Security — hobby stack.
For each requirement below, pick the option that fits your build — recommended first, then free and cheaper alternatives — or skip what your project doesn't need. Tap the info icon next to any requirement to see why it matters.
Source Code Repository & Branch Protection with Signed Commits
Where your source code lives and is collaborated on. Non-negotiable for any team or serious project.Pricing & free-tier limitsFree: unlimited public/private repos, 500MB Packages, 2000 Actions mins/mo, 1 push protection bypass / Team: $4/user/mo - 3k mins, reviewers, draft PR protection / Enterprise: $21/user/mo - 50k mins, SAML SSO, audit log streaming / Overage: $0.008/min Actions, $0.25/GB Packages over
CI/CD Pipeline & Hardened Runners
Automates testing and deploying your code. Saves enormous time and prevents “works on my machine” releases.Pricing & free-tier limitsFree: 2000 mins/mo Linux, 500MB cache, self-hosted unlimited / Team: $4/user - 3k mins incl / Paid: $0.008/min Linux, $0.016/min macOS, $0.08/min Windows 2-core, $0.32/min GPU / Cache $0.25/GB over 10GB / Overage billed minute
Artifact Registry & Signature Verification (Sigstore/Cosign)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: GHCR 500MB storage + 1GB transfer/mo free, Sigstore keyless signing free public / Harbor OSS free self-host / Paid: ECR $0.10/GB storage, $0.20/GB transfer / JFrog $50k/yr ent, $0.20/GB over / GCP AR $0.10/GB/mo + $0.12/GB egress over 1GB
Secrets Management Enterprise (Vault + HSM + CloudHSM)
Stores API keys and credentials safely, separate from your code. Leaking secrets is one of the most common breaches.Pricing & free-tier limitsFree: Vault OSS free self-hosted (no support), Infisical OSS unlimited self-host / Cheaper: AWS $0.40/secret/mo + API, Infisical $29/mo 10k secrets / Paid: HCP Vault $0.50/hr dev $1.32/hr ent (~$950/mo), $0.03/10k ops over 1M included / CloudHSM $1.88/hr/instance (~$1373/mo per HSM) + Vault Ent $50k/yr
Key Management Service (KMS) & CloudHSM
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: SoftHSM free unlimited keys for dev, LocalStack free mock / KMS: $1/key/mo, $0.03/10k requests, $0.06/10k asymmetric / CloudHSM: $1.88/hr ~$1373/mo per HSM, $0 over incl - pay for instance only / Thales: $1800/mo single, $5400/mo HA / Overages: KMS requests $0.03/10k, HSM no req overage
SAST Scanning (Static Application Security Testing)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: CodeQL unlimited public, 2000 private mins/mo / Semgrep CE unlimited scans, 2k OSS rules / SonarQube CE free unlimited LOC self-host / Team: $20/dev/mo Semgrep 5k scans, $32/mo SonarCloud 100k LOC / Paid: $98/dev/mo Snyk/Checkmarx, $150k/yr SonarQube 5M LOC + $0.05 per k LOC over
Dependency Scanning / SCA (Software Composition Analysis)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Dependabot unlimited PRs free, OSV unlimited API / Team: Snyk Team $25/dev/mo 1M tests included, $0.01 per 1k over / Socket $20/dev 500k checks / Paid: Business $98/dev 5M tests, $0.05/1k over / Mend $50k/yr ~$500/dev overage after 100 devs
Container / Image Scanning + SBOM
Where you keep files users upload or you serve — images, videos, documents — and how fast they reach visitors around the world.Pricing & free-tier limitsFree: Trivy/Grype unlimited scans OSS free self-host / Docker Scout Free 3 repo scans / Cheaper: Scout Team $12/user 200 scans/mo $0.10/scan over / Paid: Aqua $40k/yr 500 images $80/image over / Snyk Container $98/dev unlimited / Anchore $35k/yr 500 images
Audit Logs WORM Storage (Immutable Audit - S3 Object Lock)
Where you keep files users upload or you serve — images, videos, documents — and how fast they reach visitors around the world.Pricing & free-tier limitsFree: MinIO OSS free self-host WORM unlimited / B2 $0.006/GB/mo lock free / Wasabi $6.99/TB/mo immutable / AWS: S3 Standard $0.023/GB/mo, PUT $0.005/1k, CloudTrail Lake $2.5/GB ingestion + $0.75/GB/mo 7yr storage, $0.005 per 1k queries / Glacier Vault Lock $0.004/GB mo
SIEM / Log Management (Splunk, Panther, Wazuh)
Tells you when things break and why. You cannot fix what you cannot see — this is how you keep downtime short.Pricing & free-tier limitsFree: Wazuh OSS unlimited free self-host, Elastic Free 5GB/day, Graylog Community free / Cheaper: Panther Free 5GB/day > $0.30/GB over / Paid: Splunk $150/GB/day ingestion ~ $150/GB/mo, $0.10/GB over 10GB hot to warm / Chronicle $2/GB ingestion $0.20/GB retention / Elastic $95/mo + $0.15/GB over 10GB
Documentation & Security Advisory Portal (CVE Publishing)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Docusaurus/MkDocs free self-host unlimited / GitHub Pages free 100GB bandwidth / GitBook Pro $32/mo 10k views $0.01/view over / Enterprise $399/mo unlimited views + SLA / Confluence Premium $10/user/mo $870/mo 100 users / Statuspage $29/mo 100 subscribers
How this hobby security checklist works.
Each requirement below is something a hobby security build typically needs. Pick one of the four researched options — recommended, free, cheaper or paid — add your own with "Other", or skip the requirement if your project doesn't need it. Nothing is mandatory; the plan on the right tracks what you've decided so nothing gets forgotten.
Your picks are saved in this browser automatically, so you can come back anytime. Options are researched per build level and refreshed as vendors change their plans — always verify details on the provider's page before committing.