- ex HeimWall publishes the noise next to the signal
A vendor benchmark that prints its own false-positive breakdown — 1.12% alert rate, 48% of alerts from one noisy rule, a middling F1 it admits to — on a public dataset anyone can rerun, making the headline finding believable instead of dismissible.
- 07-21 The security benchmark that published its own false-positive rate
HeimWall's secret-scan post ran on a public dataset anyone can rerun, showed which rule produced half its alerts, and printed its own mediocre benchmark scores — a copyable template for content that survives a developer's fact-check.
- 07-28 Kastra: A policy layer that bets on the coding-agent market staying fragmented
Kastra shipped a runtime authorization layer that intercepts agent tool calls with identity, scope, guardrail and audit checks at sub-millisecond allow/deny, and it covers Claude Code, Cursor and Codex rather than integrating with one harness. Traction is modest — 13 points and 5 comments — on a Show HN posted around 2026-07-10 that only cleared this site's sweep on 07-28.
- 07-28 GitHub: A supply-chain bundle lands a day after a viral trust critique
GitHub shipped npm publish-time malware scanning, extended Dependabot malicious-package alerts across more ecosystems via the OpenSSF malicious-packages feed, and started holding Actions workflows it flags as potentially malicious for manual approval. It landed one day after a researcher post documenting thousands of discoverable malware repos — deleted post-hoc, with no lasting filter — reached the Hacker News front page.