DEV Community

#devsecops

Integrating security practices into the DevOps lifecycle.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Where does Secure by Design End? A 3D/4D Model

Where does Secure by Design End? A 3D/4D Model

Comments
3 min read
Why Cursor Generates Prototype Pollution in Deep Merge Functions

Why Cursor Generates Prototype Pollution in Deep Merge Functions

Comments
4 min read
Why Cursor Keeps Using Math.random() for Session Tokens (CWE-330)

Why Cursor Keeps Using Math.random() for Session Tokens (CWE-330)

Comments
2 min read
Never Let the Model Pick the Tenant ID: Securing an LLM Agent in Go

Never Let the Model Pick the Tenant ID: Securing an LLM Agent in Go

1
Comments
10 min read
L3: I built continuous runtime monitoring because certification is point-in-time, attacks are runtime

L3: I built continuous runtime monitoring because certification is point-in-time, attacks are runtime

Comments 4
2 min read
Why Cursor Keeps Generating Wildcard CORS Headers in Your API

Why Cursor Keeps Generating Wildcard CORS Headers in Your API

Comments 1
4 min read
Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later

Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later

Comments
2 min read
Ranking vs. Measuring: What a Leaderboard Throws Away

Ranking vs. Measuring: What a Leaderboard Throws Away

Comments
8 min read
Sample Size and Statistical Power: What a Small Sample Can and Cannot Tell You

Sample Size and Statistical Power: What a Small Sample Can and Cannot Tell You

Comments
8 min read
OWASP Top 10, Explained: An Address System, Not a Severity Scale

OWASP Top 10, Explained: An Address System, Not a Severity Scale

Comments
8 min read
Reproducibility vs Replicability: Why Benchmark Numbers Need Both

Reproducibility vs Replicability: Why Benchmark Numbers Need Both

Comments
7 min read
Static Analysis vs. SAST vs. Linting: The Taxonomy That Matters for Security Teams

Static Analysis vs. SAST vs. Linting: The Taxonomy That Matters for Security Teams

Comments
8 min read
Proxy Metrics: The Number You Optimize Is Not the Thing You Want

Proxy Metrics: The Number You Optimize Is Not the Thing You Want

Comments
8 min read
Fixtures First, Rules Second: How to Design a Ground-Truth Corpus

Fixtures First, Rules Second: How to Design a Ground-Truth Corpus

1
Comments
9 min read
Statistical Significance and p-Values: What p > 0.05 Actually Means

Statistical Significance and p-Values: What p > 0.05 Actually Means

Comments
8 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.