Urgent.News

What's breaking now, across thousands of outlets.

Tech

We already had a security scanner

The bigger question was: What happens if it remembers? While building SecurePush for HackWith Hyderabad 3.0, we started with a pretty straightforward idea. A developer runs git push . Before the code reaches the remote repository, SecurePush checks the changes for security problems. If something is wrong, it explains the issue and suggests a fix. The developer decides whether to accept it. The…

SecurePush is a security scanner that checks for security issues before code is pushed to a remote repository. Initially, SecurePush only checked for security problems without any memory of past reviews. However, the developers wanted to add memory to the system to remember security issues and their outcomes.

The idea was to create a feature called Hindsight, which would remember key details from previous security reviews, such as the security issue found, the file affected, the severity of the issue, the suggested fix, and whether the developer accepted or rejected the fix. This historical context would be used in subsequent reviews to provide valuable context to developers.

For example, if SecurePush finds a hardcoded credential in a file and the developer accepts the suggested fix, the memory would record this interaction. During the next review, if a developer makes a similar change, Hindsight can recall the previous interaction and provide relevant context to the security review. This helps the security review process be informed by the repository's history, rather than starting from scratch each time.

To make the memory visible and understandable, SecurePush added a Memory section. When SecurePush remembers something, developers can see what it remembers, such as the security issue, the file involved, the developer's decision, the remediation taken, and the result of the verification process.

The implementation also ensured that sensitive information, like actual API keys, are sanitized and never stored in the memory system. The memory only contains relevant, distilled information about the security issues and their outcomes, without exposing any actual credentials or sensitive data.

The developers liked this approach because it added value to the security scanning process without replacing the core security checks. Instead, it enhanced the system by leveraging the repository's history and previous security decisions to inform future reviews, making the process more efficient and informed.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Murmure: system-wide voice dictation for macOS that never leaves your Mac

The dictation tools I tried on my Mac fell into two camps. The built-in one punctuates poorly. The good ones are paid, and they send your voice to a remote service.

  • Murmure is a macOS voice dictation app with local processing
  • Uses Whisper's large-v3-turbo model for transcription
  • No subscription, no data sent, MIT licensed source code available

The Hidden Cost of Digital: Why Data Center Environmental Transparency Matters Now

In an increasingly digital world, the services we rely on—from streaming videos to complex AI models—are powered by a vast, intricate network of physical infrastructure: data centers.

  • Data centers hide environmental data, violating EED regulations.
  • Only 104 of 186 Dutch data centers report energy and water usage.
  • AI and cloud computing surge fuels data center expansion.

Daily Dose of DevOps — Secrets management: for cloud-native infrastructure

Secrets management: for cloud-native infrastructure Enterprise reliability deteriorates when automation accelerates change without strengthening evidence.

  • Secrets management crucial in cloud-native environments due to automation challenges.
  • Implement zero-trust delivery system with continuous identity, provenance, and policy evaluation.
  • Begin with limited contract, brief-lived identities, and minimum privileges for testing.

The Elephant's Magic: A Technical Leadership Story

How my daughter's bedtime story revolutionized our enterprise architecture "Dad, you said 'five minutes' a long time ago." Amara's voice carries a mix of tiredness and frustration.

  • Amara's daughter taught her father about technical leadership through a bedtime story.
  • The company's component library faced flexibility issues due to performance bottlenecks.

More from Wednesday 30 September →