Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Sighthound

open-source vulnerability scanner for source code

Details

External ID
48847577
Source
HN
Company
—
Product
Sighthound
Website domain
github.com
Launched
July 9, 2026
Cohort
—
Upvotes
19
Upvotes percentile
0.7037037037037037
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

We're open-sourcing Sighthound today, our rules-based static security scanner. What makes it special is that it's coded in rust and uses tree-sitter as it's AST making it very fast and easily extensible.Why build another scanner in 2026? We wanted to improve some of our detection outcomes but noticed the current open source scanners like Semgrep/Opengrep we're capped by a bunch of adoption limitations such as being written in OCaml, requiring a lot of work to add a language parser, and the rulesets were licensed differently and required paid offerings. It also felt that licensing was moving backwards rather than forward.We wanted something that was very fast, was easily extensible and had a great set of rules that we could use. This led us to using Rust and Tree-sitter since they are both fast and have great community adoption making extending Sighthound natural.We wanted it to focus on source-code vulnerability classes like Sql Injection, and Xss. We haven't yet done any secrets scanning as there are a lot of great options in the market at the moment. Right now, Sighthound supports Python, JS/TS, Java, Go, C#, HTML, PHP and Ruby.We still have a lot of work to do so, we'd love for your feedback, and contributions in however they come from adding new languages, new rules or bug fixes.

Enrichment

Theme
self-hosted infrastructure and security tools
Vertical
Security
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
vulnerability scanner for source code
Manually corrected
False

Could you build this?

No Developing a robust static vulnerability scanner requires deep compiler theory, abstract syntax tree (AST) traversal, and extensive cybersecurity domain expertise in writing accurate exploit detection rules.

What it would actually take: The stack centers on Rust paired with Tree-sitter grammars across multiple programming languages, compiling custom query engines (similar to Semgrep). The hard parts are data-flow analysis, taint tracking, control-flow graph generation across language idioms, and curating an authoritative library of low-false-positive security rules. This requires specialized AppSec researchers and compiler engineers.

Discussion

No comments on this launch.

Competitors

Other products that read as similar to this one — 128 launches clear the similarity bar, closest 8 shown.

Attention rank: #49 of 129 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 250 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.