Alternatives
Products that do what Weedout does
Find risky dependencies before they reach production
- 1MU
Most feedback tools are built like people actually want to report bugs. They don’t. Unless you make it dead-simple, or better yet - a little fun. After shipping a few SaaS products, I noticed a pattern: Bugs? Yes. Bug reports? No. Not because users didn’t care but because reporting bugs is usually a terrible experience. Most tools want users to: * Fill out a long form * Enter their email * Describe a bug they barely understand * Maybe sign in or create an account * Then maybe submit it Let’s be real: no one’s doing that. Especially not someone just trying to use your product. So I built…
2025
- 2

- 3NF
2014 · vuln.pub
- 4

- 5

- 6

- 7NI
Our package registry ecosystem has a serious problem... and not just npm. People are aware of this but maybe this will make them a bit more aware
2022 · github.com
- 8

- 9

- 10

- 11

- 12

- 13

- 14

- 15

- 16

- 17

- 18

- 19

- 20TD
Trusty - Search for an open source package to understand its trustworthiness based on activity, provenance, and more. Brought to you by the founders of projects such as Kubernetes and Sigstore. Hey, Luke here the CTO of stacklok. This is an early experimental preview of Trusty. We use statistical analysis to observe millions of packages and found that Malware typically follows certain patterns. We found this tool really useful to help understand the packages we our pulling into our software and wanted to share it with others. It's still early in and we have a lot more features that will be…
2023 · trustypkg.dev
- 21

- 22MA
2023 · exploit.observer
- 23PS
Hey HN, it's Farrukh and Umar. We're building listen.dev–a tool for proactive security monitoring in GitHub Actions to secure software releases from supply chain threats. Why we built this: As friends and collaborators for over a decade, we've been working on various startup ideas in dev tools and infrastructure. In 2017, while building an ML ops toolkit on Kubernetes, we got hacked. During a pilot with a fintech customer, our cluster became victim to a crypto-jacking attack. As it turned out, a dependency in our container base image contained malware (a Monero miner) which triggered inside…
2024
- 24

Ranked by how close each launch is in meaning, then by votes. Refine with a description →