DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Default-Deny Policies: Why Your AI Agent Can't Touch What You Don't Allow

Default-Deny Policies: Why Your AI Agent Can't Touch What You Don't Allow

Comments
5 min read
Building a Cost-Effective Windows Code Signing Pipeline with Sectigo, Google Cloud KMS, and GitHub Actions

Building a Cost-Effective Windows Code Signing Pipeline with Sectigo, Google Cloud KMS, and GitHub Actions

Comments
9 min read
Vercel’s "Agentic" Shift: Is Your Proprietary Code Now Training AI?

Vercel’s "Agentic" Shift: Is Your Proprietary Code Now Training AI?

8
Comments 1
2 min read
Your LangChain Agent Has No Security. Neither Does CrewAI, OpenAI, or 6 Others.

Your LangChain Agent Has No Security. Neither Does CrewAI, OpenAI, or 6 Others.

2
Comments
4 min read
We Built a Python SDK Where the Credentials Never Enter Your Code

We Built a Python SDK Where the Credentials Never Enter Your Code

6
Comments
3 min read
I Spent 3 Months Solving a Security Gap Nobody Talks About: LLM Artifact Integrity

I Spent 3 Months Solving a Security Gap Nobody Talks About: LLM Artifact Integrity

Comments
5 min read
The API Key Cursor Just Wrote Into Your Code Is Already in Git History

The API Key Cursor Just Wrote Into Your Code Is Already in Git History

Comments 1
3 min read
135K AI Agents Exposed: I Built an Open-Source Host Guardian to Fix It

135K AI Agents Exposed: I Built an Open-Source Host Guardian to Fix It

Comments
3 min read
AI-Generated Code Risks: Addressing Security Threats from Vulnerable Self-Hosted Projects

AI-Generated Code Risks: Addressing Security Threats from Vulnerable Self-Hosted Projects

1
Comments
8 min read
When Projects Fail: Why Companies Should Treat Open Source as Infrastructure

When Projects Fail: Why Companies Should Treat Open Source as Infrastructure

60
Comments 6
4 min read
The Day Facebook Went Offline: A Case Study in Centralization

The Day Facebook Went Offline: A Case Study in Centralization

Comments
3 min read
The Missing Guide to Windows Code Signing in CI/CD (GitHub Actions Edition)

The Missing Guide to Windows Code Signing in CI/CD (GitHub Actions Edition)

Comments
5 min read
The $5,000 Typo: How Beginners Are Handing Their API Keys to Hackers

The $5,000 Typo: How Beginners Are Handing Their API Keys to Hackers

2
Comments
4 min read
$599K Lost to Address Poisoning: A Technical Post-Mortem on UI/UX Vulnerabilities

$599K Lost to Address Poisoning: A Technical Post-Mortem on UI/UX Vulnerabilities

Comments
3 min read
Your DEV Credentials Shouldn't Be Able to Sink PROD

Your DEV Credentials Shouldn't Be Able to Sink PROD

Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.