Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
micksmix
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
micksmix
5mo ago
This is also a good reminder to scan CI logs, not just source code. Shameless plug: I work on Kingfisher, an Apache 2.0 OSS secret scanner and validator written in Rust, that can also map blast radius and revoke many creds: < https:/
2.
▲
Show HN: Kingfisher, a fast OSS secret scanner with validation and blast radius
(github.com)
3 points
by
micksmix
9mo ago
|
0 comments
3.
▲
by
micksmix
1y ago
I'm curious how Kingfisher would do against the proprietary dataset: https://github.com/mongodb/kingfisher Any chance you could try and share results? Full disclosure, I built Kingfisher
4.
▲
by
micksmix
1y ago
Loved this “lead bullets” framing, especially the parts on taint checking, scanners, and pre-processing/sampling logs. One practical add-on to the "Sensitive data scanners" section is verification: can you tell which candidat
5.
▲
by
micksmix
2y ago
That makes a lot of sense. I wish you the best of luck and will be happy to try it out as you continue to develop it!
6.
▲
by
micksmix
2y ago
One of the main benefits of Semgrep is its unified DSL that works across all supported languages. In contrast, using the Go module "smacker/go-tree-sitter" can expose you to differences in s-expression outputs due to variatio
7.
▲
by
micksmix
2y ago
This is a really interesting project! I'd love to hear how this project differs from Bearer, which is also written in Go and based on tree-sitter? https://github.com/Bearer/bearer Regardless, considering there is