Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

gitleaks and trufflehog are great for scanning git history for leaked secrets but that's one of 52 rules. prodlint catches the structural patterns AI coding tools specifically create: hallucinated npm packages that don't exist, server actions with no auth or validation, NEXT_PUBLIC_ on server-only env vars, missing rate limiting, empty catch blocks, and more. It's closer to a vibe-coding-aware ESLint than a secrets scanner.
 help



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: