We already had a security scanner
The bigger question was: What happens if it remembers? While building SecurePush for HackWith Hyderabad 3.0, we started with a pretty straightforward idea. A developer runs git push . Before the code reaches the remote repository, SecurePush checks the changes for security problems. If something is wrong, it explains the issue and suggests a fix. The developer decides whether to accept it. The…
SecurePush is a security scanner that checks for security issues before code is pushed to a remote repository. Initially, SecurePush only checked for security problems without any memory of past reviews. However, the developers wanted to add memory to the system to remember security issues and their outcomes.
The idea was to create a feature called Hindsight, which would remember key details from previous security reviews, such as the security issue found, the file affected, the severity of the issue, the suggested fix, and whether the developer accepted or rejected the fix. This historical context would be used in subsequent reviews to provide valuable context to developers.
For example, if SecurePush finds a hardcoded credential in a file and the developer accepts the suggested fix, the memory would record this interaction. During the next review, if a developer makes a similar change, Hindsight can recall the previous interaction and provide relevant context to the security review. This helps the security review process be informed by the repository's history, rather than starting from scratch each time.
To make the memory visible and understandable, SecurePush added a Memory section. When SecurePush remembers something, developers can see what it remembers, such as the security issue, the file involved, the developer's decision, the remediation taken, and the result of the verification process.
The implementation also ensured that sensitive information, like actual API keys, are sanitized and never stored in the memory system. The memory only contains relevant, distilled information about the security issues and their outcomes, without exposing any actual credentials or sensitive data.
The developers liked this approach because it added value to the security scanning process without replacing the core security checks. Instead, it enhanced the system by leveraging the repository's history and previous security decisions to inform future reviews, making the process more efficient and informed.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.