Renamed
Amazon CodeWhisperer became Amazon Q Developer on April 30, 2024
perch vs Amazon CodeWhisperer
Side-by-side comparison of features, pricing, and ratings
At a glance
| Dimension | perch | Amazon CodeWhisperer |
|---|---|---|
| Category | Semantic code linter (CLI) | AI coding assistant / IDE plugin |
| Pricing | Free | Freemium (free tier + Pro) |
| Install | npm install -g @lakeday/perch | IDE extension + CLI |
| Core job | Enforce repo rules with natural-language `--ensure` guarantees | Generate code, agentic tasks, security scan, modernization |
| Integrations | GitHub Actions, Claude Code, Codex, Cursor | VS Code, JetBrains, Visual Studio, Eclipse, AWS Console, Slack, Teams, GitLab, GitHub |
| Current name | Perch (@lakeday/perch) | Rebranded to Amazon Q Developer (Apr 2024) |
Perch is a semantic code linter that turns your team's review rules into committed, executable policy checks powered by Jev.
Visit WebsiteRenamed: Amazon CodeWhisperer became Amazon Q Developer on April 30, 2024; all its features moved there.
Visit WebsiteWhat real users say: perch vs Amazon CodeWhisperer
Not marketing copy and not our opinion — a structured sweep of public discussion (reviews, forums, communities and video comments), showing what people praise and what they complain about for each tool.
perch
70 mentions across 6 sources · 14% positive — critical (weighted across 6 sources)
Reddit, Hacker News, YouTube, Product Hunt, GitHub, Lemmy
What users praise
- • Free and globally installed via npm as @lakeday/perch — zero cost to try.
- • Natural-language rules in perch.yaml let you encode team conventions as reviewable code.
- • Findings include rule ID, file:line, severity, confidence percentage, and enclosing method.
- • Per-finding confidence scoring avoids binary pass/fail and reduces false-positive fatigue.
What frustrates them
- • Almost no independent user reviews or testimonials exist for the actual linter.
- • Open language-filtering bug means shipped scans may flag irrelevant vulnerability classes.
- • No listed integrations with CI/CD, editors, or Slack — everything is manual CLI wiring.
- • Name collision with Google Perch and a board game makes community support hard to find.
Researched Sep 26, 2026
Amazon CodeWhisperer
11 mentions across 3 sources · 55% positive — mixed (weighted across 3 sources)
Hacker News, YouTube, Product Hunt
What users praise
- • Generous free tier: 50 agentic chat interactions and 1,000 lines of transformation monthly.
- • Built-in open-source license reference tracker provides clear attribution and legal safety.
- • Seamless integration within AWS ecosystem, including console, Slack, and Microsoft Teams.
- • Strong security scanner that identifies vulnerabilities and suggests fixes directly in code.
What frustrates them
- • AWS-centric focus is a disadvantage for non-AWS cloud developers.
- • Semantic analysis concept criticized as fundamentally flawed by HN commenter.
- • Some view tool as trend-driven rather than innovative, lacking true 'semantic' understanding.
- • Performance quality of code suggestions not consistently benchmarked against GPT or Copilot.
Researched Sep 9, 2026
Feature-by-feature
Q Developer and Perch overlap only in "code quality," and even there they do different things. Q Developer is a generative assistant: real-time suggestions, inline chat, CLI autocompletion and natural-language-to-bash, agentic multi-step implementation with unit tests, Java 8-to-17 upgrades and .NET Windows-to-Linux porting, plus an AWS-expert chat in Slack, Teams, and the AWS Console. Its built-in security scanner finds vulnerabilities and proposes fixes. Perch doesn't generate or refactor code at all. It scans a tree with perch scan and reports rule ID, file:line, severity, a confidence percentage (e.g. 91%, 78%), and the enclosing method — probabilistic judgments, not pass/fail. Its differentiator is authoring: you write rules in perch.yaml with perch rules add --ensure in plain language, scope them with --each method/--each file and --where "src/**/*.ts", filter with --filter rule=<name>, test against a symbol with perch check <file>::<method>, and scan only changed files via --since origin/main. It catches off-by-one loops, MD5-hashed tokens, and unhandled nulls, fails CI on breaking findings with exit code 3, and stores results in .perch. Q Developer's checks are vendor-defined; Perch's are whatever your team commits.
Pricing compared
Q Developer is freemium per its pricing data: there's a free tier plus a Pro tier whose stated benefit is that proprietary content isn't used for service improvement — relevant if your code can't train a vendor model. Specific dollar figures aren't in the data provided, so verify current AWS pricing before budgeting. Perch is free and open to install globally via npm (npm install -g @lakeday/perch), with findings stored locally in .perch. The honest cost of Perch isn't license fees — it's the engineering time to write and maintain your perch.yaml rules, since zero-config linting is explicitly not the product. If your team won't invest that authoring time, Perch delivers little; if it will, the marginal cost per scan is near zero. For Q Developer, the calculus flips: you get immediate value out of the box, but you're paying (or accepting the free tier's terms) and you're anchored to the AWS ecosystem. Note the not-for lists: Q Developer isn't for multi-cloud or non-AWS teams; Perch isn't for teams needing a hosted dashboard or org-wide analytics.
Who should pick which
- AWS-centric dev team modernizing legacy appsPick: Amazon CodeWhisperer
Java 8-to-17 upgrades and .NET Windows-to-Linux porting are built-in agentic features no linter touches.
- Team reviewing AI-generated PRs from Cursor/Codex/Claude CodePick: perch
It integrates with those agents and gates code with committed, readable rules and confidence-scored findings.
- Enterprise needing IAM-based access controls and privacyPick: Amazon CodeWhisperer
IAM Identity Center controls and Pro-tier privacy protections are listed features; Perch explicitly lacks multi-user policy management.
- Solo dev who wants defect/security detection cheaplyPick: perch
Free, local findings in .perch with near-zero scan cost — provided you write your own rules.
- Team whose review friction is project-specific behaviorPick: perch
'--ensure' natural-language rules target things like logging secrets or discount caps that generic linters miss.
Frequently Asked Questions
Is Amazon CodeWhisperer still called that?
No — it rebranded to Amazon Q Developer in April 2024, with expanded agentic features. The slug here is legacy naming.
Can I run both Perch and Q Developer together?
Yes. They operate at different layers. Q Developer generates, refactors, and scans inside your IDE; Perch enforces repo-committed rules in CI. Many teams will stack them.
Does Perch generate or fix code?
No. It finds and reports issues with rule ID, location, severity, and confidence. Fixing is left to you or your AI coding agent.
Do I need to write rules for Perch to be useful?
Yes. Perch explicitly isn't zero-config drop-in linting — value depends on your perch.yaml rules authored via `perch rules add --ensure`.
Can Q Developer enforce my team's custom policy rules in CI?
Its security scanning and remediation suggestions are vendor-defined (AWS-focused). If you need repo-committed natural-language rules with exit code 3 CI gating, that's Perch's job.
Is Perch suitable for org-wide analytics or hosted dashboards?
Its not-for list rules these out. Findings live locally in `.perch`; there's no multi-user policy management or cross-repo analytics.
More perch or Amazon CodeWhisperer comparisons
These aren't really competitors, so treat it as a 'what problem are you buying for' question rather than a bake-off. Endor Labs is for security and DevSecOps teams that need reachability-verified vuln
These two do not compete for the same budget, so there is no head-to-head winner. If your problem is adversarial risk in production AI agents — shadow AI, guardrail bypasses, exploit-backed findings y
These are two different line items on the same engineering budget, and most teams adopting agents will eventually want both. Bito is the one that pays for itself only at scale — it needs multi-repo ag
These are different purchases despite both being code security tools. Snyk DeepCode AI is a platform commitment: you get hybrid symbolic+ML detection, Agent Fix autofixes, context-aware prioritization
These two will never appear on the same shortlist. If you're a lean IT team or an MSP trying to collapse endpoint, email, cloud, identity, network and data security into one agent and one console, Cor
Explore each tool further
Browse these categories
One email a week — new tools, honest comparisons, no spam.
Last reviewed: September 26, 2026