frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Kekkai – Interactive security triage in the terminal

2•kirumachi•1h ago
Hey HN,

As an AppSec engineer, I’ve spent a lot of time running and tunning open-source security scanners like Trivy, Semgrep, Gitleaks and Dojo. What I have found is that running them is easy, reviewing the results, not so much. Each tool outputs different JSON, false positives pile up, and CI either becomes noisy or blocks everything.

So I built Kekkai (formerly Hokage), a small open-source CLI that wraps these scanners and focuses specifically on human triage.

Kekkai runs the scanners in isolated Docker containers, normalizes their outputs into a single format, and provides an interactive terminal UI to review findings, mark false positives, and save decisions locally.

You can try it out:

``` pipx install kekkai-cli kekkai scan kekkai triage ```

What it currently does:

- Runs Trivy (dependencies), Semgrep (code), and Gitleaks (secrets) - Normalizes findings into a unified report - Provides a keyboard-driven TUI for reviewing and marking findings - Supports .kekkaiignore for false positives - Has a CI mode with severity-based failure thresholds

Design choices:

- Local-first by default (no SaaS required) - No proprietary scanning logic, it sits on top of existing tools - Scanners run in read-only, no-network Docker containers

This is still early and aimed at individual developers and small teams. The next things I’m working on are persistent triage state across runs (baselines) and better PR-level workflows.

Repo and docs: https://github.com/kademoslabs/kekkai

I’m around to answer questions about tradeoffs, limitations, or why this exists at all.

Comments

kirumachi•1h ago
It’s open source (Apache 2.0) and Written in Python/Textual.

Show HN: A Java library for writing Helm chart tests

https://github.com/robmoore-i/helm-test-java
1•robmoore121•3m ago•0 comments

Ultra-processed foods should be treated more like cigarettes than food – study

https://www.theguardian.com/global-development/2026/feb/03/public-health-ultra-processed-foods-re...
1•CrypticShift•3m ago•0 comments

The Ambient AI Era: Clawdbot (OpenClaw)'S Ripple Effects

https://nextword.substack.com/p/the-ambient-ai-and-clawdbot-openclaw-implications
1•walterbell•6m ago•0 comments

Introducing Agentic Vision in Gemini 3 Flash (2026)

https://blog.google/innovation-and-ai/technology/developers-tools/agentic-vision-gemini-3-flash/
1•vercaemert•7m ago•0 comments

Spain to ban social media access for under-16s, PM Sanchez says

https://www.reuters.com/world/spain-hold-social-media-executives-accountable-illegal-hateful-cont...
4•xavaki•7m ago•0 comments

Show HN: Craftplan – Elixir-based micro-ERP for small-scale manufacturers

https://puemos.github.io/craftplan/
1•deofoo•11m ago•0 comments

DIY AI bot farm OpenClaw is a security 'dumpster fire'

https://www.theregister.com/2026/02/03/openclaw_security_problems/
3•0in•12m ago•0 comments

Tgterm – Control Claude Code from Telegram on macOS (< 1000 lines of C code)

https://github.com/antirez/tgterm
1•antirez•14m ago•0 comments

Eigen: Building a Workspace

https://reindernijhoff.net/2025/10/eigen-building-a-workspace/
1•todsacerdoti•15m ago•0 comments

Imprison Younger Offenders Longer

https://nicholasdecker.substack.com/p/imprison-younger-offenders-longer
2•barry-cotter•16m ago•1 comments

Show HN: Rotativa.io – Liquid-based PDF templates with a live-preview editor

https://rotativa.io
1•webgio•18m ago•0 comments

Min Telefonbogsprofil

1•agnes-nordic•19m ago•0 comments

Helix: A post-modern text editor

https://helix-editor.com/
2•thunderbong•22m ago•0 comments

Why people say they're using 'Are You Dead?' (&others)

https://www.npr.org/2026/02/03/nx-s1-5694669/loneliness-isolation-app-are-you-dead-snug-alone
2•defrost•30m ago•0 comments

Crime rates of undocumented-, legal immigrants, & native-born citizens in Texas

https://www.pnas.org/doi/10.1073/pnas.2014704117
8•u1hcw9nx•31m ago•9 comments

Linux Emulation on Apple iPads: iSH, JIT, and the EU Digital Markets Act (2024)

https://ish.app/blog/ish-jit-and-eu
2•walterbell•37m ago•0 comments

NationStates security breach caused by own player

https://web.archive.org/web/20260130051909/https://nationstates.net/
2•aa_is_op•39m ago•0 comments

Show HN: I wrote a Semgrep alternative in Rust with cross-file taint tracking

https://github.com/bumahkib7/rust-monorepo-analyzer
1•bumahkib7•39m ago•0 comments

Curlme.io – Terminal-first HTTP request debugging

https://curlme.io/
1•OMoutaz•40m ago•1 comments

Show HN: Clienwork – Client portal for freelancers and agencies

https://clienwork.com
1•runai•43m ago•0 comments

Devs Need AI Training

1•eibrahim•43m ago•1 comments

Europe's tech sovereignty watch (74% of EU companies depend on US tech services)

https://proton.me/business/europe-tech-watch
5•giuliomagnifico•48m ago•0 comments

A11yJSON: A standard to describe the accessibility of the physical world

https://sozialhelden.github.io/a11yjson/
1•robin_reala•51m ago•0 comments

Show HN: Maths Worksheet Generator – Fun printable worksheets for kids

https://maths.antfie.com
1•antfie•51m ago•0 comments

How to Convert OST Files to PST

https://apps.microsoft.com/detail/9p62fq9z8x7p?hl=en-US&gl=US
1•tieanderson•52m ago•1 comments

The API Tooling Crisis: Why developers are abandoning Postman and its clones?

http://efp.asia/blog/2025/12/24/api-tooling-crisis/
1•birdculture•55m ago•0 comments

EU-based transactional email service

https://lettermint.co
1•Aldipower•55m ago•0 comments

How to Evaluate an Online Tarot Platform (and What Most Users Overlook)

https://medium.com/@enrique_15267/how-to-evaluate-an-online-tarot-platform-and-what-most-users-ov...
1•astroideal•58m ago•0 comments

Erys: Terminal Interface for Jupyter Notebooks

https://github.com/natibek/erys
1•gballan•1h ago•0 comments

Sealos – AI Native Cloud Cloud Operating System

https://github.com/labring/sealos
1•fanux•1h ago•0 comments