frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Kekkai – Interactive security triage in the terminal

4•kirumachi•5d ago
Hey HN,

As an AppSec engineer, I’ve spent a lot of time running and tunning open-source security scanners like Trivy, Semgrep, Gitleaks and Dojo. What I have found is that running them is easy, reviewing the results, not so much. Each tool outputs different JSON, false positives pile up, and CI either becomes noisy or blocks everything.

So I built Kekkai (formerly Hokage), a small open-source CLI that wraps these scanners and focuses specifically on human triage.

Kekkai runs the scanners in isolated Docker containers, normalizes their outputs into a single format, and provides an interactive terminal UI to review findings, mark false positives, and save decisions locally.

You can try it out:

``` pipx install kekkai-cli kekkai scan kekkai triage ```

What it currently does:

- Runs Trivy (dependencies), Semgrep (code), and Gitleaks (secrets) - Normalizes findings into a unified report - Provides a keyboard-driven TUI for reviewing and marking findings - Supports .kekkaiignore for false positives - Has a CI mode with severity-based failure thresholds

Design choices:

- Local-first by default (no SaaS required) - No proprietary scanning logic, it sits on top of existing tools - Scanners run in read-only, no-network Docker containers

This is still early and aimed at individual developers and small teams. The next things I’m working on are persistent triage state across runs (baselines) and better PR-level workflows.

Repo and docs: https://github.com/kademoslabs/kekkai

I’m around to answer questions about tradeoffs, limitations, or why this exists at all.

Comments

kirumachi•5d ago
It’s open source (Apache 2.0) and Written in Python/Textual.
jostkolega•5d ago
+1 on triage being the real problem. Question, when Semgrep surfaces something ambiguous, lets say a SQL query that looks parameterized but the ORDER BY is built elsewhere, what does reviewing that actually look like? I'm wondering how much context you get before needing to jump out to the codebase.
kirumachi•5d ago
Great question. Right now (v2.0.1), The TUI is optimized for metadata triage. You see the Rule ID, Severity, the full Semgrep message (which often contains the taint trace), and the File/Line location. The Workflow:

1. I see [High] SQL Injection in db.py:45. 2. If the description is obvious (like a string concatenation), I mark it Confirmed (c) or False Positive (f) right there. 3. For ambiguous cases (like your ORDER BY example where the context is split), I currently keep the TUI open on one side and my IDE on the other. I use the TUI to quickly filter the noise and jump to code only for the complex ones.

We are actually adding a Syntax widget to render the surrounding 10 lines of code and the taint trace directly in the TUI so you don't have to alt-tab, this is coming in v2.1. But for now, we prioritize keeping the interface snappy.

Vouch

https://github.com/mitchellh/vouch
146•dboon•1h ago•28 comments

I put a real-time 3D shader on the Game Boy Color

https://blog.otterstack.com/posts/202512-gbshader/
82•adunk•2h ago•5 comments

Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

https://nullcathedral.com/posts/2026-02-08-roundcube-svg-feimage-remote-image-bypass/
10•nullcathedral•17m ago•0 comments

Running Your Own As: BGP on FreeBSD with FRR, GRE Tunnels, and Policy Routing

https://blog.hofstede.it/running-your-own-as-bgp-on-freebsd-with-frr-gre-tunnels-and-policy-routing/
78•todsacerdoti•4h ago•23 comments

The Little Bool of Doom

https://blog.svgames.pl/article/the-little-bool-of-doom
8•pocksuppet•38m ago•0 comments

RFC 3092 – Etymology of "Foo" (2001)

https://datatracker.ietf.org/doc/html/rfc3092
78•ipnon•4h ago•14 comments

Billing can be bypassed using a combo of subagents with an agent definition

https://github.com/microsoft/vscode/issues/292452
107•napolux•1h ago•50 comments

Omega-3 is inversely related to risk of early-onset dementia

https://pubmed.ncbi.nlm.nih.gov/41506004/
92•brandonb•1h ago•42 comments

Bun v1.3.9

https://bun.com/blog/bun-v1.3.9
34•tosh•1h ago•11 comments

Exploiting signed bootloaders to circumvent UEFI Secure Boot

https://habr.com/en/articles/446238/
36•todsacerdoti•4h ago•6 comments

The First Sodium-Ion Battery EV Is a Winter Range Monster

https://insideevs.com/news/786509/catl-changan-worlds-first-sodium-ion-battery-ev/
45•andrewjneumann•1h ago•12 comments

GitHub Agentic Workflows

https://github.github.io/gh-aw/
100•mooreds•5h ago•58 comments

Show HN: I created a Mars colony RPG based on Kim Stanley Robinson's Mars books

https://underhillgame.com/
13•ariaalam•1h ago•2 comments

Formally Verifying PBS Kids with Lean4

https://www.shadaj.me/writing/cyberchase-lean
17•shadaj•6d ago•0 comments

Curating a Show on My Ineffable Mother, Ursula K. Le Guin

https://hyperallergic.com/curating-a-show-on-my-ineffable-mother-ursula-k-le-guin/
105•bryanrasmussen•8h ago•34 comments

Let's compile Quake like it's 1997

https://fabiensanglard.net/compile_like_1997/index.html
35•birdculture•1h ago•11 comments

Why E cores make Apple silicon fast

https://eclecticlight.co/2026/02/08/last-week-on-my-mac-why-e-cores-make-apple-silicon-fast/
164•ingve•7h ago•175 comments

Kolakoski Sequence

https://en.wikipedia.org/wiki/Kolakoski_sequence
36•surprisetalk•6d ago•10 comments

Show HN: It took 4 years to sell my startup. I wrote a book about it

https://derekyan.com/ma-book/
126•zhyan7109•4d ago•22 comments

OpenClaw is changing my life

https://reorx.com/blog/openclaw-is-changing-my-life/
114•novoreorx•12h ago•204 comments

Reverse Engineering Raiders of the Lost Ark for the Atari 2600

https://github.com/joshuanwalker/Raiders2600
64•pacod•9h ago•2 comments

Matchlock – Secures AI agent workloads with a Linux-based sandbox

https://github.com/jingkaihe/matchlock
114•jingkai_he•10h ago•46 comments

Dave Farber has died

https://lists.nanog.org/archives/list/nanog@lists.nanog.org/thread/TSNPJVFH4DKLINIKSMRIIVNHDG5XKJCM/
142•vitplister•7h ago•20 comments

Slop Terrifies Me

https://ezhik.jp/ai-slop-terrifies-me/
237•Ezhik•8h ago•224 comments

Show HN: LocalGPT – A local-first AI assistant in Rust with persistent memory

https://github.com/localgpt-app/localgpt
295•yi_wang•17h ago•141 comments

Beyond agentic coding

https://haskellforall.com/2026/02/beyond-agentic-coding
216•RebelPotato•16h ago•81 comments

DoNotNotify is now Open Source

https://donotnotify.com/opensource.html
334•awaaz•11h ago•47 comments

Rabbit Ear "Origami": programmable origami in the browser

https://rabbitear.org/book/origami.html
99•molszanski•4d ago•4 comments

Stop Using Face ID

https://www.pcmag.com/explainers/why-you-should-stop-using-face-id-right-now?test_uuid=04IpBmWGZl...
20•speckx•1h ago•2 comments

We mourn our craft

https://nolanlawson.com/2026/02/07/we-mourn-our-craft/
591•ColinWright•1d ago•703 comments