DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Gitlfow Secrets Management

Gitlfow Secrets Management

Comments
3 min read
How secrets work in multi-service OSC stacks (and one mistake we helped a customer avoid)

How secrets work in multi-service OSC stacks (and one mistake we helped a customer avoid)

Comments
4 min read
Why I Stopped Letting Claude Shell Out for Security Scans

Why I Stopped Letting Claude Shell Out for Security Scans

Comments 1
10 min read
OWASP Top 10 | notes may 11 2026

OWASP Top 10 | notes may 11 2026

Comments
4 min read
Bulletproof React: Strict Content Security Policies in Next.js 🛡️

Bulletproof React: Strict Content Security Policies in Next.js 🛡️

1
Comments
3 min read
Ollama Out-of-Bounds Read, Docker UFW Bypass, & EagleSpy RAT Analysis

Ollama Out-of-Bounds Read, Docker UFW Bypass, & EagleSpy RAT Analysis

Comments
4 min read
Deep inside the COM: Reading Windows ROT Without Asking Permission. Detective story

Deep inside the COM: Reading Windows ROT Without Asking Permission. Detective story

Comments
4 min read
LangChain ChromaDB Metadata Priority Injection — RAG Poisoning Vulnerability

LangChain ChromaDB Metadata Priority Injection — RAG Poisoning Vulnerability

Comments
1 min read
Pipelock Agent Egress Control: the missing CI primitive for AI agents

Pipelock Agent Egress Control: the missing CI primitive for AI agents

Comments
3 min read
Why I Built an ML-Powered Secrets Detector Instead of Just Using Regex

Why I Built an ML-Powered Secrets Detector Instead of Just Using Regex

Comments
8 min read
I Built My Own Config Format for Node.js That Separates Server and Client Secrets

I Built My Own Config Format for Node.js That Separates Server and Client Secrets

1
Comments 2
5 min read
I built 14 VS Code extensions to fix the workflows developers quietly suffer through

I built 14 VS Code extensions to fix the workflows developers quietly suffer through

Comments
2 min read
Why Prompt Injection Is an Architectural Problem - Not Just a Security Bug

Why Prompt Injection Is an Architectural Problem - Not Just a Security Bug

Comments
11 min read
Surviving Byzantine Fire: Empirical Proof of a Deterministic Web3 AI Architecture

Surviving Byzantine Fire: Empirical Proof of a Deterministic Web3 AI Architecture

1
Comments
4 min read
"Secure Financial Workflows: Key Lessons from the Trenches"

"Secure Financial Workflows: Key Lessons from the Trenches"

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.