DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The dog that didn't bark: finding security holes in what's missing, not what's misconfigured

The dog that didn't bark: finding security holes in what's missing, not what's misconfigured

Comments
7 min read
Fake AI Installers: When "Installing Claude" Turns Into Running Malware

Fake AI Installers: When "Installing Claude" Turns Into Running Malware

1
Comments
9 min read
DevSecOps for Git: Security Starts at Commit Time

DevSecOps for Git: Security Starts at Commit Time

1
Comments
3 min read
Agents can pay. They can't prove they were supposed to.

Agents can pay. They can't prove they were supposed to.

Comments
3 min read
Short-Lived Credentials in Agentic Systems: A Practical Trade-off Guide

Short-Lived Credentials in Agentic Systems: A Practical Trade-off Guide

1
Comments 1
11 min read
JWT Authentication — 7 Common Mistakes Developers Make (And How to Fix Them)

JWT Authentication — 7 Common Mistakes Developers Make (And How to Fix Them)

1
Comments
3 min read
ML-KEM: Future of Key Encapsulation

ML-KEM: Future of Key Encapsulation

Comments
12 min read
5 Critical Security Mistakes PHP Beginners Make in 2026 (And How to Fix Them)

5 Critical Security Mistakes PHP Beginners Make in 2026 (And How to Fix Them)

Comments
2 min read
Reproducible Builds: The Only Way to Verify Your Software Wasn't Tampered With

Reproducible Builds: The Only Way to Verify Your Software Wasn't Tampered With

Comments
5 min read
Before you connect AI to PostgreSQL through MCP, run this checklist

Before you connect AI to PostgreSQL through MCP, run this checklist

1
Comments
2 min read
Free Scanner Page Concept — /check

Free Scanner Page Concept — /check

Comments
4 min read
Why Fixed Container Image Versions Matter: Lessons from the Trivy Supply Chain Attack

Why Fixed Container Image Versions Matter: Lessons from the Trivy Supply Chain Attack

1
Comments
15 min read
DaloyJS Is the Latest Modern Enterprise TypeScript Framework, and It Has Your Back on Security

DaloyJS Is the Latest Modern Enterprise TypeScript Framework, and It Has Your Back on Security

Comments
6 min read
5 things missing from your AI agent audit logs (and how we fixed them in Signet v0.10)

5 things missing from your AI agent audit logs (and how we fixed them in Signet v0.10)

Comments
7 min read
Making Maven Builds Security-Aware: AppSec Checks Without CI/CD Drift

Making Maven Builds Security-Aware: AppSec Checks Without CI/CD Drift

1
Comments
9 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.