DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The dog that didn't bark: finding security holes in what's missing, not what's misconfigured

The dog that didn't bark: finding security holes in what's missing, not what's misconfigured

Comments
7 min read
Vulnerability Scan vs Penetration Test: What Small Teams Actually Need

Vulnerability Scan vs Penetration Test: What Small Teams Actually Need

Comments
7 min read
Agents can pay. They can't prove they were supposed to.

Agents can pay. They can't prove they were supposed to.

Comments
3 min read
Short-Lived Credentials in Agentic Systems: A Practical Trade-off Guide

Short-Lived Credentials in Agentic Systems: A Practical Trade-off Guide

1
Comments 1
11 min read
JWT Authentication — 7 Common Mistakes Developers Make (And How to Fix Them)

JWT Authentication — 7 Common Mistakes Developers Make (And How to Fix Them)

1
Comments
3 min read
ML-KEM: Future of Key Encapsulation

ML-KEM: Future of Key Encapsulation

Comments
12 min read
5 Critical Security Mistakes PHP Beginners Make in 2026 (And How to Fix Them)

5 Critical Security Mistakes PHP Beginners Make in 2026 (And How to Fix Them)

Comments
2 min read
Reproducible Builds: The Only Way to Verify Your Software Wasn't Tampered With

Reproducible Builds: The Only Way to Verify Your Software Wasn't Tampered With

Comments
5 min read
Before you connect AI to PostgreSQL through MCP, run this checklist

Before you connect AI to PostgreSQL through MCP, run this checklist

1
Comments
2 min read
Free Scanner Page Concept — /check

Free Scanner Page Concept — /check

Comments
4 min read
Why Fixed Container Image Versions Matter: Lessons from the Trivy Supply Chain Attack

Why Fixed Container Image Versions Matter: Lessons from the Trivy Supply Chain Attack

1
Comments
15 min read
5 things missing from your AI agent audit logs (and how we fixed them in Signet v0.10)

5 things missing from your AI agent audit logs (and how we fixed them in Signet v0.10)

Comments
7 min read
Behavioral Trust Without Surveillance Infrastructure

Behavioral Trust Without Surveillance Infrastructure

Comments
5 min read
Stop Copy-Pasting Security YAML: A Gradle Build Layer for Java AppSec

Stop Copy-Pasting Security YAML: A Gradle Build Layer for Java AppSec

1
Comments
9 min read
Don't Let Secrets Become Commits: Bringing Gitleaks Into the Developer Workflow

Don't Let Secrets Become Commits: Bringing Gitleaks Into the Developer Workflow

1
Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.