DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Twelve Trust Boundaries: A Field Guide to Supply-Chain Defense After axios@1.14.1

Twelve Trust Boundaries: A Field Guide to Supply-Chain Defense After axios@1.14.1

1
Comments
29 min read
I built an AI agent that does OSINT investigations from your terminal

I built an AI agent that does OSINT investigations from your terminal

Comments
3 min read
Approve Once, Exploit Forever: The Trust Persistence Vulnerability Vendors Will Not Fix

Approve Once, Exploit Forever: The Trust Persistence Vulnerability Vendors Will Not Fix

1
Comments
6 min read
The MCP Attack That Hides in a Tool Description

The MCP Attack That Hides in a Tool Description

Comments 1
4 min read
Open-Sourcing a Blog Without Open-Sourcing Your Drafts

Open-Sourcing a Blog Without Open-Sourcing Your Drafts

Comments
5 min read
What Is the Difference Between Functional, Performance, and Security API Testing

What Is the Difference Between Functional, Performance, and Security API Testing

1
Comments
10 min read
Why 80% of Kafka Clusters Would Fail a SOC 2 Audit Tomorrow

Why 80% of Kafka Clusters Would Fail a SOC 2 Audit Tomorrow

Comments
4 min read
GitHub's code_scanning_upload Rate Limit Field Goes Away May 19 — Your SARIF Pre-Flight Check Is About to KeyError

GitHub's code_scanning_upload Rate Limit Field Goes Away May 19 — Your SARIF Pre-Flight Check Is About to KeyError

Comments
6 min read
Four Security Problems That Don't Need a Scanner

Four Security Problems That Don't Need a Scanner

Comments
9 min read
Pre-fork due diligence for OSS contributors

Pre-fork due diligence for OSS contributors

1
Comments
7 min read
Your VPN Might Be Leaking Your Real IP Through WebRTC

Your VPN Might Be Leaking Your Real IP Through WebRTC

Comments
7 min read
Stop Trusting Every JWT: How I Handle OIDC Claims in My Go Gateway

Stop Trusting Every JWT: How I Handle OIDC Claims in My Go Gateway

4
Comments
5 min read
Why Your Next.js SaaS Needs a Production AI Agent Guardrail Architecture, Not Just a Prompt

Why Your Next.js SaaS Needs a Production AI Agent Guardrail Architecture, Not Just a Prompt

Comments
4 min read
Lock your dependency to prevent supply-chain attacks

Lock your dependency to prevent supply-chain attacks

Comments
3 min read
Why Uploading Your Bank Statement to Random PDF Compressors Is a Financial Privacy Risk

Why Uploading Your Bank Statement to Random PDF Compressors Is a Financial Privacy Risk

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.