
完整作品展
技术栈
60 projects


比较两个npm包版本以识别新增或更改的文件。
fathermarz · HN
I’ve worked in software supply-chain security for six years doing binary analysis on firmware, industrial controls systems, and commodity IT closed/open source software. What I learned is that in hopes to secure the software supply chain we have ran a very similar playbook and mostly over engineered the problem, with SBOMs and VEX documents and expected the industry to comply. But what was discovered was that every SBOM looks different depending on who produced it and at what step in the chain,

USend 是无需登录的安全文件转移工具,用一次性配对码在设备间传输文件或文本,支持端到端加密和自动删除。
@FrankFika · X
Still using a chat app to send files to yourself? I built USend: no sign-in, no app, no permanent share link. An 8-digit code moves a file or text between devices. Browser-side encryption. Auto-delete after receipt or expiry. Try it: #VibeCoding #OpenSource

检测AI生成代码中的安全漏洞,传统扫描器无法发现。
u/RyzeBlaziken · Reddit
Built a codebase security vulnerability scanner Hey guys, wanted to tell you guys about a tool I built called Scanity. Scanity scans codebases to find security vulnerabilities in code. Nowadays, with AI coding so fast, there are so many internal bugs and vulnerabilities that get missed. Here are the main features we have: Seamless integration with GitHub Actions, checking each PR before it merges, and automatically providing suggested fixes. Drop into any repository, run a full scan,

使用AI增强的安全分析扫描代码和应用漏洞。
u/swifi_ai · Reddit
After 10 years of keeping this idea alive, I finally launched my AI security platform to beta After more than 10 years of keeping this idea alive in one form or another, I finally pushed Swifi live to beta: https://swifi.ai Swifi is an AI-augmented application security platform. The goal: combine traditional security scanning with AI so teams can understand risk across code, vulnerabilities, and production context without stitching together a dozen disconnected tools. Why now? AI change

Plaintext 检查 AI 生成应用中的安全漏洞(代码、端点和数据库)。
@plaintextsecure · X
Security Scanner for Vibe Coded apps to prevent data and money leaks

独立验证 AI 生成代码,发现可利用漏洞并提供修补。
@usesecurecode · X
Free Starter is $0 forever. 3 scan credits 1 free Attacker Mode run (20 credits) Real-time SAST Dependency checking Fix previews Signing up is free and gives you scans to try it out. free&utm_content=06_start-free#pricing #vibecoding

AI 代码安全扫描器,检查 GitHub 仓库找出可利用的漏洞并提供修复建议。
u/Delicious-Action-351 · Reddit
I failed 4 times and still made an app to make your code more secure. I made an webapp to make your vibecoded app secure. Today, SaaS entrepreneurs ship fast and don’t check for security, at the end they get hacked and it’ll cost them a lot of money. I decided to solve this issue. Netherite is an AI Security Specialist, you connect Github and choose repo to run security scan. It scans your whole repo in minutes and hands you the professional report and fix prompt for your ai agent. You ca

Sentrint 扫描 AI 应用以查找数据库暴露、密钥泄露和认证缺陷等安全问题。
@Sentrint · X
Made Sentrint after seeing how many vibe-coded apps ship with RLS switched off. Point it at a GitHub repo and it finds open user tables, exposed keys and auth checks that only run in the browser. Free scan is the whole scan, no card.

分析开源 GitHub 项目的健康指标、漏洞和质量数据。
Koimiao · V2EX
做了个小工具,可以从各个维度评估一个 GitHub 项目,想请大家拍砖 找开源项目时,我们常常会先看 Star 、README 和最近一次提交。如果你是独立开发者,正在维护自己的开源项目,也想知道怎么让自己项目更健康、被更多人看见,第一步该从哪里做起? 所以最近我做了一个小项目:TrustOSS http://trustoss.org 输入一个 GitHub 仓库链接,TrustOSS 会把这些公开信号整理成一份可读的仓库健康报告:活跃度、维护情况、社区、文档与成熟度评分;也可以进一步查看漏洞、CI 、真实依赖者、维护者集中度和 Star 异常情况。 想要评估一个开源项目,或者维护自己的开源项目,想知道短板在哪里,都可以直接试试(是免费的!

通过 GridSync API 实时同步跨设备数据,具有自动威胁检测和清理功能。
@mygridsyncdev · X
Just launched GridSync ⚡️ Sub-150ms zero-trust payload inspection & real-time sync for modern APIs. Try the free tier on RapidAPI or check out the docs: #buildinpublic #API #FastAPI

在 Supabase 应用中检测安全漏洞,获得证据和修复建议。
@urti_luca · X
Sentris finds the exposures in your Supabase app before someone else does.