Gl

Globstar – Open-source static analysis toolkit

Hacker News

Globstar – Open-source static analysis toolkit

Hey HN! We’re Jai and Sanket, co-founders of DeepSource (YC W20). We're open-sourcing Globstar ( https://github.com/DeepSourceCorp/globstar ), a static analysis toolkit that lets you easily write and run custom code quality and security checkers in YAML [1] or Go [2]. After 5+ years of building AST-based static analyzers that process millions of lines of code daily at DeepSource, we kept hearing a common request from customers: "How do we write custom checks specific to our codebase?" AppSec and DevOps teams have a lot of learned anti-patterns and security rules they want to enforce across their orgs, and being able to do that without being a static analysis expert, came up as an important want. We initially built an internal framework using tree-sitter [3] for our proprietary infrastructure-as-code analyzers, which enabled us to rapidly create new checkers. We realized that making the framework open-source could solve this problem for everyone. Our key insight was that writing checkers isn't the hard part anymore. Modern AI assistants like ChatGPT and Claude are excellent at generating tree-sitter queries with very high accuracy. We realized that the tree-sitters' gnarly s-expression syntax isn’t a problem anymore (since the AI will be doing all the generation anyway), and we can instead focus on building a fast, flexible, and reliable checker runtime around it. So instead of creating yet another DSL, we use tree-sitter's native query syntax. Yes, the expressions look more complex than simplified DSLs, but they give you direct access to your code's actual AST structure – which means your rules work exactly as you'd expect them to. When you need to debug a rule, you're working with the actual structure of your code, not an abstraction that might hide important details. We've also designed Globstar to have a gradual learning curve: The YAML interface works well for simple checkers, and the Go Interface can handle complex scenarios when you need features like cross-file analysis, scope resolution, data flow analysis, and context awareness. The Go API gives you direct access to tree-sitter bindings, so you can write arbitrarily complex checkers on day one. Key features: - Written in Go with native tree-sitter bindings, distributed as a single binary - MIT-licensed - Write all your checkers in a “.globstar” folder in your repo, in YAML or Go, and just run “globstar check” without any build steps - Multi-language support through tree-sitter (20+ languages today) We have a long way to go and a very exciting roadmap for Globstar, and we’d love to hear your feedback! [1] https://globstar.dev/guides/writing-yaml-checker [2] https://globstar.dev/guides/writing-go-checker [3] https://tree-sitter.github.io/tree-sitter/

Share card

Actual performance

103points
22comments
Made the leaderboard

Launch Intel predictions

Analyze your own launch →
Product HuntOn track for Day 1 leaderboard · Strong signals: claude, apps, new · Missing: mac, agents, macos
94%94% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Indie HackersFits the IH revenue-focused audience · Strong signals: ios · Missing: supports, reddit linkedin, podcasting
81%81% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
Hacker NewsStrong engagement from HN community · Strong signals: ide, io · Missing: https docs, excited, just released
72%72% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
TrustMRRLess likely to generate early MRR · Strong signals: ios, apps, way · Missing: mobile apps, personal, entrepreneurs
46%46% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
AppSumoMay struggle as an AppSumo deal · Strong signals: interface · Missing: plus, platform, intuitive
36%36% predicted probability of success on AppSumo, based on ML models trained on real launch data.
Acquire.comPre-revenue stage for this audience · Missing: arr, mrr, revenue
21%21% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
BetaListMay not resonate with beta-testers · Strong signals: chat · Missing: web3, crypto, cryptocurrency
0%0% predicted probability of success on BetaList, based on ML models trained on real launch data.

Correct prediction on native model

Similar products

In
InvokeAI, an open source Stable Diffusion toolkit and WebUI58%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

InvokeAI, an open source Stable Diffusion toolkit and WebUI

Hacker News414
AR
ARR-Medic-CYP3A4 – Open-Source Drug Interaction Toolkit48%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

ARR-Medic-CYP3A4 – Open-Source Drug Interaction Toolkit

Hacker News1
An
An open-source platform for deploying static apps67%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

An open-source platform for deploying static apps

Hacker News7
An
An open-source platform for deploying static apps67%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

An open-source platform for deploying static apps

Hacker News1
Sy
SyncLite – Open Source Data Consolidation Toolkit74%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

SyncLite – Open Source Data Consolidation Toolkit

Hacker News3
pe
perl-lsp – annotation free static analysis for Perl47%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

perl-lsp – annotation free static analysis for Perl

Hacker News3
Li
Linting and static analysis of Clojure code59%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Linting and static analysis of Clojure code

Hacker News5
Sm
Smalisca – Static Code Analysis for Smali53%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Smalisca – Static Code Analysis for Smali

Hacker News6
Li
Lightly Insights – open-source dataset analysis50%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Lightly Insights – open-source dataset analysis

Hacker News2
Co
CodeClarity – an open source source code analysis platform48%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

CodeClarity – an open source source code analysis platform

Hacker News4