frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Hokage – Unified Orchestration for Semgrep, Trivy, and Zap

https://github.com/hokage-sec/hokage-platform
2•kirumachi•2h ago

Comments

kirumachi•2h ago
Hi HN,

I’m one of the creators of Hokage. We built this because we were tired of the usuall spreadsheet hell that comes with running open-source security tools at any reasonable scale.

If you are a small-to-mid-sized team, you likely use tools like Semgrep, Trivy, or Gitleaks. They are great scanners, but they all output different formats, don’t talk to each other, and result in hundreds of duplicate findings that make triage impossible.

Hokage is a self-hosted orchestration layer that attempts to fix this. It runs your scanners and normalizes the output into a Canonical Finding Schema (CFS). This allows us to:

1. Deduplicate findings (e.g., if a linter and a SAST tool find the same bug, we merge them). 2. Provide a single dashboard for triage across multiple repos. 3. Standardize fields (severity, confidence, location) regardless of the underlying engine.

Tech Stack:

- Backend: Python (FastAPI) - Orchestration: Docker / Subprocess wrappers - Database: PostgreSQL

Repo: https://github.com/hokage-sec/hokage-platform

This is an Alpha (Public Preview). It is not feature-complete, and the UX is still rough around the edges. We are releasing now because we need feedback on the data model:

1. Does our canonical schema cover your use cases? 2. Is the deduplication logic too aggressive? 3. Which scanners should we write adapters for next?

You can spin it up locally with Docker Compose to test it out. We’d love to hear your thoughts (and criticism) on the approach.

Thanks!

Ghost resorts: as 100s of ski slopes lie abandoned will nature reclaim the Alps?

https://www.theguardian.com/environment/2025/dec/27/alps-france-skiing-snow-warming-resorts-closi...
1•ourmandave•1m ago•0 comments

Keep the Robots Out of the Gym

https://danielmiessler.com/blog/keep-the-robots-out-of-the-gym
3•Group_B•4m ago•0 comments

Dolphin Progress Release 2512

https://dolphin-emu.org/blog/2025/12/22/dolphin-progress-report-release-2512/
1•akyuu•6m ago•0 comments

Fastverse: A Suite of High-Performance and Low-Dependency R Packages

https://fastverse.org/fastverse/
1•birdculture•7m ago•0 comments

Chain Flinger

https://nealstephenson.substack.com/p/kdk-kinetik-der-kontinua-part-1-introduction
2•roomey•7m ago•0 comments

Debate over surfing in German park after city removes wave-creating device

https://apnews.com/article/surfing-english-garden-munich-germany-ef9148ea4c5bbb779bfa16fc13ac4f32
1•c420•7m ago•1 comments

ADHD and Loneliness: What It's Like to Be "Good with People" and Lonely

https://mindfullofit.substack.com/p/adhd-and-loneliness-what-its-really
1•MindFullOfIt•8m ago•0 comments

Show HN: Desktop‑2FA – offline, encrypted 2FA authenticator for your desktop

https://github.com/wrogistefan/desktop-2fa
2•wrogistefan•9m ago•0 comments

Developing for Embedded Linux with WendyOS

https://swiftonserver.com/wendyos-setting-up-embedded-linux/
1•frizlab•10m ago•0 comments

Meet The South Pacific Ponzi King with a Bogus Bank – and a Global Fan Club

https://www.occrp.org/en/feature/meet-the-south-pacific-ponzi-king-with-a-bogus-bank-and-a-global...
1•rmason•13m ago•0 comments

Trump to hire 1k specialists for 'Tech Force' to build AI, finance projects

https://www.cnbc.com/2025/12/15/trump-ai-tech-force-amazon-apple.html
1•rmason•15m ago•1 comments

I built an API to stop manual data entry from invoices and resumes

1•scannyai•15m ago•0 comments

Feeding your chatbot Drugs A crazy SaaS idea

https://www.pharmaicy.store
3•puildupO•15m ago•2 comments

Why I Disappeared – My week with minimal internet in a remote island chain

https://www.kenklippenstein.com/p/why-i-disappeared
2•eh_why_not•17m ago•0 comments

SWEResume – clean your resume in seconds

https://www.sweresume.app/
1•zed_labs_dev•19m ago•1 comments

LoongArch 64-bit userspace emulation

https://fwsgonzo.medium.com/notes-on-libloong-loongarch-64-bit-emulation-515ea6610cad
1•ingve•20m ago•1 comments

Unity's Mono problem: Why your C# code runs slower than it should

https://marekfiser.com/blog/mono-vs-dot-net-in-unity/
3•iliketrains•21m ago•0 comments

Arch Linux package stats fun statistics

https://pkgstats.archlinux.de/fun
1•zdw•22m ago•0 comments

I tested every Japanese app in last 2 years so you don't have to, these are best

https://old.reddit.com/r/LearnJapanese/comments/1phbsk4/i_tested_every_japanese_app_that_came_out...
1•wahnfrieden•22m ago•0 comments

Reading an OLED display directly into an agent via MCP

https://mastodon.social/@rcarmo/115799340761326831
1•rcarmo•26m ago•0 comments

Soft robots harvest ambient heat for self-sustained motion

https://techxplore.com/news/2025-11-soft-robots-harvest-ambient-sustained.html
2•PaulHoule•29m ago•0 comments

Tips for making the Chrome Performance Panel less overwhelming

https://calendar.perfplanet.com/2025/tips-for-making-the-performance-panel-less-overwhelming/
1•zdw•32m ago•0 comments

I built a neon-style weekly planner for iOS because I hate clutter

https://apps.apple.com/ie/app/weeklii/id6756281596
1•qaengineerfp•33m ago•1 comments

Show HN: Handoff – Claude Code plugin to let any AI continue where you left off

https://github.com/willseltzer/claude-handoff
1•pgspaintbrush•33m ago•0 comments

The Rainforests Being Cleared to Build Your R.V

https://www.nytimes.com/2025/08/19/world/asia/indonesia-borneo-deforestation-rv.html
1•JumpCrisscross•33m ago•0 comments

Software engineers should be a little bit cynical

https://www.seangoedecke.com/a-little-bit-cynical/
26•zdw•34m ago•9 comments

What Helps Kafka Scale

https://shbhmrzd.github.io/2025/11/21/what-helps-kafka-scale.html
1•01-_-•34m ago•0 comments

Pop icon Kate Bush's £10.8M windfall from Stranger Things hit song

https://www.dailymail.co.uk/tvshowbiz/article-15416747/TALK-TOWN-Running-bank-pop-icon-Kate-Bushs...
2•canucker2016•35m ago•0 comments

Determining Current Arm Cortex-M Security State with GDB

https://danielmangum.com/posts/arm-cortex-m-security-state-gdb/
1•hasheddan•37m ago•0 comments

Fake AI videos of snowy Amsterdam leave tourists disappointed, anger tour guides

https://nltimes.nl/2025/12/23/fake-ai-videos-snowy-amsterdam-leave-tourists-disappointed-anger-to...
1•belter•39m ago•0 comments