DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Every CISO Needs an AIBOM in 2026 — Here's What Vendors Get Wrong

Every CISO Needs an AIBOM in 2026 — Here's What Vendors Get Wrong

Comments
8 min read
Why the Execution Layer Can't Solve AI Agent Trust (And What's Missing)

Why the Execution Layer Can't Solve AI Agent Trust (And What's Missing)

Comments
5 min read
npm Is on Fire: Why the Architecture Is the Product

npm Is on Fire: Why the Architecture Is the Product

Comments
10 min read
I Started With a Blocklist. That Was the Wrong Instinct and VaultPay Taught Me Why.

I Started With a Blocklist. That Was the Wrong Instinct and VaultPay Taught Me Why.

1
Comments
7 min read
A pragmatic threat model for AI coding agents, with controls you can ship today

A pragmatic threat model for AI coding agents, with controls you can ship today

Comments
6 min read
When AI Agents Go Rogue: Preventing Destructive Automation

When AI Agents Go Rogue: Preventing Destructive Automation

Comments
5 min read
Security Patch on My Own VPS: Hours Stolen from a Client Project

Security Patch on My Own VPS: Hours Stolen from a Client Project

Comments
2 min read
The 5 API Attacks That Hit Production in 2024

The 5 API Attacks That Hit Production in 2024

Comments
6 min read
Why I built Akmon, the AI coding agent for regulated engineering

Why I built Akmon, the AI coding agent for regulated engineering

Comments
6 min read
Observability and evidence in AI coding workflows: two log streams, two masters

Observability and evidence in AI coding workflows: two log streams, two masters

Comments
5 min read
AI coding compliance for 2026: a working checklist for ISO 42001, the EU AI Act, SOC 2, and tool qualification

AI coding compliance for 2026: a working checklist for ISO 42001, the EU AI Act, SOC 2, and tool qualification

Comments
6 min read
The trust pipeline: three commands to run before merging an AI-assisted change

The trust pipeline: three commands to run before merging an AI-assisted change

Comments
5 min read
Sanitizing AI coding sessions before external review: the redaction workflow that ships

Sanitizing AI coding sessions before external review: the redaction workflow that ships

Comments
4 min read
Your AI Agents Are Probably Accessing Data They Shouldn't

Your AI Agents Are Probably Accessing Data They Shouldn't

Comments
3 min read
Why the Variable Name Is the Most Important Feature in Secrets Detection

Why the Variable Name Is the Most Important Feature in Secrets Detection

Comments
8 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.