DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Your GitHub profile shows your follower count. It also shows attackers your whole attack surface.

Pins action versions to SHAs for safety

Your GitHub profile shows your follower count. It also shows attackers your whole attack surface.

24
Picked as gem Comments 6
4 min read
I Built a Privacy Scanner With Zero Dependencies —SafeSearch

I Built a Privacy Scanner With Zero Dependencies —SafeSearch

1
Comments
3 min read
A .git Folder Is Not Data: Inside the Forgejo Template RCE, and How to Audit Your Own Instance

A .git Folder Is Not Data: Inside the Forgejo Template RCE, and How to Audit Your Own Instance

3
Comments 1
7 min read
The One Line of Code That Stops Rainbow Table Attacks

The One Line of Code That Stops Rainbow Table Attacks

Comments
3 min read
Go Server-Rendered Login Controls: Auditable Session Verification Through Password Recovery

Go Server-Rendered Login Controls: Auditable Session Verification Through Password Recovery

Comments
6 min read
How to Tell If Your Windows PC Has Been Hacked (11 Warning Signs)

How to Tell If Your Windows PC Has Been Hacked (11 Warning Signs)

Comments
7 min read
When AI-generated code outruns the reader, the fix is tooling, not a stronger reviewer

When AI-generated code outruns the reader, the fix is tooling, not a stronger reviewer

Comments
5 min read
What Was on This Machine? Answering the Blast Radius Question After a Laptop Compromise

What Was on This Machine? Answering the Blast Radius Question After a Laptop Compromise

Comments
10 min read
Valid provenance is not valid code: a supply-chain worm shipped with a valid SLSA attestation

Valid provenance is not valid code: a supply-chain worm shipped with a valid SLSA attestation

Comments
5 min read
CrackMe Level 6

CrackMe Level 6

Comments
14 min read
Your AI Coding Agent Can Be Attacked by the Repository It Opens

Automatic workspace scans trigger risks instantly

Your AI Coding Agent Can Be Attacked by the Repository It Opens

69
Picked as gem Comments 66
5 min read
HTTP Security Headers Explained: A Practical Guide for Developers

HTTP Security Headers Explained: A Practical Guide for Developers

2
Comments
9 min read
F*ck CTF: Can a Multi-Agent LLM really play Capture The Flag?

F*ck CTF: Can a Multi-Agent LLM really play Capture The Flag?

Comments
2 min read
A security checklist my coding agent has to run

A security checklist my coding agent has to run

Comments 1
7 min read
An AI Agent Found Admin Access to a $13B Startup in 25 Minutes. Here's the Free Tool It Used, and the Docker Mistake That Made It Possible

An AI Agent Found Admin Access to a $13B Startup in 25 Minutes. Here's the Free Tool It Used, and the Docker Mistake That Made It Possible

1
Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.