Code scanning for security vulnerabilities now available
51–60 of 125 posts
Re: Code scanning for security vulnerabilities now available
#52Earlier quoted context omitted.
There's a genuine security fatigue issue (much like event fatigue) that comes from false positives. Unfortunately that doesn't reduce the value of the scanning - the onus is on the false positives. At the very least, running and pruning scans should happen on projects so that at least we can have the conversation. It's like PCI (as an example, not an ideal); PCI isn't perfect, but at least it encourages a conversatio…
Automated proof of vulnerability is valuable. Kafkaesque pattern matching, is not.
Re: Code scanning for security vulnerabilities now available
#53Open Source authors [1] [2] (including myself) have complained of automatic security scans. They yield way too many false positives, increasing the burden of maintaining repositories. Specially troublesome are when e.g. the "vulnerability" (if it's even one) is in a devDependency that is not deployed to production. In theory automatic vulnerability scans sounds great, but having every repo ping you with not-actually-…
I'm glad it's not just me seeing this - My repos aren't even that popular and some of the issues just seem to be "help me build my project..."
Re: Code scanning for security vulnerabilities now available
#54Re: Code scanning for security vulnerabilities now available
#55Bio Etihad cancellation policy - Read how to cancel etihad flight booking within 24 hour and how to get refund on cancellation.More info: https://airlinesreservationsdeals.com/etihad-airways/flight-...
Re: Code scanning for security vulnerabilities now available
#56In the not-so-distant future: Code snippet scanning for copyright infringement or Stack Overflow attribution. 2 years? 4?
Will never happen. Can you imagine what would occur if Github started harrassing private repo owners for including GPL licensed code? Or automatically making them public? All their customers would bolt immediately. Copyright infringement is Github's bread and butter.
Stack Overflow attribution is equally unlikely. The same group that says Oracle's claim that Java's API is not original and unworthy of copyright protection, cannot then turn around and claim 30 lines of code from SO is original and deserves recognition.
Re: Code scanning for security vulnerabilities now available
#57Re: Code scanning for security vulnerabilities now available
#58Open Source authors [1] [2] (including myself) have complained of automatic security scans. They yield way too many false positives, increasing the burden of maintaining repositories. Specially troublesome are when e.g. the "vulnerability" (if it's even one) is in a devDependency that is not deployed to production. In theory automatic vulnerability scans sounds great, but having every repo ping you with not-actually-…
Re: Code scanning for security vulnerabilities now available
#59Pass from me, given the published pricing is: > Contact Sales to learn more
So, I guess, "well done"? (it hurts a little though, I'm too in the camp of wanting to see the pricing beforehand)
Re: Code scanning for security vulnerabilities now available
#60Earlier quoted context omitted.
There's a genuine security fatigue issue (much like event fatigue) that comes from false positives. Unfortunately that doesn't reduce the value of the scanning - the onus is on the false positives. At the very least, running and pruning scans should happen on projects so that at least we can have the conversation. It's like PCI (as an example, not an ideal); PCI isn't perfect, but at least it encourages a conversatio…
Automated proof of vulnerability is valuable. Kafkaesque pattern matching, is not.
Neither is proof of a vulnerability. Both I will gladly, always 100% validate.