frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Detail, a Bug Finder

https://detail.dev/
22•drob•1h ago
Hi HN, tl;dr we built a bug finder that's working really well, especially for app backends. Try it out and send us your thoughts!

Long story below.

--------------------------

We originally set out to work on technical debt. We had all seen codebases with a lot of debt, so we had personal grudges about the problem, and AI seemed to be making it a lot worse.

Tech debt also seemed like a great problem for AI because: 1) a small portion of the work is thinky and strategic, and then the bulk of the execution is pretty mechanical, and 2) when you're solving technical debt, you're usually trying to preserve existing behavior, just change the implementation. That means you can treat it as a closed-loop problem if you figure out good ways to detect unintended behavior changes due to a code change. And we know how to do that – that's what tests are for!

So we started with writing tests. Tests create the guardrails that make future code changes safer. Our thinking was: if we can test well enough, we can automate a lot of other tech debt work at very high quality.

We built an agent that could write thousands of new tests for a typical codebase, most "merge-quality". Some early users merged hundreds of PRs generated this way, but intuitively the tool always felt "good but not great". We used it sporadically ourselves, and it usually felt like a chore.

Around this point we realized: while we had set out to write good tests, we had built a system that, with a few tweaks, might be very good at finding bugs. When we tested it out on some friends' codebases, we discovered that almost every repo has tons of bugs lurking in it that we were able to flag. Serious bugs, interesting enough that people dropped what they were doing to fix them. Sitting right there in peoples codebases, already merged, running in prod.

We also found a lot of vulns, even in mature codebases, and sometimes even right after someone had gotten a pentest.

Under the hood: - We check out a codebase and figure out how to build it for local dev and exercise it with tests. - We take snapshots of the built local dev state. (We use Runloop for this and are big fans.) - We spin up hundreds of copies of the local dev environment to exercise the codebase in thousands of ways and flag behaviors that seem wrong. - We pick the most salient, scary examples and deliver them as linear tickets, github issues, or emails.

In practice, it's working pretty well. We've been able to find bugs in everything from compilers to trading platforms (even in rust code), but the sweet spot is app backends.

Our approach trades compute for quality. Our codebase scans take hours, far beyond what would be practical for a code review bot. But the result is that we can make more judicious use of engineers’ attention, and we think that’s going to be the most important variable.

Longer term, we think compute is cheap, engineer attention is expensive. Wielded properly, the newest models can execute complicated changes, even in large codebases. That means the limiting reagent in building software is human attention. It still takes time and focus for an engineer to ingest information, e.g. existing code, organizational context, and product requirements. These are all necessary before an engineer can articulate what they want in precise terms and do a competent job reviewing the resulting diff.

For now we're finding bugs, but the techniques we're developing extend to a lot of other background, semi-proactive work to improve codebases.

Try it out and tell us what you think. Free first scan, no credit card required: https://detail.dev/

We're also scanning on OSS repos, if you have any requests. The system is pretty high signal-to-noise, but we don't want to risk annoying maintainers by automatically opening issues, so if you request a scan for an OSS repo the results will go to you personally. https://detail.dev/oss

Comments

howinator•1h ago
I played around with Detail recently and it was super helpful to point me directly to the code causing some bugs that I know I had, but wasn't sure about the root cause.

Waxing philosophical a bit, I think tools like these are going to be super helpful as our collective understanding of the codebases we own decreases over time due to the proliferation of AI generated code. I'm not making a value judgement here, just pointing out that as we understand codebases less, tools that help us track down the root causes of bugs will be more important.

sbruchmann•1h ago
Got redirected to a 404 after signing in with GitHub:

https://app.detail.dev/onboarding

drob•1h ago
Fix is deploying, sorry about that!
dbworku•52m ago
Very impressed with the results on our repo. Great stuff for managing all of the AI slop.
chrsw•32m ago
How does this work if your repos aren't on GitHub? And what if your code has nothing to do with backend web apps?
drob•27m ago
Github only for now. Out of curiosity, is yours on gitlab? Something else?

We should be able to find something interesting in most codebases, as long as there's some plausible way to build and test the code and the codebase is big enough. (Below ~250 files the results get iffy.) We've just tested it a lot more thoroughly on app backends, because that's what we know best.

ZeroConcerns•22m ago
So, this is only for codebases hosted on Github, right? Any plans for folks not in that ecosystem? And which languages do you support? The examples show Go, (Type|Java)Script, Python, Rust and Zig, which is rather diverse, but lacks some typical 'enterprise' options. The examples look nice and quite different from the usual static analyzer slop, so that is welcome!
drob•19m ago
Just github for now, but purely for reasons of plumbing. We'll add gitlab and others.

We support java, c/c++, kotlin, ruby, and swift as well. Did you have something specific in mind?

ZeroConcerns•15m ago
My immediate personal use case would be C# on a self-hosted Gitea instance.

Realistically, anything paid would need to be fully self-hostable, though. There's a bunch of Java codebases that I work on that would benefit from something like this, but they're all behind two or three layers of Citrix...

More people crowdfunded basic needs in 2025, GoFundMe report shows

https://www.fastcompany.com/91457282/gofundme-year-in-help-report-crowdfunding-basic-needs
1•geox•1m ago•0 comments

Prediction: AI will make formal verification go mainstream

https://martin.kleppmann.com/2025/12/08/ai-formal-verification.html
1•gritzko•1m ago•0 comments

Taxonomy, Ontology, Knowledge Graph, and Semantics [video]

https://www.youtube.com/watch?v=sr257blfdY8
1•vamsi_kurama•2m ago•0 comments

Linux Kernel Version Numbers

http://www.kroah.com/log/blog/2025/12/09/linux-kernel-version-numbers/
1•stefanhoelzl•4m ago•0 comments

54% of 22–32‑year‑old finance professionals "love" Excel

https://windowsforum.com/threads/excel-in-modern-finance-generational-love-ai-and-governance.393026/
1•sh_tomer•5m ago•0 comments

1 html search engine

https://k8o5.github.io/search
1•k8o5•6m ago•0 comments

10 Years of Let's Encrypt

https://letsencrypt.org/2025/12/09/10-years
2•SGran•6m ago•0 comments

Marketing for games, a metric dashboard to help indiedevs to find creators

https://www.marketingforgames.com/
1•benithemaker•6m ago•0 comments

Show HN: DepsShield – Real-time dependency security for AI coding agents

https://depsshield.com
1•mikehanol•7m ago•0 comments

Adactio: Journal–Installing Web Apps

https://adactio.com/journal/22278
1•ulrischa•9m ago•0 comments

ASML sold chip machine parts to Chinese military and quantum research institutes

https://nltimes.nl/2025/12/09/asml-sold-chip-machine-parts-chinese-military-quantum-research-inst...
1•giuliomagnifico•9m ago•0 comments

Claude Island

https://github.com/farouqaldori/claude-island
1•handfuloflight•9m ago•0 comments

Quick Docker Tutorial to Run a Python Script

https://en.andros.dev/blog/5d4edfbf/quick-docker-tutorial-to-run-a-python-script/
2•ibobev•9m ago•0 comments

Bublr – If Pinterest and Substack had a child

https://www.bublr.life/
1•SolomonLijo•10m ago•1 comments

What companies can learn from past products we love – a retro tech gift guide

https://caseorganic.medium.com/what-companies-can-learn-from-past-products-we-love-and-an-alterna...
1•SLHamlet•10m ago•1 comments

Modern SQL: Beyond Relational

https://modern-sql.com/
1•ciconia•11m ago•0 comments

Kill old app versions instantly

https://teardown.dev
1•UrbanChrisy•15m ago•1 comments

Japan warns of possible megaquake after powerful earthquake, 98-foot tsunami

https://www.cbsnews.com/news/japan-earthquake-megaquake-advisory-tsunami/
1•mikhael•16m ago•1 comments

The Vault Guy

https://www.science.org/content/article/biologist-aims-solve-cell-s-biggest-mystery-could-it-help...
1•mzs•17m ago•0 comments

Why AI reading science fiction could be a problem

https://www.transformernews.ai/p/why-ai-reading-science-fiction-could
1•bookofjoe•18m ago•0 comments

So You Want to Speak at Software Conferences?

https://dylanbeattie.net/2025/12/08/so-you-want-to-speak-at-software-conferences.html
5•speckx•19m ago•0 comments

What I Wish I Knew When I Started in Identity

https://sphericalcowconsulting.com/2025/12/09/starting-in-identity/
1•mooreds•19m ago•0 comments

The CLaRa-7B models unify RAG and provide built-in semantic doc compression

https://huggingface.co/apple/CLaRa-7B-Base
1•anactofgod•19m ago•1 comments

The Birth of the Internet Troll (2014)

https://gizmodo.com/the-first-internet-troll-1652485292
3•fanf2•19m ago•0 comments

NPM classic tokens revoked, session-based auth and CLI token management now

https://github.blog/changelog/2025-12-09-npm-classic-tokens-revoked-session-based-auth-and-cli-to...
1•sdko•20m ago•0 comments

Ask HN: IPv6 capable transactional email senders?

1•hevisko•21m ago•0 comments

'Food and fossil fuel production causing $5B of environmental damage an hour'

https://www.theguardian.com/environment/2025/dec/09/food-fossil-fuel-production-5bn-environmental...
1•ndsipa_pomu•24m ago•0 comments

Crunchyroll Is Shutting Down Its Free Ad-Supported Plan

https://cordcuttersnews.com/crunchyroll-is-shutting-down-its-free-ad-supported-plan/
1•akyuu•24m ago•0 comments

0.5.0 release for protoc-gen-prost with buf.build

https://old.reddit.com/r/rust/comments/1pif945/new_protocgenprost_release
1•mxplusb•24m ago•0 comments

Former Twitter Attorney Files for 'Twitter' Trademark

https://www.gerbenlaw.com/blog/former-twitter-attorney-files-for-twitter-trademark-challenges-x-c...
4•edent•25m ago•1 comments