frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Whisper – AI code reviewer that catches security issues and bugs

https://www.usewhisper.dev/
1•alameenpd•2w ago
Hi HN, I'm building Whisper (https://usewhisper.dev), an AI code reviewer that does both code quality and security analysis. It traces execution flow to catch SQL injections, auth bypasses, and race conditions that standard PR reviewers miss.

The Problem

AI code reviewers catch style issues. Security scanners only check dependencies. But logical security flaws in YOUR code slip through. The SQL injection that happens because user input flows through three functions before hitting your database. The race condition in payment processing. The auth bypass hidden in middleware.

I've shipped these bugs. Your PR reviewer said "looks good." Your security scanner was green (only checks deps anyway). Two weeks later, a pentester finds the vulnerability that was visible in the PR all along.

Why Compete Against Well-Funded Startups?

Fair question. Greptile raised millions. Codacy, SonarQube, Snyk are giants. Here's my thesis: they're solving the wrong problem.

Most AI reviewers are linters with GPT. They look at the diff and comment on style. Security scanners either only check dependencies or dump 1000+ false positives. The ones that do both? Separate products that don't talk.

I'm building something different: execution flow tracing with semantic understanding. Whisper traces data from user input through your logic to find where it reaches sensitive operations.

The big players can't easily copy this. They're built on pattern matching. Tracing execution flow requires different architecture. And I have advantages:

- Speed: I ship features in days vs their enterprise compliance process - Focus: One problem (security in PRs) vs everything to everyone - Pricing: $30/dev vs their $100-300/seat enterprise model - DX: 2-minute setup vs 45-minute enterprise onboarding

They optimize for enterprise contracts. I optimize for devs who want PRs to stop shipping bugs.

How It Works

Example: Standard reviewers say "looks good"

const user = await getUser(req.headers.auth); const data = await db.query( `DELETE FROM users WHERE id = ${user.id}` );

Whisper traces user.id from JWT payload through getUser() to the SQL template literal. Flags SQL injection. Suggests parameterized queries.

Race condition example:

async function processPayment(userId, amount) { const balance = await getBalance(userId); if (balance >= amount) { await charge(userId, amount); await updateBalance(userId, balance - amount); } }

Whisper spots concurrent requests could cause double-charging between check and update.

Status

Private beta with early engineering teams. 2.4M+ lines analyzed, 1,247 bugs caught, 47s avg scan time. Supports all major languages with deep framework understanding for Next.js, React, and tRPC.

What I Want

Feedback from engineers who: - Are drowning in false positives from scanners - Keep shipping bugs visible in PRs - Think competing here is crazy (tell me why!)

Building mostly solo, no VC. Just solving a problem I kept hitting.

Try free: https://usewhisper.dev

Comments

evs91•2w ago
the name...almost like we have been here before...https://openai.com/index/whisper/
alameenpd•2w ago
i could not come up with a better name to be honest . im sorry but have you tried the product? would seriously love to hear your review .

Tiny Clippy – A native Office Assistant built in Rust and egui

https://github.com/salva-imm/tiny-clippy
1•salvadorda656•3m ago•0 comments

LegalArgumentException: From Courtrooms to Clojure – Sen [video]

https://www.youtube.com/watch?v=cmMQbsOTX-o
1•adityaathalye•6m ago•0 comments

US moves to deport 5-year-old detained in Minnesota

https://www.reuters.com/legal/government/us-moves-deport-5-year-old-detained-minnesota-2026-02-06/
1•petethomas•9m ago•1 comments

If you lose your passport in Austria, head for McDonald's Golden Arches

https://www.cbsnews.com/news/us-embassy-mcdonalds-restaurants-austria-hotline-americans-consular-...
1•thunderbong•14m ago•0 comments

Show HN: Mermaid Formatter – CLI and library to auto-format Mermaid diagrams

https://github.com/chenyanchen/mermaid-formatter
1•astm•29m ago•0 comments

RFCs vs. READMEs: The Evolution of Protocols

https://h3manth.com/scribe/rfcs-vs-readmes/
2•init0•36m ago•1 comments

Kanchipuram Saris and Thinking Machines

https://altermag.com/articles/kanchipuram-saris-and-thinking-machines
1•trojanalert•36m ago•0 comments

Chinese chemical supplier causes global baby formula recall

https://www.reuters.com/business/healthcare-pharmaceuticals/nestle-widens-french-infant-formula-r...
1•fkdk•39m ago•0 comments

I've used AI to write 100% of my code for a year as an engineer

https://old.reddit.com/r/ClaudeCode/comments/1qxvobt/ive_used_ai_to_write_100_of_my_code_for_1_ye...
1•ukuina•41m ago•1 comments

Looking for 4 Autistic Co-Founders for AI Startup (Equity-Based)

1•au-ai-aisl•51m ago•1 comments

AI-native capabilities, a new API Catalog, and updated plans and pricing

https://blog.postman.com/new-capabilities-march-2026/
1•thunderbong•52m ago•0 comments

What changed in tech from 2010 to 2020?

https://www.tedsanders.com/what-changed-in-tech-from-2010-to-2020/
2•endorphine•57m ago•0 comments

From Human Ergonomics to Agent Ergonomics

https://wesmckinney.com/blog/agent-ergonomics/
1•Anon84•1h ago•0 comments

Advanced Inertial Reference Sphere

https://en.wikipedia.org/wiki/Advanced_Inertial_Reference_Sphere
1•cyanf•1h ago•0 comments

Toyota Developing a Console-Grade, Open-Source Game Engine with Flutter and Dart

https://www.phoronix.com/news/Fluorite-Toyota-Game-Engine
1•computer23•1h ago•0 comments

Typing for Love or Money: The Hidden Labor Behind Modern Literary Masterpieces

https://publicdomainreview.org/essay/typing-for-love-or-money/
1•prismatic•1h ago•0 comments

Show HN: A longitudinal health record built from fragmented medical data

https://myaether.live
1•takmak007•1h ago•0 comments

CoreWeave's $30B Bet on GPU Market Infrastructure

https://davefriedman.substack.com/p/coreweaves-30-billion-bet-on-gpu
1•gmays•1h ago•0 comments

Creating and Hosting a Static Website on Cloudflare for Free

https://benjaminsmallwood.com/blog/creating-and-hosting-a-static-website-on-cloudflare-for-free/
1•bensmallwood•1h ago•1 comments

"The Stanford scam proves America is becoming a nation of grifters"

https://www.thetimes.com/us/news-today/article/students-stanford-grifters-ivy-league-w2g5z768z
4•cwwc•1h ago•0 comments

Elon Musk on Space GPUs, AI, Optimus, and His Manufacturing Method

https://cheekypint.substack.com/p/elon-musk-on-space-gpus-ai-optimus
2•simonebrunozzi•1h ago•0 comments

X (Twitter) is back with a new X API Pay-Per-Use model

https://developer.x.com/
3•eeko_systems•1h ago•0 comments

Zlob.h 100% POSIX and glibc compatible globbing lib that is faste and better

https://github.com/dmtrKovalenko/zlob
3•neogoose•1h ago•1 comments

Show HN: Deterministic signal triangulation using a fixed .72% variance constant

https://github.com/mabrucker85-prog/Project_Lance_Core
2•mav5431•1h ago•1 comments

Scientists Discover Levitating Time Crystals You Can Hold, Defy Newton’s 3rd Law

https://phys.org/news/2026-02-scientists-levitating-crystals.html
3•sizzle•1h ago•0 comments

When Michelangelo Met Titian

https://www.wsj.com/arts-culture/books/michelangelo-titian-review-the-renaissances-odd-couple-e34...
1•keiferski•1h ago•0 comments

Solving NYT Pips with DLX

https://github.com/DonoG/NYTPips4Processing
1•impossiblecode•1h ago•1 comments

Baldur's Gate to be turned into TV series – without the game's developers

https://www.bbc.com/news/articles/c24g457y534o
3•vunderba•1h ago•0 comments

Interview with 'Just use a VPS' bro (OpenClaw version) [video]

https://www.youtube.com/watch?v=40SnEd1RWUU
2•dangtony98•1h ago•0 comments

EchoJEPA: Latent Predictive Foundation Model for Echocardiography

https://github.com/bowang-lab/EchoJEPA
1•euvin•2h ago•0 comments