DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
The Honest Ceiling of Offline License Verification

The Honest Ceiling of Offline License Verification

Comments
5 min read
We checked every single-typo of the 30 most popular npm and PyPI packages. Here's what's actually registered.

We checked every single-typo of the 30 most popular npm and PyPI packages. Here's what's actually registered.

Comments
5 min read
Claude Code permissions: how allow, ask, and deny actually compose

Claude Code permissions: how allow, ask, and deny actually compose

Comments
8 min read
I Rotated 4 Secrets in 6 Days. 3 of Them Broke Production.

I Rotated 4 Secrets in 6 Days. 3 of Them Broke Production.

1
Comments
6 min read
TruffleHog vs Gitleaks vs GitHub Secret Scanning: Why Most CI Scanners Fail (2026)

TruffleHog vs Gitleaks vs GitHub Secret Scanning: Why Most CI Scanners Fail (2026)

Comments
7 min read
Your Sentry DSN Is a GitHub Variable, Not a Secret

Your Sentry DSN Is a GitHub Variable, Not a Secret

Comments
4 min read
Measuring China's Company Registry from the Outside: A Technical Writeup

Measuring China's Company Registry from the Outside: A Technical Writeup

Comments
4 min read
Why XopProtector Is the Best Android App Protection Tool I’ve Used

Why XopProtector Is the Best Android App Protection Tool I’ve Used

Comments
5 min read
Your AI Agent’s Chain of Thought Is Not an Audit Log

Your AI Agent’s Chain of Thought Is Not an Audit Log

5
Comments 2
9 min read
Custom ID-JAG on PingFederate, Part 3: Managing the Integration with Terraform

Custom ID-JAG on PingFederate, Part 3: Managing the Integration with Terraform

Comments
4 min read
Custom ID-JAG on PingFederate, Part 2: Building the Generator and Handling Runtime Constraints

Custom ID-JAG on PingFederate, Part 2: Building the Generator and Handling Runtime Constraints

Comments
4 min read
Custom ID-JAG on PingFederate, Part 4: Testing Live Issuance Without Overclaiming

Custom ID-JAG on PingFederate, Part 4: Testing Live Issuance Without Overclaiming

Comments
4 min read
Custom ID-JAG on PingFederate, Part 1: Can PingFederate 12.3.3 Issue an ID-JAG?

Custom ID-JAG on PingFederate, Part 1: Can PingFederate 12.3.3 Issue an ID-JAG?

Comments
4 min read
TypeScript SDK for autonomous Solidity security auditing — 7 breach scenarios, LangChain.js + Vercel AI SDK integration

TypeScript SDK for autonomous Solidity security auditing — 7 breach scenarios, LangChain.js + Vercel AI SDK integration

Comments
3 min read
Mask, Hash, Tokenize, or Encrypt? Choosing the Right PII Protection for Your Pipeline

Mask, Hash, Tokenize, or Encrypt? Choosing the Right PII Protection for Your Pipeline

Comments
6 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.