Hacker Newsnew | past | comments | ask | show | jobs | submit | prdonahue's commentslogin

What are some good SaaS alternatives to GitHub for CI (that aren't GitLab)? Is anyone doing anything particularly novel in this space?


I build Fjord, managed Forgejo with runners. The idea is to keep the GitHub-like workflow without having to operate the forge and CI infrastructure yourself.


Why excluding GitLab?


gitlab is a pig to self host.


Their omnibus docker image isn't bad at all in my experience

https://docs.gitlab.com/install/docker/installation/#install...


But the question was about SaaS


What would you have done if they said no?


There are a bunch of other options. Cameras with agreed-upon privacy blackout areas. Realistic fake cameras. Non-camera security products, like lights and fences. Get a dog.


you place the camera in such a way that it only covers your own property. in germany having a camera that goes beyond your own property is even illegal, so that's the only way to place cameras there.


Chainguard | Product Manager, Scanner | REMOTE | Full-Time | https://www.chainguard.dev/

Chainguard is the trusted source for open source. We build hardened, minimal, continuously-updated images, libraries, and packages that eliminate vulnerabilities before they ship — used by teams at Anduril, Canva, OpenAI, Snap, and Snowflake, among others.

We're hiring a PM to own the malware and greyware scanning engine inside Chainguard Repository — the system that analyzes source code, build behavior, and maintainer activity across the open source packages flowing through our platform to catch compromised or malicious artifacts before they reach a customer's environment. You'd own the roadmap for detection coverage, scanner accuracy (precision/recall trade-offs are the daily grind), and how findings get surfaced to security teams and translated into policy enforcement. Close partnership with our detection engineering and threat research teams, and with customers who are increasingly asking "how do you know this package is safe?"

Good fit if you've done PM work on a detection, fraud, spam, or security scanning system before, are comfortable being hands-on with data and false-positive/false-negative trade-offs, and want to work on a problem that's getting more urgent as AI agents pull in more open source dependencies automatically.

JD to be posted imminently but email me if interested and I'll route appropriately: [email protected]


They're used quite a bit for nerve entrapment—both in diagnosing and treating.


> Anyone know of a better way to protect yourself than setting a min release age on npm/pnpm/yarn/bun/uv (and anything else that supports it)?

Most of these attacks don't make it into the upstream source, so solutions[1] that build from source get you ~98% of the way there. If you can't get a from-source build vs. pulling directly from the registries, can reduce risk somewhat with a cooldown period.

For the long tail of stuff that makes it into GitHub, you need to do some combination of heuristics on the commits/maintainers and AI-driven analysis of the code change itself. Typically run that and then flag for human review.

[1] Here's the only one I know that builds everything from source: https://www.chainguard.dev/libraries

(Disclaimer: I work there.)


Can you give some examples for the claim that most of the attacks don't make it upstream? My gut tells me that, yes, mostly binaries have been compromised. But I am sure you have some real-world examples proving the point.


Build from source is a great idea, I assume you provide SLSA/sigstore like provenance as well?


The chainguard folks built sigstore :)


Yep yep, hence the ask, expected for containers, wondering if also for build from source.


Hmm, we just bought my wife an annual subscription at the Pro tier, largely to use Claude Code. Wonder if she'd be grandfathered in or if we'll need to get a refund.


Isn't this sort of repeated communication gaffe why they hired @OfficialLoganK?


Do any of the bug bounty programs let you filter by some scoring of the source reporter?

Seems like it’d be helpful to bury mass reporters in a de facto spam bucket (where “mass” is some absolute quantity of reports along with percent that are accepted).


I stopped reading the article because of it.


And you moved at a glacial pace compared to Cloudflare. There are tradeoffs.


Yes, of course, I want the organization that inserted itself into handling 20% of the world's internet traffic to move fast and break things. Like breaking the internet on a bi-weekly basis. Yep, great tradeoff there.

Give me a break.


While you're taking your break, exploits gain traction in the wild and one of the value propositions for using a service provider like CloudFlare is catching and mitigating theses exploits as fast as possible. From the OP, this outage was in relation to handling a nasty RCE.


But if your job is mitigate attacks/issues then things can very broken while you're being slow to mitigate it.


Lest we forget, they initially rose to prominence by being cheaper than the existing solutions, not better, and I suppose this is a tradeoff a lot of their customers are willing to make.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: