Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
Foundations Series' Articles
Back to Ofri Peretz's Series
The Base Rate Problem: Why 95% Precision Means Nothing Without Context
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 18
The Base Rate Problem: Why 95% Precision Means Nothing Without Context
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
7 min read
Bias in Measurement: The Silent Failure Mode in Benchmark Design
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 18
Bias in Measurement: The Silent Failure Mode in Benchmark Design
#
security
#
devsecops
#
node
#
javascript
1
reaction
Comments
Add Comment
8 min read
Goodhart's Law in Benchmarking: When the Metric Becomes the Target
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 18
Goodhart's Law in Benchmarking: When the Metric Becomes the Target
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
7 min read
Inter-Rater Agreement and Cohen's Kappa: When Your Labels Are Opinions
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 18
Inter-Rater Agreement and Cohen's Kappa: When Your Labels Are Opinions
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
7 min read
The Confusion Matrix: What TP, FP, FN, and TN Actually Mean
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
The Confusion Matrix: What TP, FP, FN, and TN Actually Mean
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
8 min read
Composite Scores and Weighting: Your 'Overall Score' Is an Editorial
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
Composite Scores and Weighting: Your 'Overall Score' Is an Editorial
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
8 min read
CVSS Scores Explained: The Number Measures Severity, Not Risk
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
CVSS Scores Explained: The Number Measures Severity, Not Risk
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
8 min read
The CWE Taxonomy, Explained: A Name Is Not a Verdict
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
The CWE Taxonomy, Explained: A Name Is Not a Verdict
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
8 min read
Ground Truth in Security Testing: Who Decides What's Vulnerable?
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
Ground Truth in Security Testing: Who Decides What's Vulnerable?
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
8 min read
OWASP Top 10, Explained: An Address System, Not a Severity Scale
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
OWASP Top 10, Explained: An Address System, Not a Severity Scale
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
8 min read
Ranking vs. Measuring: What a Leaderboard Throws Away
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
Ranking vs. Measuring: What a Leaderboard Throws Away
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
8 min read
Reproducibility vs Replicability: Why Benchmark Numbers Need Both
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
Reproducibility vs Replicability: Why Benchmark Numbers Need Both
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
7 min read
Statistical Significance and p-Values: What p > 0.05 Actually Means
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
Statistical Significance and p-Values: What p > 0.05 Actually Means
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
8 min read
Taint vs. Heuristic Detection: The Difference Between a Proof and a Hunch
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
Taint vs. Heuristic Detection: The Difference Between a Proof and a Hunch
#
security
#
eslint
#
devsecops
#
javascript
1
reaction
Comments
1
comment
7 min read
Precision, Recall, and F1 for Static Analysis: Same Score, Opposite Tools
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
Precision, Recall, and F1 for Static Analysis: Same Score, Opposite Tools
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
8 min read
Proxy Metrics: The Number You Optimize Is Not the Thing You Want
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
Proxy Metrics: The Number You Optimize Is Not the Thing You Want
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
8 min read
Sample Size and Statistical Power: What a Small Sample Can and Cannot Tell You
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
Sample Size and Statistical Power: What a Small Sample Can and Cannot Tell You
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
8 min read
Static Analysis vs. SAST vs. Linting: The Taxonomy That Matters for Security Teams
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
Static Analysis vs. SAST vs. Linting: The Taxonomy That Matters for Security Teams
#
security
#
devsecops
#
node
#
javascript
Comments
Add Comment
8 min read
Valid vs. Reliable Metrics: Consistent Numbers Can Still Be Wrong
Ofri Peretz
Ofri Peretz
Ofri Peretz
Follow
Jul 19
Valid vs. Reliable Metrics: Consistent Numbers Can Still Be Wrong
#
security
#
devsecops
#
node
#
javascript
1
reaction
Comments
Add Comment
7 min read
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account