DEV Community

Ofri Peretz profile picture

Ofri Peretz

IC5/M2 Leader @ Snappy US. Building revenue APIs & AI-ready ESLint plugins. Expert in distributed teams, scalable infra, and fostering a culture of craftsmanship.

Education

CS

Work

Engineering Manager @ Snappy | Open Source Developer | ESLint for AI tools

I Audited 203 of Our Own ESLint Security Rules. 16% Mislabel Their Own CVSS Score.

I Audited 203 of Our Own ESLint Security Rules. 16% Mislabel Their Own CVSS Score.

1
Comments
9 min read

Want to connect with Ofri Peretz?

Create an account to connect with Ofri Peretz. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
142,076 Weekly Downloads. Zero Releases Since 2021. Is the Niche Defended?

142,076 Weekly Downloads. Zero Releases Since 2021. Is the Niche Defended?

2
Comments
9 min read
We Were Wrong About sls remove

We Were Wrong About sls remove

1
Comments
8 min read
25% of My Benchmark Verdict Is an Opinion. Here's the Anatomy.

25% of My Benchmark Verdict Is an Opinion. Here's the Anatomy.

1
Comments
8 min read
Marketing Pages Rot Silently. Mine Print an Expiry Date on Every Claim.

Marketing Pages Rot Silently. Mine Print an Expiry Date on Every Claim.

1
Comments
8 min read
Fixtures First, Rules Second: How to Design a Ground-Truth Corpus

Fixtures First, Rules Second: How to Design a Ground-Truth Corpus

1
Comments
9 min read
Valid vs. Reliable Metrics: Consistent Numbers Can Still Be Wrong

Valid vs. Reliable Metrics: Consistent Numbers Can Still Be Wrong

1
Comments
7 min read
Static Analysis vs. SAST vs. Linting: The Taxonomy That Matters for Security Teams

Static Analysis vs. SAST vs. Linting: The Taxonomy That Matters for Security Teams

Comments
8 min read
Sample Size and Statistical Power: What a Small Sample Can and Cannot Tell You

Sample Size and Statistical Power: What a Small Sample Can and Cannot Tell You

Comments
8 min read
Proxy Metrics: The Number You Optimize Is Not the Thing You Want

Proxy Metrics: The Number You Optimize Is Not the Thing You Want

Comments
8 min read
Precision, Recall, and F1 for Static Analysis: Same Score, Opposite Tools

Precision, Recall, and F1 for Static Analysis: Same Score, Opposite Tools

Comments
8 min read
Taint vs. Heuristic Detection: The Difference Between a Proof and a Hunch

Taint vs. Heuristic Detection: The Difference Between a Proof and a Hunch

1
Comments 1
7 min read
Statistical Significance and p-Values: What p > 0.05 Actually Means

Statistical Significance and p-Values: What p > 0.05 Actually Means

Comments
8 min read
Reproducibility vs Replicability: Why Benchmark Numbers Need Both

Reproducibility vs Replicability: Why Benchmark Numbers Need Both

Comments
7 min read
Ranking vs. Measuring: What a Leaderboard Throws Away

Ranking vs. Measuring: What a Leaderboard Throws Away

Comments
8 min read
OWASP Top 10, Explained: An Address System, Not a Severity Scale

OWASP Top 10, Explained: An Address System, Not a Severity Scale

Comments
8 min read
Ground Truth in Security Testing: Who Decides What's Vulnerable?

Ground Truth in Security Testing: Who Decides What's Vulnerable?

Comments
8 min read
The CWE Taxonomy, Explained: A Name Is Not a Verdict

The CWE Taxonomy, Explained: A Name Is Not a Verdict

Comments
8 min read
CVSS Scores Explained: The Number Measures Severity, Not Risk

CVSS Scores Explained: The Number Measures Severity, Not Risk

Comments
8 min read
Composite Scores and Weighting: Your 'Overall Score' Is an Editorial

Composite Scores and Weighting: Your 'Overall Score' Is an Editorial

Comments
8 min read
The Confusion Matrix: What TP, FP, FN, and TN Actually Mean

The Confusion Matrix: What TP, FP, FN, and TN Actually Mean

Comments
8 min read
Inter-Rater Agreement and Cohen's Kappa: When Your Labels Are Opinions

Inter-Rater Agreement and Cohen's Kappa: When Your Labels Are Opinions

Comments
7 min read
I Built What I Benchmark. Here's How I Try Not to Cheat.

I Built What I Benchmark. Here's How I Try Not to Cheat.

Comments
9 min read
Goodhart's Law in Benchmarking: When the Metric Becomes the Target

Goodhart's Law in Benchmarking: When the Metric Becomes the Target

Comments
7 min read
I Maintain 23 Benchmark Suites Across My Own Packages. Only 1 of the Serverless Ones Has Real Numbers Yet.

I Maintain 23 Benchmark Suites Across My Own Packages. Only 1 of the Serverless Ones Has Real Numbers Yet.

Comments
9 min read
Bias in Measurement: The Silent Failure Mode in Benchmark Design

Bias in Measurement: The Silent Failure Mode in Benchmark Design

1
Comments
8 min read
The Base Rate Problem: Why 95% Precision Means Nothing Without Context

The Base Rate Problem: Why 95% Precision Means Nothing Without Context

Comments
7 min read
My credential rule reported 842 secrets in vercel/ai. The real count was 0.

The failure of positive-only testing

My credential rule reported 842 secrets in vercel/ai. The real count was 0.

8
Comments 3
11 min read
MongoDB Injection Bugs Your Code Review Misses: 4 Shapes, 16 ESLint Rules, 1 Honest Gap

MongoDB Injection Bugs Your Code Review Misses: 4 Shapes, 16 ESLint Rules, 1 Honest Gap

1
Comments
21 min read
Gemini 2.5 Pro Wrote Unsafe SQL 96% of the Time: 3 Node.js Injection Patterns — and the ESLint Rule That Catches Them

Gemini 2.5 Pro Wrote Unsafe SQL 96% of the Time: 3 Node.js Injection Patterns — and the ESLint Rule That Catches Them

Comments
12 min read
Claude vs Gemini Across 4 Security Domains: A Dead Heat — and the Hardening 63% of AI Code Skips

Claude vs Gemini Across 4 Security Domains: A Dead Heat — and the Hardening 63% of AI Code Skips

6
Comments 7
9 min read
The Bug That Passes Every Toolchain Check: Circular Dependencies in JavaScript

Bundler trade-offs and hidden CI slowdowns

The Bug That Passes Every Toolchain Check: Circular Dependencies in JavaScript

3
Comments 4
8 min read
Payload CMS Has 508 Circular Dependencies. Next.js Has 17. Here's Why They Form in Every Large JS Codebase.

Payload CMS Has 508 Circular Dependencies. Next.js Has 17. Here's Why They Form in Every Large JS Codebase.

Comments
10 min read
Math.random() Is Not Secure. I Found It Generating API Keys in a 44K-Star Repo.

Math.random() Is Not Secure. I Found It Generating API Keys in a 44K-Star Repo.

4
Comments 2
6 min read
Same NestJS Prompt. Claude Got 6 Security Errors. Gemini Got 2. Here's What Both Got Wrong.

Same NestJS Prompt. Claude Got 6 Security Errors. Gemini Got 2. Here's What Both Got Wrong.

2
Comments
13 min read
5 Cycles Invisible in 14,556 Files. The Cache Bug That Hid Them.

5 Cycles Invisible in 14,556 Files. The Cache Bug That Hid Them.

1
Comments
13 min read
eslint-plugin-import Has 38M Weekly Downloads. Here's What It Still Gets Wrong.

eslint-plugin-import Has 38M Weekly Downloads. Here's What It Still Gets Wrong.

1
Comments
13 min read
Claude Wrote a NestJS Service. TypeScript Was Happy. ESLint Found 6 Security Holes.

Claude Wrote a NestJS Service. TypeScript Was Happy. ESLint Found 6 Security Holes.

5
Comments 7
20 min read
I Inherited a NestJS Codebase. One 12-Second ESLint Run Found 47 Violations Across 6 Vulnerability Classes.

I Inherited a NestJS Codebase. One 12-Second ESLint Run Found 47 Violations Across 6 Vulnerability Classes.

1
Comments 2
18 min read
1.5M Weekly Downloads, 1 False Alarm per Real Bug: the eslint-plugin-security False-Positive Tax

1.5M Weekly Downloads, 1 False Alarm per Real Bug: the eslint-plugin-security False-Positive Tax

Comments
31 min read
The #1 ESLint Security Plugin Just Got Fixed. It Still Catches 0 of 6 SQL Injections.

The #1 ESLint Security Plugin Just Got Fixed. It Still Catches 0 of 6 SQL Injections.

Comments
32 min read
Our linter reported 0 cycles. A cache bug hid 245 files at scale.

Our linter reported 0 cycles. A cache bug hid 245 files at scale.

Comments
18 min read
Aggregate Benchmarks Lie. Here's What 700 AI Functions Look Like by Security Domain.

Aggregate Benchmarks Lie. Here's What 700 AI Functions Look Like by Security Domain.

Comments
27 min read
2 of 3 bugs a 5KB corpus caught were the exact shapes AI writes by default

2 of 3 bugs a 5KB corpus caught were the exact shapes AI writes by default

Comments
15 min read
We Ranked 5 AI Models by Security. The Leaderboard Is Wrong.

We Ranked 5 AI Models by Security. The Leaderboard Is Wrong.

2
Comments
15 min read
I Asked Claude to Fix Its Own Security Bugs. 1 in 3 Fixes Added a NEW Vulnerability.

I Asked Claude to Fix Its Own Security Bugs. 1 in 3 Fixes Added a NEW Vulnerability.

Comments
26 min read
Microsoft's SDL ESLint Plugin Caught 5 Node Vulns. The Domain Plugins Caught 46 — Same File, Wrong Layer

Microsoft's SDL ESLint Plugin Caught 5 Node Vulns. The Domain Plugins Caught 46 — Same File, Wrong Layer

1
Comments
18 min read
SonarJS Has 269 Rules. It Still Missed 26 of My 40 Node.js Vulnerabilities.

SonarJS Has 269 Rules. It Still Missed 26 of My 40 Node.js Vulnerabilities.

Comments
14 min read
eslint-plugin-security Caught 21 Issues. The Domain Plugins Caught 46. Here's the 25-Finding Gap.

eslint-plugin-security Caught 21 Issues. The Domain Plugins Caught 46. Here's the 25-Finding Gap.

Comments
14 min read
I Let Claude Write 80 Functions. 65-75% Had Security Vulnerabilities.

I Let Claude Write 80 Functions. 65-75% Had Security Vulnerabilities.

4
Comments 4
32 min read
PostgreSQL's COPY FROM Can Read /etc/passwd Into Your Database — One ESLint Rule Blocks It.

PostgreSQL's COPY FROM Can Read /etc/passwd Into Your Database — One ESLint Rule Blocks It.

Comments
16 min read
One INSERT Loop Made Our CSV Import 500x Slower. One ESLint Rule Catches It Before It Ships.

One INSERT Loop Made Our CSV Import 500x Slower. One ESLint Rule Catches It Before It Ships.

1
Comments 3
11 min read
search_path Hijacking: the PostgreSQL Attack That Turns SELECT * FROM users Into the Attacker's Table

search_path Hijacking: the PostgreSQL Attack That Turns SELECT * FROM users Into the Attacker's Table

Comments
16 min read
The Express.js Vulnerability Is the Middleware You Forgot — 14 ESLint Rules That Catch What Isn't There

The Express.js Vulnerability Is the Middleware You Forgot — 14 ESLint Rules That Catch What Isn't There

Comments
12 min read
You Can't Review a Decorator That Isn't There — 6 ESLint Rules for NestJS Security

You Can't Review a Decorator That Isn't There — 6 ESLint Rules for NestJS Security

Comments
10 min read
AWS Lambda Security Bugs Your Serverless Functions Are Shipping — 14 ESLint Rules That Catch Them in CI

AWS Lambda Security Bugs Your Serverless Functions Are Shipping — 14 ESLint Rules That Catch Them in CI

Comments
14 min read
4 Browser Security Bugs That Pass Code Review — One Lint Run, 8 CI Errors

4 Browser Security Bugs That Pass Code Review — One Lint Run, 8 CI Errors

Comments
15 min read
JWT Vulnerabilities Your Code Review Approves Every Day — 13 ESLint Rules Stop Them in CI

JWT Vulnerabilities Your Code Review Approves Every Day — 13 ESLint Rules Stop Them in CI

Comments
18 min read
Node.js Security Bugs That Pass Code Review Every Day — 35 Static Analysis Rules That Don't

Node.js Security Bugs That Pass Code Review Every Day — 35 Static Analysis Rules That Don't

Comments
12 min read
no-cycle Is Commented Out in Your ESLint Config. Here Is the Two-Minute Swap That Turns It Back On.

no-cycle Is Commented Out in Your ESLint Config. Here Is the Two-Minute Swap That Turns It Back On.

Comments
9 min read
loading...