How Vibeship works
From the repo you built to a live URL — in six steps.
Detect, scan, fix, build, deploy, watch. Here is exactly what Vibeship does at each step, and what you see while it does it.
Step 1 of 6 · Detect
- package.json
- next.config.ts
- prisma/schema.prisma
- app/api/checkout/route.ts
- app/page.tsx
- vercel.json
Your stack
Services it needs
It reads your code and works out how to run it.
Point Vibeship at a GitHub repo, a ZIP or a folder. It finds the framework, the language, and the services your app expects to exist.
- Frameworks like Next.js, Vite, Express, NestJS, Rails, Django, FastAPI, Flask, Laravel, Go, Spring Boot and .NET
- Services it needs — Postgres, Redis, MongoDB, S3-style storage, cron jobs
- No Dockerfile? It writes one. Have one? It uses yours.
- package.json
- next.config.ts
- prisma/schema.prisma
- app/api/checkout/route.ts
- app/page.tsx
- vercel.json
Your stack
Services it needs
A readiness score, and every finding behind it.
The scan checks for the things that break or leak once an app is on the internet, and scores the repo from 0 to 100. The score is a guide to how ready the app is, not a security certificate.
- Leaked secrets — in the code and, for GitHub repos, in git history
- Risky code patterns (Semgrep) and dependencies with known advisories (Trivy)
- Readiness checks for auth, database, payments, email, storage, jobs and headers
- Free, no account needed — with a link you can share
Readiness
68/100
Dependency with a known critical advisory
package-lock.json
Stripe secret key hard-coded in source
lib/stripe.ts:4
.env is committed to the repository
.env
checked: secrets · git history · code (Semgrep) · dependencies (Trivy) · readiness
The exact patch for each finding — you decide.
Fix preview shows the diff for every finding it can repair and re-runs the checks on the patched files, so you can see that the fix works. Nothing is written until you choose.
- Previews are free and change nothing
- Fix and deploy: vulnerable dependencies are bumped, lockfiles rebuilt, and each fix committed separately to a vibeship/deploy branch — your main branch is untouched
- Deploy as is: an owner can go ahead anyway, with a written reason and an expiry date
Fix and deployrecommended
each fix is its own commit on vibeship/deploy
Deploy as is
owner only · needs a reason and an expiry
A signed image, pinned to the byte.
Your app is built in an isolated builder, then locked to an exact image digest so what we tested is exactly what runs.
- Pinned by sha256 digest, never by a moveable tag
- Signed with cosign, with a software bill of materials (SPDX) attached
- The built image is scanned too — a critical vulnerability stops the release
- Dockerfile ready — generated for Next.js
- Built in an isolated builder
- Pinned: my-app@sha256:9f2c…e41a
- Signed with cosign
- SBOM attached (SPDX)
- Image scanned — 0 critical
A live HTTPS URL — proven, not assumed.
Vibeship gives the app its own address on vibeship.run with a certificate, sets up the databases it needs, and then checks it really works before calling it live.
- https://your-app.vibeship.run
- Postgres, Redis, MongoDB or storage provisioned when the app needs them
- Verified: it starts, answers over HTTP, each database answers a real query, and routes match your localhost when you have captured it
Verified before we call it live
- Image built and pinned
- Pods ready, port open
- Answers over HTTP
- Postgres answers a real query
- Routes match your localhost (if captured)
HTTPS certificate issued automatically
Every release kept. Roll back in two clicks.
Every release is kept. Roll back to an earlier verified version in two clicks, and if a new release fails to start, Vibeship puts the previous one back automatically. Your code goes back; your database stays as it is now.
- Drift shows when what is running differs from what was declared
- Roll back to any earlier verified version: two clicks, no migrations run
- A release that doesn’t settle is replaced by the previous one automatically
Drift: running differs from declared
replicas — declared 2 · running 1
a release that doesn’t settle is replaced by the previous one automatically
How long does it take? About 5 minutes.
A scan usually finishes in seconds — half take under 3, and 9 in 10 under 20. A deploy — build, database, certificate and verification — takes about 5 minutes — most deploys land in 4 to 7. Median of successful deploys over the last 14 days (≈5 min); 9 in 10 finish within about 7.
What’s free, and what’s in the deploy beta
Free, always
- Scan any repo — no account needed
- The full readiness report, with a share link
- Fix preview: the exact patch for each finding
Deploy beta · by invitation
- Build: signed, digest-pinned images
- Deploy to your own HTTPS URL, databases included
- Automatic security repair on a vibeship/deploy branch
- Verification before anything is called live
- Every release image kept — roll back to an earlier verified version in two clicks
Deploying is opening in stages while paid plans get ready. Join the waitlist and we’ll turn it on for your workspace.
Join the deploy betaNot yet part of Vibeship: metrics and alerting, templates, agent integrations — they’re coming, and nothing on this page depends on them.
Start with a free scan.
Paste a GitHub URL or drop a ZIP. You’ll get the readiness score, every finding, and the fixes — before you decide anything.