nowfound

Dev tools · May 12, 2022

FS

Free secrets scanning for unlimited private GitHub repos

My name is Nir! I am one of the three co-founders of arnica.io. I’ve worn many hats in cyber security over the years – sys admin, pen-tester, security architect, and Chief Information Security Officer (CISO). What really gets me excited about my work is making security easy and effective for developers and ops teams! In my last role, at one of the top 3 FinTechs, following the attack against Solarwinds, the CEO asked me what we are doing to secure our software supply chain. I met with 15+ vendors, did a few POCs, but unfortunately each solution either increased operational cost or was too…

In plain words

Arnica provides secrets scanning for unlimited private GitHub repositories at no cost. The tool detects exposed credentials and sensitive information in code to help development and operations teams secure their software supply chain. It addresses the need for accessible, low-overhead security scanning that integrates directly into developers' existing workflows without adding significant operational burden or complexity.

written from the facts on this page · September 2026

From the sources

In the maker’s words, at launch

My name is Nir! I am one of the three co-founders of arnica.io. I’ve worn many hats in cyber security over the years – sys admin, pen-tester, security architect, and Chief Information Security Officer (CISO). What really gets me excited about my work is making security easy and effective for developers and ops teams! In my last role, at one of the top 3 FinTechs, following the attack against Solarwinds, the CEO asked me what we are doing to secure our software supply chain. I met with 15+ vendors, did a few POCs, but unfortunately each solution either increased operational cost or was too narrow in scope. I really wanted to buy a solution instead building it, but even the ones that hit the short list were rejected by my team (thank you guys!). I also found that many fellow CISOs faced the same problem. This is when I joined forces with my incredible co-founders - Diko and Eran. They were seeing the same pain in their worlds (engineering and ops) too! As a starting point for Arnica, we researched every software supply chain attack since 2018, and based on our research, we found two primary root causes: 1) improper access management to developer tools 2) inability to identify abnormal identity and code behavior We studied the anatomy of each supply chain attack and designed a product to effectively secure developer tool stacks with a DevOps-first approach: 1) Identify excessive permissions to source code starting with GitHub and Azure DevOps repos (free) 2) Mitigate excessive permissions with an ability to regain access via self-service on Slack for your developers 3) Automatically generate & modify a CODEOWNERS file via pull request, based on the contextual behavior of the pull request reviewers 4) Secret detection and validation without modifications of the build pipelines for all repositories, public and private without any user-count limitations (free) 5) Map GitHub users to your SAML/SSO provider. Also free forever. Why are we giving away so much functionality for free? I believe Arnica can do well by doing good in the DevSecOps community. Our mission is to be the easy button for DevOps security. Anything that is considered “single pane of glass” is our free contribution. If we do that first and foremost, we are sure we will build a successful business. ~Nir

Does the same job

all alternatives →
  • GitGuardian2018 · ▲132

    Detect secrets in source code, public and private!

  • IB
  • OS
    Open-source certificate from GitHub activityJan 2026 · certificate.brendonmatos.com · ▲43

    I built this as a small side project to learn and experiment, and I ended up with this! I used a subdomain from my personal portfolio, and everything else runs on free tiers. The project uses Nuxt, SVG, Cloudflare Workers, D1 (SQL), KV, Terraform, and some agentic coding with OpenAI Codex and Claude Code. What started as a joke among friends turned into a fun excuse to build something end to end, from zero to production, and to explore a few things I’d never touched before. I’d really appreciate any feedback or suggestions.

  • PS
    Proactive Security Monitoring for GitHub Actions Workflows2024 · ▲32

    Hey HN, it's Farrukh and Umar. We're building listen.dev–a tool for proactive security monitoring in GitHub Actions to secure software releases from supply chain threats. Why we built this: As friends and collaborators for over a decade, we've been working on various startup ideas in dev tools and infrastructure. In 2017, while building an ML ops toolkit on Kubernetes, we got hacked. During a pilot with a fintech customer, our cluster became victim to a crypto-jacking attack. As it turned out, a dependency in our container base image contained malware (a Monero miner) which triggered inside…

  • AA
    Abusing a GitHub repo as a private certificate authority2024 · github.com · ▲26

    I tend to create a private certificate authority for every side project, in order to create TLS certs for local development. I find it useful to have local development closely resemble production when at all possible, and "real" certificates are an important element. Anyway I got tired of having these CA private keys on my local machine, especially as I started thinking about setting up a private CA for my company (https://riza.io). So I started thinking about what the simplest way to host a private CA might be. You really only need two things: 1) secret storage, to hold the CA's…

  • KG
    kiln – Git-native, decentralized secret management using age2025 · kiln.sh · ▲12

    Hi HN, I've been building this tool for the past couple of weeks to solve a problem that seems universal across development teams: sharing environment variables securely. You know the drill - someone needs the staging database URL, so it gets shared over chat. Production API keys end up in plaintext files. Or you set up some complex secret management system that becomes a single point of failure during critical deployments. At Zerodha, we're a stock broker with strict regulatory requirements. Our infrastructure needs to be auditable, and our data must stay with us for instant recovery. But…

More dev tools this month

the category →
  • Dograh592

    The open source VAPI alternative

    Dev tools · 25d ago · dograh.com

  • Meridian530

    Don't let your work go unnoticed. Get promoted!

    Dev tools · 20d ago · meridiona.com

  • x1516

    Lovable for iPhone apps go from idea to App Store

    Dev tools · 11d ago · x1.new

  • Open-source GTM skills for technical founders

    Dev tools · 29d ago · gtmcofounder.com

  • OpenTrailPaper is open-source bike computer firmware for the LilyGO T5S3 4.7" E-Paper PRO. It supports offline maps, GPX routes, FIT recording and Bluetooth sensors.

    Dev tools · 2d ago · opentrailpaper.com

  • Nuphos380

    The AI-Native DevOps Workspace.

    Dev tools · 24d ago · nuphos.ai

Launched alongside, May 2022

the whole month →