Sighthound
open-source vulnerability scanner for source code
Details
- External ID
- 48847577
- Source
- HN
- Company
- —
- Product
- Sighthound
- Website domain
- github.com
- Launched
- July 9, 2026
- Cohort
- —
- Upvotes
- 19
- Upvotes percentile
- 0.7037037037037037
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
We're open-sourcing Sighthound today, our rules-based static security scanner. What makes it special is that it's coded in rust and uses tree-sitter as it's AST making it very fast and easily extensible.Why build another scanner in 2026? We wanted to improve some of our detection outcomes but noticed the current open source scanners like Semgrep/Opengrep we're capped by a bunch of adoption limitations such as being written in OCaml, requiring a lot of work to add a language parser, and the rulesets were licensed differently and required paid offerings. It also felt that licensing was moving backwards rather than forward.We wanted something that was very fast, was easily extensible and had a great set of rules that we could use. This led us to using Rust and Tree-sitter since they are both fast and have great community adoption making extending Sighthound natural.We wanted it to focus on source-code vulnerability classes like Sql Injection, and Xss. We haven't yet done any secrets scanning as there are a lot of great options in the market at the moment. Right now, Sighthound supports Python, JS/TS, Java, Go, C#, HTML, PHP and Ruby.We still have a lot of work to do so, we'd love for your feedback, and contributions in however they come from adding new languages, new rules or bug fixes.
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Security
- Function
- Dev tools
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- vulnerability scanner for source code
- Manually corrected
- False
Could you build this?
No Developing a robust static vulnerability scanner requires deep compiler theory, abstract syntax tree (AST) traversal, and extensive cybersecurity domain expertise in writing accurate exploit detection rules.
What it would actually take: The stack centers on Rust paired with Tree-sitter grammars across multiple programming languages, compiling custom query engines (similar to Semgrep). The hard parts are data-flow analysis, taint tracking, control-flow graph generation across language idioms, and curating an authoritative library of low-false-positive security rules. This requires specialized AppSec researchers and compiler engineers.
Discussion
No comments on this launch.
Competitors
Other products that read as similar to this one — 128 launches clear the similarity bar, closest 8 shown.
Attention rank: #49 of 129 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 250 days after the earliest competitor.
- Artifact Keeper · hn · 2026-02-06 · 166 upvotes · similarity 0.50
- Bloodhound · hn · 2025-12-09 · 5 upvotes · similarity 0.46
- HoundDog.ai · hn · 2026-02-02 · 16 upvotes · similarity 0.44
- Aura · hn · 2026-09-02 · 27 upvotes · similarity 0.40
- REPOSIGHT · ph · 2026-09-09 · 2 upvotes · similarity 0.39
- OpenHack · hn · 2026-06-04 · 12 upvotes · similarity 0.39
- Open-source tool to generate OpenAPI docs from your code · hn · 2025-11-20 · 11 upvotes · similarity 0.39
- Glintlog · hn · 2026-02-04 · 10 upvotes · similarity 0.39
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.