How Vibeship works

From the repo you built to a live URL — in six steps.

Detect, scan, fix, build, deploy, watch. Here is exactly what Vibeship does at each step, and what you see while it does it.

Step 1 of 6 · Detect

1 / DetectFree

It reads your code and works out how to run it.

Point Vibeship at a GitHub repo, a ZIP or a folder. It finds the framework, the language, and the services your app expects to exist.

  • Frameworks like Next.js, Vite, Express, NestJS, Rails, Django, FastAPI, Flask, Laravel, Go, Spring Boot and .NET
  • Services it needs — Postgres, Redis, MongoDB, S3-style storage, cron jobs
  • No Dockerfile? It writes one. Have one? It uses yours.
github.com/you/my-app — reading 214 files
  • package.json
  • next.config.ts
  • prisma/schema.prisma
  • app/api/checkout/route.ts
  • app/page.tsx
  • vercel.json

Your stack

Next.jsTypeScriptPrisma

Services it needs

PostgresStripe SDK1 cron job
No Dockerfile? Vibeship writes one for your framework.
2 / ScanFree

A readiness score, and every finding behind it.

The scan checks for the things that break or leak once an app is on the internet, and scores the repo from 0 to 100. The score is a guide to how ready the app is, not a security certificate.

  • Leaked secrets — in the code and, for GitHub repos, in git history
  • Risky code patterns (Semgrep) and dependencies with known advisories (Trivy)
  • Readiness checks for auth, database, payments, email, storage, jobs and headers
  • Free, no account needed — with a link you can share
Readiness reportfree · no account

Readiness

68/100

critical1
high2
medium4
low2

Dependency with a known critical advisory

package-lock.json

fix ready

Stripe secret key hard-coded in source

lib/stripe.ts:4

fix ready

.env is committed to the repository

.env

fix ready

checked: secrets · git history · code (Semgrep) · dependencies (Trivy) · readiness

3 / FixFree

The exact patch for each finding — you decide.

Fix preview shows the diff for every finding it can repair and re-runs the checks on the patched files, so you can see that the fix works. Nothing is written until you choose.

  • Previews are free and change nothing
  • Fix and deploy: vulnerable dependencies are bumped, lockfiles rebuilt, and each fix committed separately to a vibeship/deploy branch — your main branch is untouched
  • Deploy as is: an owner can go ahead anyway, with a written reason and an expiry date
Fix preview — nothing is written until you choose
package.json re-scanned clean
"dependencies": {
- "some-lib": "4.17.20",
+ "some-lib": "4.17.21",
}
.gitignore
+ .env

Fix and deployrecommended

each fix is its own commit on vibeship/deploy

Deploy as is

owner only · needs a reason and an expiry

4 / BuildDeploy beta

A signed image, pinned to the byte.

Your app is built in an isolated builder, then locked to an exact image digest so what we tested is exactly what runs.

  • Pinned by sha256 digest, never by a moveable tag
  • Signed with cosign, with a software bill of materials (SPDX) attached
  • The built image is scanned too — a critical vulnerability stops the release
Build
  • Dockerfile ready — generated for Next.js
  • Built in an isolated builder
  • Pinned: my-app@sha256:9f2c…e41a
  • Signed with cosign
  • SBOM attached (SPDX)
  • Image scanned — 0 critical
5 / DeployDeploy beta

A live HTTPS URL — proven, not assumed.

Vibeship gives the app its own address on vibeship.run with a certificate, sets up the databases it needs, and then checks it really works before calling it live.

  • https://your-app.vibeship.run
  • Postgres, Redis, MongoDB or storage provisioned when the app needs them
  • Verified: it starts, answers over HTTP, each database answers a real query, and routes match your localhost when you have captured it
https://my-app.vibeship.runlive

Verified before we call it live

  • Image built and pinned
  • Pods ready, port open
  • Answers over HTTP
  • Postgres answers a real query
  • Routes match your localhost (if captured)

HTTPS certificate issued automatically

6 / WatchDeploy beta

Every release kept. Roll back in two clicks.

Every release is kept. Roll back to an earlier verified version in two clicks, and if a new release fails to start, Vibeship puts the previous one back automatically. Your code goes back; your database stays as it is now.

  • Drift shows when what is running differs from what was declared
  • Roll back to any earlier verified version: two clicks, no migrations run
  • A release that doesn’t settle is replaced by the previous one automatically
my-app — overview

Drift: running differs from declared

replicas — declared 2 · running 1

v4add checkout page live
v3fix login redirect kept
v2first deploy with Postgres kept

a release that doesn’t settle is replaced by the previous one automatically

How long does it take? About 5 minutes.

A scan usually finishes in seconds — half take under 3, and 9 in 10 under 20. A deploy — build, database, certificate and verification — takes about 5 minutes — most deploys land in 4 to 7. Median of successful deploys over the last 14 days (≈5 min); 9 in 10 finish within about 7.

What’s free, and what’s in the deploy beta

Free, always

  • Scan any repo — no account needed
  • The full readiness report, with a share link
  • Fix preview: the exact patch for each finding
Scan your repo free

Deploy beta · by invitation

  • Build: signed, digest-pinned images
  • Deploy to your own HTTPS URL, databases included
  • Automatic security repair on a vibeship/deploy branch
  • Verification before anything is called live
  • Every release image kept — roll back to an earlier verified version in two clicks

Deploying is opening in stages while paid plans get ready. Join the waitlist and we’ll turn it on for your workspace.

Join the deploy beta

Not yet part of Vibeship: metrics and alerting, templates, agent integrations — they’re coming, and nothing on this page depends on them.

Start with a free scan.

Paste a GitHub URL or drop a ZIP. You’ll get the readiness score, every finding, and the fixes — before you decide anything.