DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Checkov's OIDC Bug: Why CKV_AWS_358 Misses 80% of Misconfigurations

Checkov's OIDC Bug: Why CKV_AWS_358 Misses 80% of Misconfigurations

Comments
3 min read
Passwordless Login Needs Less Than Passkeys

Passwordless Login Needs Less Than Passkeys

Comments
6 min read
npm Publish Without Tokens

npm Publish Without Tokens

Comments
3 min read
The Compliance Trap: Why 90% of Security Scans are Technically Correct but Strategically Worthless

The Compliance Trap: Why 90% of Security Scans are Technically Correct but Strategically Worthless

Comments
7 min read
Why I built attack-chain correlation on top of Semgrep and Joern

Why I built attack-chain correlation on top of Semgrep and Joern

Comments
3 min read
Why AI Agent Authorization Is Still Unsolved in 2026

Why AI Agent Authorization Is Still Unsolved in 2026

Comments
7 min read
Delete the Vercel Claude Code Plugin. Here's Why I Did.

Delete the Vercel Claude Code Plugin. Here's Why I Did.

Comments
5 min read
Securing Package Manager Postinstall Scripts: Mitigating Access to Sensitive User Data During Installation

Securing Package Manager Postinstall Scripts: Mitigating Access to Sensitive User Data During Installation

Comments
8 min read
When Your Security Scanner Becomes the Weapon: Lessons from the Trivy Supply Chain Attack

When Your Security Scanner Becomes the Weapon: Lessons from the Trivy Supply Chain Attack

1
Comments
2 min read
I Built a Gate That Blocks Vulnerable AI-Generated Code Before It Merges

I Built a Gate That Blocks Vulnerable AI-Generated Code Before It Merges

Comments 3
3 min read
Beyond the Token: Securing Your Localhost with Biometric Passkeys

Beyond the Token: Securing Your Localhost with Biometric Passkeys

Comments
9 min read
I Added Minimum GitHub Security Settings to My OSS Repositories and Created a Setup Guide

I Added Minimum GitHub Security Settings to My OSS Repositories and Created a Setup Guide

Comments
4 min read
How to Secure AI Agents in Production: What MCP Gets Right (and What It Doesn’t)

The lethal trifecta of agent risk

How to Secure AI Agents in Production: What MCP Gets Right (and What It Doesn’t)

81
Comments 25
8 min read
Every Compliance Framework Requires Key Rotation. No Platform Tells You When.

Every Compliance Framework Requires Key Rotation. No Platform Tells You When.

Comments
5 min read
I Was a Blockchain Developer for Years. Then I Tried to Add KYC to a Web3 App.

I Was a Blockchain Developer for Years. Then I Tried to Add KYC to a Web3 App.

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.