p/bearer-cli
Free & Open Source security scanner for developers 🛡
Nicolas Grenié
Bearer CLI — Free & open source security scanner for developers
Featured
52
Bearer CLI is a free, open-source command-line tool to help developers secure their code. It analyzes source code against common security risks and vulnerabilities and provides a direct output in a terminal with the right context to fix them quickly.
Replies
Best
Nicolas Grenié
Security should never be an afterthought. Bearer makes developers' life easier by installing a security scanner in just a few minutes. You already get results and recommendations on the first run. And it's open source 🤯
Cédric Fabianski
Thank you @picsoung for hunting us!
Guillaume Montard
Hello tech hunters 🤓 I am excited to share with you two years of work, now available to everyone through today's PH launch! As software developers, we know that security is essential, but can also be difficult because it is time-consuming, costly, and often feels inaccessible. At Bearer.com, we believe that developers deserve better security tools, and it starts with a great developer experience. We show you what matters by reducing noise, maximizing context, and providing remediation hints. Security doesn't have to be scary. Today, we are thrilled to Open Source our code security solution with an easy-to-use CLI. You can install it in minutes and test your code for known security issues, starting with the most critical issues that can lead to data breaches or leaks. I hope this encourages all of us to provide better software and ultimately better protect our data. 🐻🛡️ Guillaume.
Maximilien Tyc
Thank you that looks super great, lots of rules already! How easy is it to write new rules? What’s the main use case you’ve seen so far? CI integration I guess?
Cédric Fabianski
@maximilientyc Thank you! Writing rules is as easy as 1-2-3 but we also have a doc for it https://docs.bearer.com/guides/c... You can always hop into the Discord to get help should you need it! Regarding the main use case, yeah CI integration is a good one, getting an inventory is another one
Maximilien Tyc
@cfabianski also I'm curious, your documentation website is very nice, are you relying on docusaurus behind the scene to build it? or something else maybe?
Cédric Fabianski
@maximilientyc thank you! @markmichon will be happy :) It's all Eleventy and GitHub Pages.
Mark Michon
@cfabianski @maximilientyc Thanks, Maximilien! As @cfabianski mentioned, it's built with @eleven_ty and tailwind. Gives us lots of flexibility without the bloat and knowledge requirement of docusaurus(react). 11ty's data setup is pretty powerful once you get the hang of it. We build our rules search, all individual rule pages, and anything that isn't a tutorial directly from the source with it.
Ivo Scherkamp
I am not a developer, but I know about the importance of security scanning (firsthand experiences, unfortunately 😬). I am a fan if this makes software a tiny bit less vulnerable!
Cédric Fabianski
@ivo_scherkamp Should never have been an afterthought! Thanks
Nipun Gupta
Thank you for hunting us @picsoung! I wanted to share some perspective on this launch from a security product builder. Not often it is that you hear than a security product is available open-source. We are in a market where something as simple as trying out a product is buried within sales cycles, security questionnaires, and bake-offs. As a former application security engineer, I know the pain of using poorly designed static code analyzers or as market knows them - SAST. In my experience at an enterprise, the scan took a few days, output was literally un-usable and required weeks of triage - forget about ever getting anything fixed because convincing developers about such risk without frequent engagement was close to impossible. Super proud of our team here, who has done an amazing job in creating Bearer CLI that is easily adopted by engineering teams, and makes security team's job easy by focusing on what matters most - sensitive data at risk. As Apple's founder Steve Jobs used to say - 'less is more'. If you are in building a software product business or lead a security-forward engineering team, you know how important it is to get adoption and engagement between your security and engineering teams for long-term risk reduction, and Bearer makes it easy - please give it a try, and let us know your feedback!
Deepak Prabhakara
This is a fantastic way to shift left privacy. We use the CLI with our projects and love the actionable recommendations we get. It is extremely easy to set up and use. Congratulations on the launch team Bearer!
flo merian
added to my collection of awesome developer-first products. congrats on the launch, ?makers, cocorico!
Nipun Gupta
@fmerian Thanks Flo, feel free to join our discord for questions - https://discord.com/invite/eaHZB...
Jack Bridger
Congratulations, looks awesome, I'm always worried about vulnerabilities. Bearer should give me ease of mind!
Cédric Fabianski
@jack_bridger That is our goal. Thank you!
Nipun Gupta
@jack_bridger totally! Feel free to ask any questions on our discord as you try it - https://discord.com/invite/eaHZB...
Arnaud Breton
Excited to see folks tackling the data security problem in a developer-first fashion! Still a lot to figure out but this iteration is very promising and the team behind seems to be the best one to crack this problem
Cédric Fabianski
@arnaud_breton Thank you Arnaud for the kind words! Not an easy problem to tackle but as we say, security should be easy for developers so that it becomes easier to build secure applications than insecure applications
I love your logo and it caught my attention. I voted for your product on Product Hunt, and I wish you the best of luck!
Cédric Fabianski
@kate_bovkunova 🐻 Also kudos to @ombeline_brard for the logo :)
Knight 
No PHP support?
Cédric Fabianski
@imknight not yet but it will come sooner rather than later ;)
Edoardo Lanzini
Congrats on the launch! I was wondering how you place Bearer compared to GitHub Dependabot, which can also detect call sites in case you are calling a vulnerable function. https://github.blog/2022-04-14-d....
Yaro Shm
I've tried running bearer on a few of my rails apps -> the scan results looks quite useful for finding security gaps in the code that I otherwise would not have even thought about. I think it's a tool worth adding to the CI pipeline.
Guillaume Luccisano
Nice! I tried our Bearer on my codebase and it surprisingly worked without any setup required and highlighted some issues. I totally recommend it!
Nipun Gupta
@luckwi That's amazing to hear, thanks for your feedback Guillaume!
Ari Bajo
Nice! Seems like it's easy to get it up and running for an existing codebase!
Cédric Fabianski
@ari_bajo_rouvinen Well it should but there is only one way to find out ;)
Nipun Gupta
@ari_bajo_rouvinen Thanks Ari, feel free to join our discord if you have any questions - https://discord.com/invite/eaHZB...
Chuck Hardy
Fantastic! Excited to use this in my daily development.
Nipun Gupta
@chuckjhardy1 Awesome, looking forward to your feedback Chuck! Feel free to join our Discord - https://discord.com/invite/eaHZB...
Jim Engine
That will save me a lot of work @picsoung . 😻
Cédric Fabianski
@officialexaking That is the goal indeed! :)
Paul Bleicher
Congrats on the launch!
Cédric Fabianski
@bl_paul Thank you Paul!
Timmy Wahba
congrats!
Nipun Gupta
@timmy_wahba thank you Timmy!
Lazar Radenovic
very cool - we have been using kiuwan and switched to SonarQube. would love to try this.
Nipun Gupta
@lazar_radenovic would love to get your feedback, feel free to join our discord https://discord.com/invite/eaHZB...