What Leaks Through the Pipe That Publishes
A private-to-public sync excluded every file it was supposed to exclude and still published the committer's identity, the commit bodies, and a sentence naming the directory it had just hidden.
Pipelines, platforms, and automation — putting security controls where delivery actually happens.
32 articles
A private-to-public sync excluded every file it was supposed to exclude and still published the committer's identity, the commit bodies, and a sentence naming the directory it had just hidden.
A scheduled worker was reading a Cloudflare bot challenge as a rate limit. Classifying it correctly was the right fix, and the first version of that fix doubled the traffic the worker sent.
Two commits a day apart set opposite failure defaults in the same backend, and what decided each one was not the sensitivity of the asset but who gets refused when the control is wrong.
A pre-production security review of a mobile game backend produced seven merged fixes in one day, and almost none of them added a control that was missing.
Device attestation is a control where a correct implementation and a botched rollout produce the same 403, so the rollout mechanics matter more than the cryptography.
A security finding about swallowed email errors was fixed correctly, and the same commit is why the notification emails stopped arriving for four days.
Five review passes over one backend in seven days. The finding count fell every time, the top severity band did not move until the last pass, and two of those top findings were defects the pass before had introduced.
A Next.js downgrade that fixed a broken static export also put five open security advisories back into the lockfile for fifteen hours, and nothing recorded that as a decision.
An agent's permissions are whatever its tools can reach, not whatever its role description says, so the policy has to be written at the tool boundary and tested like a control.
Writing a maturity score down as a function forces you to answer the scoring questions a consultant never has to say out loud, starting with what an unanswered question is worth.
A pipeline reporting green while its security tests never execute looks identical to one that passed, and nothing in the default tooling tells you which you have.
Automation accelerates execution and mistakes. Security guardrails must be designed into workflows without becoming bottlenecks.
Architecture reviews should reduce downstream risk, not become documentation theatre.
As platform teams own more delivery pathways, AppSec governance has to shift from ticketing to policy-driven enablement.
SOC scale comes from better detections, not more alerts. Detection quality must become an engineering discipline.
AI-enabled workflows are now embedded in daily operations. Security teams need practical guardrails that protect data without blocking productivity.
Roadmaps fail when scope grows faster than team capacity. Sustainable planning is a security capability, not just a management practice.
Platform engineering gives security teams a new lever: embed controls into the paths developers already want to use.
Breaking high-risk activities into smaller, verifiable components lets teams build roads instead of climbing mountains — and makes AppSec compliance continuous rather than ceremonial.
Generative AI is everywhere in security conversations, but value only comes when teams tie AI use cases to measurable outcomes and operational reality.
Container adoption moved fast, but many security programs still treat Kubernetes like traditional infrastructure. Here's a practical security model that fits modern platforms.
Build vs. buy in DevSecOps isn't a tooling preference debate. It's an operating-model decision with long-term security and delivery consequences.
DevSecOps maturity isn't about tooling volume. It's about how consistently security controls produce better outcomes at delivery speed.
Cloud scale breaks manual security operations. The path forward is automation tied to policy and measurable control outcomes.
Managing open source risk at enterprise scale requires process discipline, ownership, and signal-focused prioritization — not endless alert volume.
AppSec maturity is less about tool count and more about operating model discipline, ownership, and measurable outcomes.
After SolarWinds, software supply chain security moved from niche concern to board-level priority. Here's a practical framework for 2021.
SolarWinds exposed a hard truth: trusted software channels can become attack channels. Here's what security leaders should do next.
Fast pipelines can quietly become high-risk pipelines. Here are the security gaps I see most often — and how to close them without slowing delivery.
Threat modeling isn't just for security specialists. Here's a practical framework product and engineering teams can use without slowing delivery.
'Shift left' was a good start, but it's no longer enough. Modern DevSecOps demands security controls across the entire software factory.
Most enterprises don't know what's inside the software they ship. Software Composition Analysis isn't optional anymore — here's what ignoring it actually costs.