Observed arrival · 2026-08-26
BlastRadius catches the Terraform destroy hiding in your pull request
A Terraform plan reviewer that posts one severity-ranked pull-request comment about destructive changes and widening access.
Field notes
BlastRadius runs against the Terraform plan file a CI workflow already creates, using terraform show -json rather than requiring a separate planning process. Its homepage describes redaction inside the runner, including Terraform-sensitive values and provider secret attributes, before anything is uploaded. The current rule set is AWS-focused and includes stateful replacement and security-group widening; each rule is checked against both a plan that should trigger it and one that should not.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue