering leaders for over 15…

    2023

  14. 14

    Search millions of open source repos without leaving the IDE

    2022

  15. 15TO

    Hey Xinwei and Zecheng here, we are the authors of TraceRoot (https://github.com/traceroot-ai/traceroot). TraceRoot (https://traceroot.ai) is an open-source debugging platform that helps engineers fix production issues faster by combining structured traces, logs, source code contexts and discussions in Github PRs, issues and Slack channels, etc. with AI Agents. At the heart are our lightweight Python (https://github.com/traceroot-ai/traceroot-sdk) and TypeScript (https://github.com/traceroot-ai/traceroot-sdk-ts) SDKs -…

    2025 · github.com

  16. 16

    High performance secure & portable Rust functions in Node.js

    2020

  17. 17
    Deptic3

    Scan any GitHub repo.Generate SBOMs & detect CVEs instantly.

    Jun 2026 · deptic.netlify.app

  18. 18

    Pixelperfect SBOM analytics

    May 2026 · blitsbom.eu

  19. 19UC

    Hi HN, https://companies.bx.tc My colleague and I put together this tool for easily searching UK company data. We run a few server side batches daily to extract data from various government sources before linking it all together in (what is now) a fairly large database. We're also using this project as a way to test out a new JS UI library we built (similar to Vue, but a bit faster) to see how it stands up in a real project. We'd love to hear your feedback and any ideas you have for how we can improve the dashboard! Thanks :)

    2020

  20. 20

    Find Security Flaws — No Code Needed.

    2025

  21. 21

    Continuous SBOM Risk Management for Software Supply Chains

    Mar 2026 · sbomarchi.us

  22. 22IB

    Linux Foundation survey says 70-90% of modern software constitute OSS code. Yet we are stuck with tools that scan only for vulnerabilities in 3rd party libraries and that too with high degree of false positives. I built `vet` for policy and data driven analysis of 3rd party packages that goes beyond only vulnerability and allows codifying organisational policies related to OSS consumption. https://github.com/safedep/vet Looking forward to feedback and suggestions from HN :)

    2023 · github.com

  23. 23

    Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs)

    Jul 2026 · github.com

  24. 24

    Track your products. We’ll watch the vulnerabilities.

    Dec 2025 · vulntracker.io

Ranked by how close each launch is in meaning, then by votes. Refine with a description →