frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Security scanner that detect's AI-generated code vulnerabilities

https://codeslick.dev/
1•vitorlourenco•1h ago

Comments

vitorlourenco•1h ago
Hey HN! Solo developer here. I spent 4 months building CodeSlick - a security scanner for GitHub PRs.

What's different about v1.3 (launched today):

1. One command runs security AND tests `cs scan --verify` blocks commits only if BOTH pass Catches "security passed, prod broke" situations

2. Configurable pass/fail gates Not all-or-nothing: "block CRITICAL only" or "max 10 vulnerabilities" Teams control what blocks their PRs (not the tool)

3. Auto-creates GitHub issues for vulnerabilities Security work becomes visible (trackable like features) No more "found vulnerabilities, forgot to fix"

Technical details: - 294 security checks (SQL injection, XSS, SSRF, AI hallucinations) - 5 languages: JavaScript, TypeScript, Python, Java, Go - AST-based static analysis (Acorn for JS/TS, custom parsers for others) - Auto-detects test frameworks (npm, pytest, go test, maven, gradle) - <3s per file analysis time - OWASP 2025 compliant (95% coverage)

What I'm proud of: - First scanner to detect AI-generated code vulnerabilities - Thresholds that actually fit how teams work (not all-or-nothing) - CLI + GitHub App + WebTool (3 surfaces, same engine)

What still needs work: - No C/C++/Rust support yet - GitHub only (no GitLab/Bitbucket) - Solo founder (just me, scaling support is hard)

Try it: - CLI: npx codeslick-cli@latest init - GitHub App: https://github.com/settings/apps/codeslick-security-scanner - Blog post: https://codeslick.dev/blog/security-quality-developer-workfl...

Happy to answer questions about the technical implementation, design decisions, or trade-offs I made.

Built with: Next.js 15, TypeScript, Acorn, Neon Postgres, Vercel

Ubuntu is the reason Windows users don't want to switch to Linux

https://www.xda-developers.com/ubuntu-reason-linux-users-dont-want-switch-linux/
1•tartoran•4m ago•0 comments

A Wonkish Note on Tariffs and Inflation

https://paulkrugman.substack.com/p/a-wonkish-note-on-tariffs-and-inflation
2•rbanffy•6m ago•0 comments

Notes for January 26 – February 1

https://taoofmac.com/space/notes/2026/02/01/2200
1•rcarmo•7m ago•0 comments

Show HN: GuardWave v1 – Local-First Security CLI for real-time monitoring

https://github.com/bee933769/GuardWave
1•bee933769•8m ago•0 comments

Beating context rot in Claude Code with GSD

https://thenewstack.io/beating-the-rot-and-getting-stuff-done/
1•jimminyx•10m ago•0 comments

Vibing with the Agent Control Protocol

https://taoofmac.com/space/notes/2026/02/01/2100
1•rcarmo•11m ago•0 comments

Thoughts on AI-Assisted Software Development in 2026

https://taoofmac.com/space/notes/2026/02/01/2130
2•rcarmo•11m ago•0 comments

Why decisions decay in engineering orgs

https://notsolvingthis.substack.com/p/part-2-decision-half-life
1•sun123•12m ago•0 comments

Tell HN: iPhones screen time widget is broken

2•garyfirestorm•13m ago•0 comments

To Save Everything Click Here: The Folly of Technological Solutionism (2016) [video]

https://www.youtube.com/watch?v=9yQqrZUD6Gk
1•measurablefunc•13m ago•0 comments

Cursorless: Voice Coding at the Speed of Thought

https://www.cursorless.org/
1•PaulHoule•13m ago•0 comments

Autonomy and Clarity in Leadership Styles – Bjorg

https://bjorg.bjornroche.com/management/autonomy-vs-clarity/
2•kiyanwang•14m ago•0 comments

Treasures found on HS2 route stored in secret warehouse

https://www.bbc.com/news/articles/c93v21q5xdvo
1•breve•16m ago•0 comments

Two CBP Agents Identified in Alex Pretti Shooting

https://www.propublica.org/article/alex-pretti-shooting-cbp-agents-identified-jesus-ochoa-raymund...
6•lawrencejgd•21m ago•1 comments

Peep this sgnl_interceptor hacking concept

https://ab73acf1acd5a5.lhr.life/
3•gh0stwalk•25m ago•0 comments

LLMs achieve adult human performance on higher-order "theory of mind" tasks

https://pmc.ncbi.nlm.nih.gov/articles/PMC12808479/
3•stareatgoats•25m ago•0 comments

Show HN: Pro Gamer Gear- the Ninjutsu Sora V3

https://xthe.com/news/pro-gamer-gear-the-ninjutsu-sora-v3/
2•xthe•28m ago•1 comments

The Futurama Episode That Set the Show's Writers Free from Fox's Terrible Notes

https://www.slashfilm.com/1408546/futurama-episode-set-writers-free-fox/
2•rolph•28m ago•0 comments

My (very) fast zero-allocation webserver using OxCaml

https://anil.recoil.org/notes/oxcaml-httpz
2•todsacerdoti•32m ago•0 comments

Escutcheon

https://en.wikipedia.org/wiki/Escutcheon_(furniture)
2•huhtenberg•32m ago•1 comments

Google Introduces Managed Connection Pooling for AlloyDB

https://www.infoq.com/news/2026/01/alloydb-managed-connection-pool/
1•GavCo•32m ago•0 comments

Show HN: Echo – Local-first kindle-like reader with annotations and LLM chat

https://github.com/tibi-iorga/echo-reading
2•tb8424•33m ago•0 comments

Audio on Hp300

http://miod.online.fr/software/openbsd/stories/arcofi.html
2•todsacerdoti•34m ago•0 comments

Embedded AI usage controls and spend limits for your enterprise customers

https://www.stigg.io/ai-usage-management
1•anton-stigg•36m ago•2 comments

Show HN: Smith – A visual control room for managing parallel coding agents

https://trysmith.dev/
2•tomhr•37m ago•0 comments

Lily Programming Language

https://lily-lang.org
1•FascinatedBox•37m ago•0 comments

Embedded AI usage controls and spend limits for your enterprise customers

https://stigg-x.webflow.io/ai-usage-management
1•anton-stigg•37m ago•1 comments

Magnetic core memory 128-byte USB drive

https://www.tomshardware.com/pc-components/usb-flash-drives/researcher-builds-bizarre-128-byte-us...
2•stevenjgarner•39m ago•0 comments

Show HN: OpenRAPP – AI agents autonomously evolve a world via GitHub PRs

https://kody-w.github.io/openrapp/rappbook/
2•bothangles•39m ago•0 comments

Making a Zig Agent Skill

https://austinrude.com/blog/making-a-zig-agent-skill/
2•rudedogg•39m ago•0 comments