DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Why Strict "Zero Trust" Breaks Secret Management (And How We Built a Zero-Persistence Vault Instead)

Why Strict "Zero Trust" Breaks Secret Management (And How We Built a Zero-Persistence Vault Instead)

4
Comments
3 min read
78% of Production AI Systems Score F on Prompt Defense — Data from 1,646 Leaked System Prompts

78% of Production AI Systems Score F on Prompt Defense — Data from 1,646 Leaked System Prompts

Comments
7 min read
I launched a free software end-of-life tracker — here's why it matters more than most people realize

I launched a free software end-of-life tracker — here's why it matters more than most people realize

Comments
2 min read
Essential SSL Certificate Validity Facts to Protect Sites

Essential SSL Certificate Validity Facts to Protect Sites

Comments
7 min read
npm Publish Without Tokens

npm Publish Without Tokens

Comments
3 min read
Checkov's OIDC Bug: Why CKV_AWS_358 Misses 80% of Misconfigurations

Checkov's OIDC Bug: Why CKV_AWS_358 Misses 80% of Misconfigurations

Comments
3 min read
Passwordless Login Needs Less Than Passkeys

Passwordless Login Needs Less Than Passkeys

Comments
6 min read
The Compliance Trap: Why 90% of Security Scans are Technically Correct but Strategically Worthless

The Compliance Trap: Why 90% of Security Scans are Technically Correct but Strategically Worthless

Comments
7 min read
Why I built attack-chain correlation on top of Semgrep and Joern

Why I built attack-chain correlation on top of Semgrep and Joern

Comments
3 min read
Securing Package Manager Postinstall Scripts: Mitigating Access to Sensitive User Data During Installation

Securing Package Manager Postinstall Scripts: Mitigating Access to Sensitive User Data During Installation

Comments
8 min read
Delete the Vercel Claude Code Plugin. Here's Why I Did.

Delete the Vercel Claude Code Plugin. Here's Why I Did.

Comments
5 min read
When Your Security Scanner Becomes the Weapon: Lessons from the Trivy Supply Chain Attack

When Your Security Scanner Becomes the Weapon: Lessons from the Trivy Supply Chain Attack

1
Comments
2 min read
I Built a Gate That Blocks Vulnerable AI-Generated Code Before It Merges

I Built a Gate That Blocks Vulnerable AI-Generated Code Before It Merges

Comments 3
3 min read
Beyond the Token: Securing Your Localhost with Biometric Passkeys

Beyond the Token: Securing Your Localhost with Biometric Passkeys

Comments
9 min read
I Added Minimum GitHub Security Settings to My OSS Repositories and Created a Setup Guide

I Added Minimum GitHub Security Settings to My OSS Repositories and Created a Setup Guide

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.