Urgent.News

What's breaking now, across thousands of outlets.

Tech

The AppSec prompt I created found 1 gap in 174 routes.

Pessoal, eu quase abri uma issue com uma lista. O modelo tinha devolvido XSS, CORS, CSP, um SVG suspeito. Eu sentia que tinha trabalhado. Aí parei e perguntei a pergunta chata: disto aqui, o que eu mandaria pra um mantenedor sem vergonha? A conta virou quando eu parei de pedir "audita meu código" e passei a escrever o contrato antes de abrir o repo. Padrão externo, invariante falsificável,…

Translated from Portuguese Read in Portuguese

A developer has been testing an AI model to audit code for security vulnerabilities. The model was initially producing inconsistent results, but the developer created a set of guidelines, or a "contract", to control the model's behavior. This contract includes a standard external pattern, an invariant that can be verified, and specific reporting requirements.

Using this contract, the developer was able to successfully identify vulnerabilities in six open-source repositories over the course of two days. The developer found issues such as missing authorization checks and potential XSS vulnerabilities. The contract helped to ensure that the model's findings were accurate and relevant.

Written by urgent.news from Dev.to's report — not a translation of it. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Tuesday 1 September →