Free secrets scanning for unlimited private GitHub repos
My name is Nir! I am one of the three co-founders of arnica.io. I’ve worn many hats in cyber security over the years – sys admin, pen-tester, security architect, and Chief Information Security Officer (CISO). What really gets me excited about my work is making security easy and effective for developers and ops teams! In my last role, at one of the top 3 FinTechs, following the attack against Solarwinds, the CEO asked me what we are doing to secure our software supply chain. I met with 15+ vendors, did a few POCs, but unfortunately each solution either increased operational cost or was too…
In plain words
Arnica provides secrets scanning for unlimited private GitHub repositories at no cost. The tool detects exposed credentials and sensitive information in code to help development and operations teams secure their software supply chain. It addresses the need for accessible, low-overhead security scanning that integrates directly into developers' existing workflows without adding significant operational burden or complexity.
written from the facts on this page · September 2026
From the sources
In the maker’s words, at launch
My name is Nir! I am one of the three co-founders of arnica.io. I’ve worn many hats in cyber security over the years – sys admin, pen-tester, security architect, and Chief Information Security Officer (CISO). What really gets me excited about my work is making security easy and effective for developers and ops teams! In my last role, at one of the top 3 FinTechs, following the attack against Solarwinds, the CEO asked me what we are doing to secure our software supply chain. I met with 15+ vendors, did a few POCs, but unfortunately each solution either increased operational cost or was too narrow in scope. I really wanted to buy a solution instead building it, but even the ones that hit the short list were rejected by my team (thank you guys!). I also found that many fellow CISOs faced the same problem. This is when I joined forces with my incredible co-founders - Diko and Eran. They were seeing the same pain in their worlds (engineering and ops) too! As a starting point for Arnica, we researched every software supply chain attack since 2018, and based on our research, we found two primary root causes: 1) improper access management to developer tools 2) inability to identify abnormal identity and code behavior We studied the anatomy of each supply chain attack and designed a product to effectively secure developer tool stacks with a DevOps-first approach: 1) Identify excessive permissions to source code starting with GitHub and Azure DevOps repos (free) 2) Mitigate excessive permissions with an ability to regain access via self-service on Slack for your developers 3) Automatically generate & modify a CODEOWNERS file via pull request, based on the contextual behavior of the pull request reviewers 4) Secret detection and validation without modifications of the build pipelines for all repositories, public and private without any user-count limitations (free) 5) Map GitHub users to your SAML/SSO provider. Also free forever. Why are we giving away so much functionality for free? I believe Arnica can do well by doing good in the DevSecOps community. Our mission is to be the easy button for DevOps security. Anything that is considered “single pane of glass” is our free contribution. If we do that first and foremost, we are sure we will build a successful business. ~Nir
Does the same job
all alternatives →
- IBI built a tool that helps people scan and clean any repo for secrets2024 · securelog.com · ▲20
- OSOpen-source certificate from GitHub activityJan 2026 · certificate.brendonmatos.com · ▲43
I built this as a small side project to learn and experiment, and I ended up with this! I used a subdomain from my personal portfolio, and everything else runs on free tiers. The project uses Nuxt, SVG, Cloudflare Workers, D1 (SQL), KV, Terraform, and some agentic coding with OpenAI Codex and Claude Code. What started as a joke among friends turned into a fun excuse to build something end to end, from zero to production, and to explore a few things I’d never touched before. I’d really appreciate any feedback or suggestions.
- PSProactive Security Monitoring for GitHub Actions Workflows2024 · ▲32
Hey HN, it's Farrukh and Umar. We're building listen.dev–a tool for proactive security monitoring in GitHub Actions to secure software releases from supply chain threats. Why we built this: As friends and collaborators for over a decade, we've been working on various startup ideas in dev tools and infrastructure. In 2017, while building an ML ops toolkit on Kubernetes, we got hacked. During a pilot with a fintech customer, our cluster became victim to a crypto-jacking attack. As it turned out, a dependency in our container base image contained malware (a Monero miner) which triggered inside…
- AAAbusing a GitHub repo as a private certificate authority2024 · github.com · ▲26
I tend to create a private certificate authority for every side project, in order to create TLS certs for local development. I find it useful to have local development closely resemble production when at all possible, and "real" certificates are an important element. Anyway I got tired of having these CA private keys on my local machine, especially as I started thinking about setting up a private CA for my company (https://riza.io). So I started thinking about what the simplest way to host a private CA might be. You really only need two things: 1) secret storage, to hold the CA's…
- KGkiln – Git-native, decentralized secret management using age2025 · kiln.sh · ▲12
Hi HN, I've been building this tool for the past couple of weeks to solve a problem that seems universal across development teams: sharing environment variables securely. You know the drill - someone needs the staging database URL, so it gets shared over chat. Production API keys end up in plaintext files. Or you set up some complex secret management system that becomes a single point of failure during critical deployments. At Zerodha, we're a stock broker with strict regulatory requirements. Our infrastructure needs to be auditable, and our data must stay with us for instant recovery. But…
More dev tools this month
the category →



Open-source GTM skills for technical founders
Dev tools · 29d ago · gtmcofounder.com

OpenTrailPaper is open-source bike computer firmware for the LilyGO T5S3 4.7" E-Paper PRO. It supports offline maps, GPX routes, FIT recording and Bluetooth sensors.
Dev tools · 2d ago · opentrailpaper.com

Launched alongside, May 2022
the whole month →
Peerlist▲1,052A professional network w/ robust work profiles at its core
Life & fun · 2022 · peerlist.io



- MA
Life & fun · 2022 · github.com
