frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: My API was leaking its full database schema. I found out by accident

https://github.com/brakit-ai/brakit
3•speak2aditya•1h ago

Comments

speak2aditya•1h ago
Last month I was debugging an unrelated issue and noticed one of my endpoints was returning the full table schema and a list of user emails as objects. It should have been returning just an ID.

That endpoint had been live for months. It returned 200. The UI worked. I never looked at the actual response body.

Static analysis can't catch what's actually being sent over the wire at runtime. That's when I started building Brakit. I wanted a tool that does three things:

1. See everything. Every HTTP request and response, every database query, every external fetch, grouped by what the user actually did. "Checkout" → 3 requests → 6 queries → 1 Stripe call.

2. Automatic checks. 8 security rules and 13 performance rules scanning every response in real time. If an endpoint is leaking PII, exposing stack traces, or running the same query 14 times in a loop, brakit flags it.

3. Cross-session regression tracking. If an endpoint gets slower or fires more queries after a refactor, you see it before your users do.

It also has a built-in MCP server. Type "fix brakit findings" in Cursor or Claude Code and the AI gets full runtime context: every request, query, and issue.

Most observability tools catch these problems in production. Brakit catches them on your machine, during development, before you ship.

    npx brakit install
One command. Then run your app normally. Dashboard at localhost:3000/__brakit.

Tested on Next.js + Prisma + PostgreSQL and MySQL. Brakit is designed to be framework agnostic. Adding support for a new framework is a single adapter file.

Open source (MIT). Everything runs locally.

Demo: https://www.youtube.com/watch?v=IqTmlyIo3Mo GitHub: https://github.com/brakit-ai/brakit Site: https://brakit.ai

Would you add something like this to your dev workflow? What security rules or framework support would matter most to you?

The Hater's Guide to Oracle

https://www.wheresyoured.at/haters-guide-oracle/
1•NoGravitas•21s ago•0 comments

MongoDB Stock Falls 27% Even as Earnings Beat Estimates

https://www.barrons.com/articles/mongodb-earnings-stock-price-fc2ad40b
1•alecco•29s ago•0 comments

Show HN: FakeScan – Free AI fake review detector (Fakespot alternative)

https://fakescan.site
1•crawde•1m ago•0 comments

Show HN: PingMeBud – A macOS app that listens to meetings so you don't have to

https://www.pingmebud.com/
1•spaceman3•1m ago•0 comments

Show HN: ScrapAI – We scrape 500 sites. AI runs once per site, not per page

https://github.com/discourselab/scrapai-cli
1•iranu•2m ago•1 comments

The SaaS-pocalypse is (somewhat) overblown

https://12gramsofcarbon.com/p/tech-things-saas-is-dead-long-live
1•theahura•2m ago•0 comments

Show HN: I built an AI data analyst that never sees your data

https://www.queryveil.com/blog/i-built-an-ai-data-analyst-that-never-sees-your-data
1•david-rodriguez•3m ago•1 comments

Show HN: GovMatch – Daily government contract alerts matched to your business

https://www.govmatch.live/
1•realdanigil•3m ago•0 comments

France will allow temporary deployment of nuclear-armed jets to European allies

https://apnews.com/article/france-nuclear-weapons-macron-deterrence-ccbcfb03ef4a1e3efe287fb744adb148
2•geox•3m ago•0 comments

Better News

https://doc.searls.com/2026/03/03/better-news/
1•speckx•5m ago•0 comments

Bunny.net Shared Storage Zones

https://dbushell.com/2026/03/04/bunny-shared-storage-zones/
1•speckx•5m ago•0 comments

Pre-Order: Asimov DIY Kit – Build a Humanoid Robot

https://asimov.inc/diy-kit
1•bilsbie•5m ago•0 comments

EU MEPs let Chat Control fail

https://www.heise.de/en/news/Setback-for-the-Commission-EU-MEPs-let-chat-control-fail-11197237.html
1•carschno•7m ago•0 comments

Show HN: We built a zero-webhook Merchant of Record for SaaS

https://www.kelviq.com/
1•sachinneravath•8m ago•0 comments

Claude Code Permission Policy

https://github.com/defrex/claude-code-permission-policy
1•defrex•9m ago•0 comments

AutomaDocs – AI-powered documentation that stays in sync with your code

https://automadocs.com
2•purplegumdropz1•9m ago•0 comments

My first science video in 3 years (Pysics Girl)

https://www.youtube.com/watch?v=B3m3AMRlYfc
2•pcdavid•9m ago•0 comments

Gregory Gerganov and llama.cpp team joining HF

https://huggingface.co/blog/ggml-joins-hf
1•spwa4•10m ago•0 comments

Show HN: Run any Google Chrome version(+116) in Docker for web automation

https://github.com/blitzbrowser/blitzbrowser
1•sam_march•11m ago•0 comments

Space Jellyfish Predictor

https://jellyfish.johnkrausphotos.com/homepage
1•LorenDB•11m ago•0 comments

Florida public universities to pause hiring new H-1B workers

https://www.wusf.org/education/2026-03-03/hiring-h1b-workers-florida-public-universities-pause-en...
1•rawgabbit•12m ago•0 comments

Zero Public Ports: How I Secured a B2B API Against 10K Scraper Requests

https://blog.tripvento.com/zero-public-ports-how-i-secured-my-b2b-api
1•iistrate3•13m ago•0 comments

Show HN: Open-source digital signage ecosystem to escape vendor lock-in

1•sagiadinos•13m ago•0 comments

Show HN: Vocova – Paste a link, get a transcript in 100 languages

https://vocova.app/
1•jmcraft•16m ago•1 comments

Show HN: BloonsBench – Evaluate agent performance on Bloons Tower Defense 5

https://github.com/cnqso/bloonsbench
1•cnqso•17m ago•1 comments

Lawyers don't need "Legal AI"

https://theredline.versionstory.com/p/why-cant-43b-in-legal-ai-investment
2•jpbryan•17m ago•0 comments

Knowdust – Multi-tool hub for devs and everyday users

https://knowdust.com
1•thenamo•17m ago•1 comments

The gap between vague and specific AI direction is not small

https://thoughts.jock.pl/p/directed-ai-experiments-vibe-business
1•joozio•18m ago•0 comments

We're about to turn night into day. Is that a good idea?

https://www.washingtonpost.com/climate-environment/2026/02/27/satellites-light-pollution-spacex/
1•JeanKage•19m ago•2 comments

LinkedIn Ragebait

https://balanarayan.com/2026/03/03/linkedin-ragebait/
1•speckx•20m ago•0 comments