404 Not Found Yet · dawidwojda/404-not-found-yet
A rigorously engineered and honestly scoped defensive cloud-exposure response prototype whose detection loop and degraded-state handling are genuinely live, held back mainly by limited conceptual novelty and a remediation loop proven only in fixture mode.
The built product is a focused cloud posture scanner with a safety-first remediation loop, an established category where Security Hub and Prowler already compete. The pitched differentiators (CodeQL, email, correlation) are roadmap rather than code, so the evidence supports the lower read: solid and well-reasoned, with the real originality sitting in evidence handling and degraded-state design rather than a new concept.
Members disagree here: scores range by 2.0 points.Squarely defensive work: real public SSH, S3 and IAM detectors plus a consequence-reducing remediation path with manual approval, verification and audit. Degraded handling is explicitly implemented (failed scans retain last-known findings, permission errors surface as permission_missing, per-source health), which matches the brief's incomplete-information requirement. All three members confirm this and none of their reservations change it.
A live public demo with a guided operator flow, judge credentials and readable error states is real. But onboarding requires a customer-deployed Terraform connector, Cognito and IAM setup, and the deployment allowlists a single tenant, account and region, so a judge or small team cannot connect their own environment and live remediation is disabled.
A deliberate visual system is evident: semantic severity colors, keyboard navigation, reduced-motion support, and polished error and denial states. Reservations stand about crisis readability of the dense cyberpunk style, and the five described screenshots skew toward error pages, so positive-state dashboard quality rests mostly on deck and docs.
Exceptional for 24 hours by any of the reviews: about 15,800 lines of TypeScript, 133 tests including Terraform tests, three infrastructure roots, and a deployed cross-account stack validated with concrete finding IDs. The measured facts support the higher scores here over member C's lower one; the only real gap is that live remediation was never executed against real AWS, so the flagship closed loop is proven live only through detection.
Members disagree here: scores range by 2.0 points.claude:glm-5.3-flash74.090% agreedots-studio/dots-3-note-preview:free83.580% agreeinclusionai/ling-3.0-flash-sante:free70.070% agreeclaude:glm-5.3–judgeThe council, the evidence pack, the prompts and the queue are all on GitHub. If a review helped you, a star helps other teams find it.