DEV Community

#devsecops

Integrating security practices into the DevOps lifecycle.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026

Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026

Comments
6 min read
Confronting Vault Sprawl And The Risks It Brings

Confronting Vault Sprawl And The Risks It Brings

Comments
8 min read
Where does Secure by Design End? A 3D/4D Model

Where does Secure by Design End? A 3D/4D Model

Comments
3 min read
Why Cursor Keeps Using Math.random() for Session Tokens (CWE-330)

Why Cursor Keeps Using Math.random() for Session Tokens (CWE-330)

Comments
2 min read
Never Let the Model Pick the Tenant ID: Securing an LLM Agent in Go

Never Let the Model Pick the Tenant ID: Securing an LLM Agent in Go

1
Comments
10 min read
Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later

Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later

Comments
2 min read
Responding to feedback: runtime trust, CA key rotation, and the canonicalization bug

Responding to feedback: runtime trust, CA key rotation, and the canonicalization bug

1
Comments 3
4 min read
Software Composition Analysis (SCA): The 2026 Complete Guide

Software Composition Analysis (SCA): The 2026 Complete Guide

Comments
7 min read
Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers

Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers

Comments
3 min read
Hardcoded Secrets: Why AI Code Fails Your First SOC 2 Audit

Hardcoded Secrets: Why AI Code Fails Your First SOC 2 Audit

Comments 1
3 min read
I caught a trojan in my MCP marketplace. Here's the 8-layer defense I built.

I caught a trojan in my MCP marketplace. Here's the 8-layer defense I built.

Comments
4 min read
Cursor Keeps Skipping Rate Limits on Login Routes (CWE-307)

Cursor Keeps Skipping Rate Limits on Login Routes (CWE-307)

Comments
3 min read
Inside the Chain: the tj-actions compromise wasn't one incident — it was three

Inside the Chain: the tj-actions compromise wasn't one incident — it was three

Comments
2 min read
SafeWeave vs Snyk vs Checkmarx: Cheapest AI Code Scanner

SafeWeave vs Snyk vs Checkmarx: Cheapest AI Code Scanner

Comments
4 min read
MCP for AWS Security Engineers: Build a Read-Only Security Hub Triage Agent

MCP for AWS Security Engineers: Build a Read-Only Security Hub Triage Agent

1
Comments
20 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.