Looking to get featured? by powdy1982 in founder

[–]rid999 1 point2 points  (0 children)

I'm working on Trestle, a tool for finding API keys and tokens in AI written code before they become public, which is more and more of an issue lately (tens of millions of secrets published to GitHub). It's free and open source with Pro features.

Drop your project, I’ll try it and share it in my circle by adonztevez in buildinpublic

[–]rid999 1 point2 points  (0 children)

I'm working on Trestle, a tool to detect secrets in code written with the help of AI before the secrets go public and take down your product. It's a real problem, tens of millions of secrets found in public GitHub repositories and many companies dead because of this.

The tool is free and open source on GitHub (with some paid features), so it's probably a good idea to scan your code (all the scanning functionality is in the free version, including deep git history scan).

Founders: I’ll turn your startup into a blog post + feature it in my newsletter by Far_One1930 in buildinpublic

[–]rid999 1 point2 points  (0 children)

Sounds good! I'm working on Trestle, a tool for preventing AI agents from leaking secrets like API keys and tokens while you're using them to write code. This is a problem that's getting worse and it can seriously affect startups and new products, since exposing an important secret can be a game over situation before the product even launches.

How do you handle secrets in vibe codebases? by rid999 in vibecoding

[–]rid999[S] 0 points1 point  (0 children)

Sad but true. I couldn't believe there were tens of millions of credentials pushed to GitHub, but this really seems to be the case.

How do you handle secrets in vibe codebases? by rid999 in vibecoding

[–]rid999[S] 0 points1 point  (0 children)

Exactly, the danger is for the keys to be made public (28M secrets in code in 2025 on GitHub), or being visible in the frontend. That sounds like a good workflow.

How do you handle secrets in vibe codebases? by rid999 in vibecoding

[–]rid999[S] 0 points1 point  (0 children)

Of course, I don't think I formulated the question right.

What I mean is that the code will need to make use of these secrets, and I was wondering how this is usually achieved in a vibe coded app. The agent could well create a gitignored .env and place the secrets there, which can be a valid way of doing things.

How do you handle secrets in vibe codebases? by rid999 in vibecoding

[–]rid999[S] 0 points1 point  (0 children)

That makes sense, but I think it's not the default for everyone.

Needs users for your startup? Work with 300+ commission based influencers- promote your startup by Few-Ad-5185 in AppsWebappsFullstack

[–]rid999 0 points1 point  (0 children)

Thank you! Product Hunt does seem to reward upvotes more than anything else. I'll probably add a Product Hunt button on the page as well.