Viewing profile — gmontard
gmontard
HN member- Joined
- Thu, Oct 24, 2013, 1:24 PM UTC
- HN karma
- 104
- Public activity
- 97 items
- HN profile
- View on Hacker News ↗
About gmontard
Recent public activity
-
story
Show HN: Bearer Code Security Scanner Add Support for Java, PHP, Go, and Python
Hello there, I’m Guillaume, the cofounder and CEO of Bearer, a code security startup trying to rethink security products for a developer-first World. 7 months ago we introduced on …
- story
-
story
Detecting sensitive data shared with OpenAI
Hi HN, I'm Guillaume, the founder of Bearer, an Open Source code security scanning tool. Despite the buzz around generative AI (which, as a reader of HN, you've likely encountered)…
-
comment
Comment #35578411
I’ve been on a call with a few security folks where their organization work with OpenAI and they are all clearly afraid of leaking sensitive data. No one yet really know how to han…
-
story
Show HN: TypeScript Security Scanner
Hi HN, I’m Guillaume, the cofounder of Bearer, an Open Source SAST solution. After launching a few weeks ago here on Hacker News with support for Ruby and JavaScript stacks, I’m ha…
-
comment
Comment #35527842
I like your counter approach to everything we read lately on the topic! I think to your point, besides the quality of the output (that we can challenge with every tool, AI or not),…
-
comment
Comment #35527150
Here is an interesting article from Contrast CTO, especially in an industry that is quite opaque. Comparing one tool with another remains a big challenge, but at least this gives a…
- story
- story
-
comment
Comment #35066621
Oh, I’m really sorry about that, I didn’t know (my fault) mentioning we were on HN was against the rules. Calling that « vote manipulation » is quite exaggerated imho but I get it.…
-
comment
Comment #35061721
Btw if you have some exemple please share or even better write an issue, we’d be super happy to look at it and fine tune the rules. It’s just a 1.0, we can do much better for sure …
-
comment
Comment #35061699
I agree, in theory :) But I’m happy you say that and gives me hope our future automated remediation suggestion can be easily adopted.
-
comment
Comment #35061675
In an ideal world security tools like this one should be useless… but unfortunately we don’t all live in this world where security requirements are all captured, understood and imp…
-
comment
Comment #35061642
We need to open for configuration the filtering and prioritization logic that essentially does that today, but so you can apply your own logic. I advise to start today by looking f…
-
comment
Comment #35059612
You're pushing it ^^
-
comment
Comment #35059200
Once we're a bit more ready on the Cloud version, we'll release the pricing. Honestly I also hate when pricing is not available, so I'd like us to avoid this going further! Thanks …
-
comment
Comment #35058608
Also, super expensive, you need the $99 plan :) https://about.gitlab.com/pricing/ Integration with SCM is clearly a top priority for us, especially directly in PR. GitHub SARIF is …
-
comment
Comment #35058573
SARIF output is on our Roadmap btw! Github code scanning is not so great from what we've heard so far, but also it's very expensive, you need to be on the Enterprise plan...
-
comment
Comment #35058553
Well, we're getting there, at least into proposing some fixes. Automatically fixing is tricky, it means changing your code that can get automatically deployed in production without…
-
comment
Comment #35058501
Not taken, just wanted to give the context of why this license.
-
comment
Comment #35058177
I wouldn't say dominating tbh, but clearly one of the good solution out there for sure. Probably the biggest differentiator is our ability to detect sensitive data flows and map th…
-
comment
Comment #35057682
Workflow is coming with our Cloud offering, with all the cool integration you can think of as Jira or Slack. On the "marking" part, we have two options that will be available super…
-
comment
Comment #35057477
We hear you
-
comment
Comment #35057469
That's right, we don't want to have someone doing managed service on top of us without a getting a license (or just an agreement). Basically, it's the AWS vs Elastic case, that res…
-
comment
Comment #35057356
Absolutely! We wanted to find a good balance with a license to allow any team to use it for their own usage no strings attached and at the same time protect us against a big vendor…