
Security News
Scaling Socket from Zero to 10,000+ Organizations
Socket CEO Feross Aboukhadijeh shares lessons from scaling a developer security startup to 10,000+ organizations in this founder interview.
@wholelottahoopla/vkanban
Advanced tools
<source srcset="frontend/public/vibe-kanban-logo-dark.svg" media="(prefers-color-scheme: dark)"> <source srcset="frontend/public/vibe-kanban-logo.svg" media="(prefers-color-s
Get 10X more out of Claude Code, Gemini CLI, Codex, Amp and other coding agents...

AI coding agents are increasingly writing the world's code and human engineers now spend the majority of their time planning, reviewing, and orchestrating tasks. Vibe Kanban streamlines this process, enabling you to:
You can watch a video overview here.
Make sure you have authenticated with your favourite coding agent. A full list of supported coding agents can be found in the docs. Then in your terminal run:
npx vibe-kanban
Please head to the website for the latest documentation and user guides.
We use GitHub Discussions for feature requests. Please open a discussion to create a feature request. For bugs please open an issue on this repo.
We would prefer that ideas and changes are first raised with the core team via GitHub Discussions or Discord, where we can discuss implementation details and alignment with the existing roadmap. Please do not open PRs without first discussing your proposal with the team.
Additional development tools:
cargo install cargo-watch
cargo install sqlx-cli
Install dependencies:
pnpm i
pnpm run dev
This will start the backend. A blank DB will be copied from the dev_assets_seed folder.
To build just the frontend:
cd frontend
pnpm build
build-npm-package.shnpx-cli folder run npm packnpx [GENERATED FILE].tgzThe following environment variables can be configured at build time or runtime:
| Variable | Type | Default | Description |
|---|---|---|---|
GITHUB_CLIENT_ID | Build-time | Ov23li9bxz3kKfPOIsGm | GitHub OAuth app client ID for authentication |
POSTHOG_API_KEY | Build-time | Empty | PostHog analytics API key (disables analytics if empty) |
POSTHOG_API_ENDPOINT | Build-time | Empty | PostHog analytics endpoint (disables analytics if empty) |
BACKEND_PORT | Runtime | 0 (auto-assign) | Backend server port |
FRONTEND_PORT | Runtime | 3000 | Frontend development server port |
HOST | Runtime | 127.0.0.1 | Backend server host |
DISABLE_WORKTREE_ORPHAN_CLEANUP | Runtime | Not set | Disable git worktree cleanup (for debugging) |
Build-time variables must be set when running pnpm run build. Runtime variables are read when the application starts.
By default, Vibe Kanban uses Bloop AI's GitHub OAuth app for authentication. To use your own GitHub app for self-hosting or custom branding:
user:email,repoGITHUB_CLIENT_ID=your_client_id_here pnpm run build
When running Vibe Kanban on a remote server (e.g., via systemctl, Docker, or cloud hosting), you can configure your editor to open projects via SSH:
When configured, the "Open in VSCode" buttons will generate URLs like vscode://vscode-remote/ssh-remote+user@host/path that open your local editor and connect to the remote server.
See the documentation for detailed setup instructions.
FAQs
<source srcset="frontend/public/vibe-kanban-logo-dark.svg" media="(prefers-color-scheme: dark)"> <source srcset="frontend/public/vibe-kanban-logo.svg" media="(prefers-color-s
The npm package @wholelottahoopla/vkanban receives a total of 0 weekly downloads. As such, @wholelottahoopla/vkanban popularity was classified as not popular.
We found that @wholelottahoopla/vkanban demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Socket CEO Feross Aboukhadijeh shares lessons from scaling a developer security startup to 10,000+ organizations in this founder interview.

Research
Socket Threat Research maps a rare inside look at OtterCookie’s npm-Vercel-GitHub chain, adding 197 malicious packages and evidence of North Korean operators.

Research
Socket researchers identified a malicious Chrome extension that manipulates Raydium swaps to inject an undisclosed SOL transfer, quietly routing fees to an attacker wallet.