Lintel
Catch cloud-native risks before they ship — with simple, deterministic, advisory-only linters.
Shift-left security that developers actually use
Lintel provides small, read-only APIs that inspect common artifacts in modern delivery pipelines. No agents. No policy engines. No “trust us” magic — just explainable findings you can wire into CI/CD.
What Lintel does
Terraform Plan Risk Inspector
Inspect a Terraform plan JSON and surface security + operational risks before terraform apply.
Dockerfile Security Linter
Analyze Dockerfiles for insecure defaults, unsafe patterns, and build-time risks.
Dependency Confusion Checker (coming next)
Detect private/internal package names that exist on public registries like PyPI or npm — a critical supply chain defense.
Built for developers
- Stateless, read-only APIs
- Deterministic results
- CI/CD friendly
- Clear JSON output
- No vendor lock-in