close

DEV Community

#devsecops

Integrating security practices into the DevOps lifecycle.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
drainscan vs gitleaks vs trufflehog: Why Web3 Needs Its Own Secret Scanner (2026 Benchmark)

drainscan vs gitleaks vs trufflehog: Why Web3 Needs Its Own Secret Scanner (2026 Benchmark)

Comments
4 min read
How to Measure Time to Revoke for Exposed Credentials

How to Measure Time to Revoke for Exposed Credentials

Comments
5 min read
Building a Read-Only Cloudflare Worker AI Security Console

Building a Read-Only Cloudflare Worker AI Security Console

1
Comments
8 min read
The Perimeter Moved to the Laptop: From Network, to Identity, to the Developer Endpoint

The Perimeter Moved to the Laptop: From Network, to Identity, to the Developer Endpoint

Comments
8 min read
AWS Continuum: AI-Powered Security at Machine Speed — What It Is, How It Works, and Why It Changes AppSec

AWS Continuum: AI-Powered Security at Machine Speed — What It Is, How It Works, and Why It Changes AppSec

Comments
6 min read
Popular projects SHA-pin GitHub Actions 67.6% of the time — but Docker base images only 7.6%

Popular projects SHA-pin GitHub Actions 67.6% of the time — but Docker base images only 7.6%

Comments
3 min read
What CISA Got Right After Its GitHub Leak: Lessons Every Organization Should Copy

What CISA Got Right After Its GitHub Leak: Lessons Every Organization Should Copy

Comments
4 min read
Vulnerability advisories grew 2.3x-6.6x in 5 years; open-source tool count stayed flat

Vulnerability advisories grew 2.3x-6.6x in 5 years; open-source tool count stayed flat

Comments
4 min read
Slopsquatting: Why Cursor Recommends Packages Attackers Own

Slopsquatting: Why Cursor Recommends Packages Attackers Own

1
Comments
4 min read
Architecting a Custom Purple Team Infrastructure Scanner in Go.

Architecting a Custom Purple Team Infrastructure Scanner in Go.

Comments
3 min read
Trivy en CI/CD: bloqueando imágenes Docker vulnerables antes del deploy

Trivy en CI/CD: bloqueando imágenes Docker vulnerables antes del deploy

Comments
6 min read
7 Problems That Start Hurting When Your Engineering Team Scales

7 Problems That Start Hurting When Your Engineering Team Scales

Comments
2 min read
🛡️ Vulnerability Math: CVE vs. CVSS vs. EPSS

🛡️ Vulnerability Math: CVE vs. CVSS vs. EPSS

1
Comments
1 min read
Can Copilot Fix Its Own Security Findings? Testing GitHub Agentic Autofix

Can Copilot Fix Its Own Security Findings? Testing GitHub Agentic Autofix

1
Comments
10 min read
The Command Injection Fix Cursor Writes Still Runs Code (CWE-78)

The Command Injection Fix Cursor Writes Still Runs Code (CWE-78)

1
Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.