Turning Audit Findings into CI Checks
Originally appeared on The Rails Tech Debt Blog.You get a site audit report and it looks manageable. A few dozen findings, most of them small: a page with barely any text on it, a...
Search fresh public links, source activity, and ready-to-use post angles for Code Audit.
Fresh curated links around Code audit are collected here so marketers can spot useful updates and turn timely ideas into posts faster.
Recent items include:
Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.
Originally appeared on The Rails Tech Debt Blog.You get a site audit report and it looks manageable. A few dozen findings, most of them small: a page with barely any text on it, a...
Reports that a coding CLI transmitted unexpectedly broad local data are trending today. A social post is a lead, not a verdict, so the useful response is a reproducible audit. Sta...
Over the years, we have written about many of the tools we use: Skunk for combining code quality and code coverage data, bundler-audit for security vulnerabilities in your dependen...
A month ago I shipped aicraft-code-review, an MCP server that reviews code locally. This week I added a CLI mode — because not everyone wants to wire up an MCP client just to che...
Most Solidity scanners are high-recall, low-precision. They flag 40 things, 38 are noise, and after the third report you stop reading them — so the one real bug ships. Precision, n...
In a paid audit, a false positive is not just noise — it's a credibility killer. Hand a founder a "CRITICAL: unprotected fund sweep" that turns out to be safe-by-design, and you'...
A smart contract can look finished long before it is safe to release. The functions work in testing, the expected transactions pass, and…Continue reading on Medium »
Originally appeared on The Rails Tech Debt Blog.Today I’m excited to share a new open source project: A Claude Code skill to assess technical debt in a Ruby on Rails application. I...
I was comparing crypto trading terminals and did what I usually do first: curl the top-ranking page and read the HTML instead of the rendering. The site ranks first for its target...
Security Audit Report: Reentrancy & Access Control Review: Poloniex Target Protocol: Poloniex (TVL: $1493.5M) Security Audit Report: Reentrancy & Access Control...
Vibe coded a useful thing for Rubyists over the weekend. Audition is a linter/fixer that gets your code Ractor-ready: static analysis powered by Shopify’s rubydex, plus dynamic pro...
Патч был на две строки: правка в проверке прав доступа. На ревью читается ровно то, что задумано, — апрув, мёрж. Через день выясняется, что проверка не срабатывает, хотя код перед...
My Solana Program Security Checklist This is for anyone shipping an Anchor program to mainnet — especially if you're coming from a web2 background and looking for the Solana equiv...
Structured data breaks silently: the page renders fine while your Product schema has "$19.99" as a price, your LocalBusiness lost its address in a redesign, and your breadcrumbs go...
A $550,000 community audit contest uncovered two critical vulnerabilities in XRP Ledger features that could have drained user accounts without private keys. The findings reveal how...
Originally appeared on avdi.codes. We’ve spent years loading an extraordinary number of responsibilities onto the humble code review: quality gate, security check, architecture rev...
Теперь можно говорить без всяких прикрас: мы выпустили анализатор для языков JavaScript и TypeScript. А значит, это повод испытать его в полевых условиях и посмотреть, что он найдё...
<p><em>When the pilot episode of Deep Build circulated, someone in the Discord asked the fairest question a show like this</p></em>
I recently inherited a web + mobile platform that lives in GitHub and is deployed through Vercel with Cloudflare in front. Everything runs, but the architecture feels overly comple...
Small AI-built apps often lose trust before anyone gets to the interesting part. The model might work. The demo might be clever. But a first visitor still has to answer boring que...
The default mental model treats a security audit as a gate at the end of development — write the contract, finish testing, then send it…Continue reading on Medium »
I need a comprehensive audit of my mobile app, available on both iOS and Android platforms. The audit should cover: - UI/UX Design: Evaluate the user interface and user experience...
I just shipped AL Griller, a static analyzer for Dynamics 365 Business Central AL code that roasts you when it finds a real problem. Before I talk about the jokes, I want to talk a...
Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.