DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
We shipped OSV + Trivy inside GitHub/GitLab PR reviews—no extra CI YAML

We shipped OSV + Trivy inside GitHub/GitLab PR reviews—no extra CI YAML

Comments
1 min read
The Habit That Was The Bug

The Habit That Was The Bug

Comments
9 min read
Test a DNS Leak in 2 Minutes: Complete Methodology + Per-OS Fixes (2026)

Test a DNS Leak in 2 Minutes: Complete Methodology + Per-OS Fixes (2026)

Comments
5 min read
MP3 - SQLi, XSS, and CSRF WriteUp

MP3 - SQLi, XSS, and CSRF WriteUp

Comments
7 min read
Codex Got Blocked by macOS. I Reinstalled Instead of Bypassing It.

Codex Got Blocked by macOS. I Reinstalled Instead of Bypassing It.

4
Comments
3 min read
Your AI agent has a master key to everything. Here's why that's a problem.

Your AI agent has a master key to everything. Here's why that's a problem.

Comments
2 min read
Reconnaissance Is Not Hacking (And That's Why It's So Powerful)

Reconnaissance Is Not Hacking (And That's Why It's So Powerful)

Comments
2 min read
What Is Steganography? How It Works, Types, and Why It Matters

What Is Steganography? How It Works, Types, and Why It Matters

5
Comments 1
4 min read
Weekly Dev Log 2026-W11

Managing feature creep with AI and Notion

Weekly Dev Log 2026-W11

14
Comments 11
4 min read
Anthropic just published a jailbreak severity scale. Here's what it means.

Anthropic just published a jailbreak severity scale. Here's what it means.

Comments
3 min read
I built an offline threat-hunting CLI in python because spinning up a SIEM for one log file is overkill

I built an offline threat-hunting CLI in python because spinning up a SIEM for one log file is overkill

1
Comments 2
4 min read
How to Decode JWT Tokens Without a Backend

How to Decode JWT Tokens Without a Backend

1
Comments 4
3 min read
Why `async def` without `await` is the #1 vibe-coding bug (and how to catch it)

Why `async def` without `await` is the #1 vibe-coding bug (and how to catch it)

1
Comments
2 min read
Making a local-first tool's CSV export audit-ready (and why charts don't belong in a CSV)

Making a local-first tool's CSV export audit-ready (and why charts don't belong in a CSV)

1
Comments
3 min read
SaaS Security Best Practices: Auth, Authorization, and Data Protection

SaaS Security Best Practices: Auth, Authorization, and Data Protection

1
Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.