# code security

Code security is the practice of protecting software source code, dependencies, and configuration files from vulnerabilities, including throughout the software development lifecycle.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Putting models to the secure coding test: Plan vs default mode

DevFeed: [Putting models to the secure coding test: Plan vs default mode](<https://devfeed.tech/articles/putting-models-to-the-secure-coding-test-plan-vs-default-mode-8297.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/putting-models-to-the-secure-coding-test-plan-vs-default-mode/>)

Author: Kennedy Toomey

Published: 2026-08-19T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Code quality](<https://devfeed.tech/topics/code-quality.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [codex](<https://devfeed.tech/topics/codex.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [claude](<https://devfeed.tech/tags/claude.md>), [code-quality](<https://devfeed.tech/tags/code-quality.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [codex](<https://devfeed.tech/tags/codex.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article describes an experiment comparing plan mode with default mode for secure code generation. The author tested Sonnet 5, Composer 2.5, and GPT 5.5 through Claude, Cursor, and Codex, using security and code-quality analysis to assess the results.

### Source excerpt

We tested Sonnet 5, Composer 2.5, and GPT 5.5 in plan mode and default mode to see whether plan mode produces measurably more secure code.

## Capital One Announces Open-Source VulnHunter Agentic AI Code Security Tool

DevFeed: [Capital One Announces Open-Source VulnHunter Agentic AI Code Security Tool](<https://devfeed.tech/articles/announcing-vulnhunter-22570.md>)

Original publisher: [Read original article](<https://medium.com/capital-one-tech/announcing-vulnhunter-ce9784834ca9?source=rss----3db3a67cb648---4>)

Author: Capital One Tech

Published: 2026-07-17T17:01:41Z

Content type: release

Language: en

Sources: [Capital One Tech](<https://devfeed.tech/sources/capital-one-tech.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Developer experience](<https://devfeed.tech/topics/developer-experience.md>)

Tags: [agentic-ai-security](<https://devfeed.tech/tags/agentic-ai-security.md>), [ai-code-security](<https://devfeed.tech/tags/ai-code-security.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [build](<https://devfeed.tech/tags/build.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [code-vulnerability](<https://devfeed.tech/tags/code-vulnerability.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developer-experience](<https://devfeed.tech/tags/developer-experience.md>), [developers](<https://devfeed.tech/tags/developers.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [generative-ai-tools](<https://devfeed.tech/tags/generative-ai-tools.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Capital One announces the open-source release of VulnHunter, an agentic AI security tool that analyzes source code from an attacker's perspective. It is designed to identify potentially exploitable defects, map prospective attack paths, and propose targeted code remediations.

### Source excerpt

Capital One's open-source, agentic AI code security tool. The rules of software security are changing faster than most defenders can keep pace. Advanced AI models have dramatically lowered the barrier for bad actors to discover and exploit vulnerabilities in software. What once required significant skill and time can now be automated, accelerated, and scaled. The world faces an increasingly short window of time before highly sophisticated, next-generation AI attack capabilities become affordable and accessible to virtually every adversary. Across the industry, organizations are racing to prepare for this paradigm shift. Traditional environmental protections like network segmentation, identity controls, and monitoring remain essential, but are no longer sufficient on their own. The ultimate defense in this new reality requires a shift in approach: organizations need to consider and detect the vulnerabilities in their code and fix them before adversaries can deploy advanced models to discover and exploit them. At Capital One, we decided that the right response to AI-enabled threats wasn't to wait, but to build cutting-edge AI-driven defenses and put them in the hands of defenders everywhere. That's why we are announcing today the open-source release of VulnHunter, an advanced agentic AI security tool designed to apply proactive, attacker-perspective analysis directly to the source code. Developed internally at Capital One, VulnHunter is not a traditional, passive vulnerability scanner. It represents a shift in defensive tooling with an agentic reasoning workflow to identify potentially exploitable defects, map prospective attack paths, and propose highly targeted code remediations. Built for the developer experience To fully unlock the utility of VulnHunter, we knew ease of use mattered. A persistent challenge with traditional security tools is that they are often built primarily to enforce rigid cybersecurity practices, without much consideration for a developer's ac

## Introducing Gemini 3.5 Flash Cyber

DevFeed: [Introducing Gemini 3.5 Flash Cyber](<https://devfeed.tech/articles/introducing-gemini-3-5-flash-cyber-6195.md>)

Original publisher: [Read original article](<https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/>)

Author: Raluca Ada Popa; Four Flynn

Published: 2026-07-17T15:00:11Z

Content type: article

Language: en

Sources: [Google DeepMind News](<https://devfeed.tech/sources/google-deepmind-news.md>)

Topics: [code security](<https://devfeed.tech/topics/code-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Code](<https://devfeed.tech/topics/code.md>), [Language models](<https://devfeed.tech/topics/language-models.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [gemini](<https://devfeed.tech/tags/gemini.md>), [google](<https://devfeed.tech/tags/google.md>), [model](<https://devfeed.tech/tags/model.md>), [models](<https://devfeed.tech/tags/models.md>), [scale](<https://devfeed.tech/tags/scale.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Google introduces Gemini 3.5 Flash Cyber, a lightweight cybersecurity model built on Gemini 3.5 Flash and fine-tuned to find, validate, and patch software vulnerabilities. The article describes its use through CodeMender, its efficiency for scanning large codebases and codepaths, a limited-access pilot for governments and trusted partners, and planned customer access through the Gemini Enterprise Agent Platform.

### Source excerpt

Google introduces Gemini 3.5 Flash Cyber, a lightweight cybersecurity model to find and patch vulnerabilities.

## Technology Short Take 197

DevFeed: [Technology Short Take 197](<https://devfeed.tech/articles/technology-short-take-197-10931.md>)

Original publisher: [Read original article](<https://blog.scottlowe.org/2026/06/19/technology-short-take-197/>)

Author: Scott Lowe

Published: 2026-06-19T14:00:00Z

Content type: opinion

Language: en

Sources: [Scott's Weblog](<https://devfeed.tech/sources/scott-s-weblog.md>)

Topics: [networking](<https://devfeed.tech/topics/networking.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [cloud security](<https://devfeed.tech/topics/cloud-security.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [cli](<https://devfeed.tech/tags/cli.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cni](<https://devfeed.tech/tags/cni.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cri-o](<https://devfeed.tech/tags/cri-o.md>), [devops](<https://devfeed.tech/tags/devops.md>), [docker](<https://devfeed.tech/tags/docker.md>), [go](<https://devfeed.tech/tags/go.md>), [iac](<https://devfeed.tech/tags/iac.md>), [k8s](<https://devfeed.tech/tags/k8s.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [linux](<https://devfeed.tech/tags/linux.md>), [networking](<https://devfeed.tech/tags/networking.md>), [oci](<https://devfeed.tech/tags/oci.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

A commentary roundup covering radical network redesign at AWS, quantum computing's implications for encryption, AI's effects on certifications and code security, AI agent exploits, open-source vulnerabilities, Kubernetes resources, cloud operations, the AI bubble, and AWS IAM guidance.

### Source excerpt

Welcome to Technology Short Take 197! I've been traveling for business for the last week, so this Technology Short Take has a tad fewer links than I typically include. Even so, I still have links on radical new network designs, the impacts of AI on code security, things beginners get wrong about AWS IAM, and more! Let's get into the content. Networking This story about a radical network redesign at AWS--along with this accompanying arXiv paper--was intriguing to me. I'm not a networking expert, but designing networks with quasi-random connections between endpoints definitely flies in the face of the traditional wisdom. I do wonder, though, if this is the sort of technology that only makes sense for the hyperscalers, and not for the rest of us. Doug Dawson provides a quick update on current encryption standards and what he terms the "pending encryption crisis" presented by quantum computing. It would appear that AI is affecting even Cisco's well-known industry certifications, as outlined by Daniel Dib. Security CodeRabbit shared the results of an analysis of PRs to open source projects showing that AI-written code produces ~1.7x more issues. Along the same lines, Jens Wessling of Veracode indicates that 45% of all AI-generated code samples contained OWASP Top 10 security vulnerabilities. Anyone who didn't expect seemingly-dangerous AI agent security exploits to appear hasn't been paying attention. Enterprise AI tools don't appear exempt, either. The complex interdependencies of open source software projects once again means that a single critical vulnerability threatens a much larger number of projects and tools. Cloud Computing/Cloud Management This is an older post, but the author recently updated it--check out Marcus Noble's recommended resources for Kubernetes newbies. I am not yet sure about pulumi do (direct operations for any cloud resource; see the Pulumi blog post about it). On one hand, I can see the utility in situations where you "just need a quick" whatever

## How Dropbox uses MCP and Dash to close the design-to-code security gap

DevFeed: [How Dropbox uses MCP and Dash to close the design-to-code security gap](<https://devfeed.tech/articles/how-dropbox-uses-mcp-and-dash-to-close-the-design-to-code-security-gap-180.md>)

Original publisher: [Read original article](<https://dropbox.tech/security/dropbox-mcp-dash-design-code-security>)

Author: Yasmin McDowell,Lawrence Good,Ilya Yakovlev,Andrew Cheung,Binoy Dash,Simran Jumani,Dmitriy Meyerzon,Mark Breitenbach,Ishan Mishra

Published: 2026-06-12T18:00:00Z

Content type: article

Language: en

Sources: [Dropbox Tech Blog](<https://devfeed.tech/sources/dropbox-tech-blog.md>)

Topics: [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Code review](<https://devfeed.tech/topics/code-review.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Language models](<https://devfeed.tech/topics/language-models.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [code-quality](<https://devfeed.tech/tags/code-quality.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developer-tools](<https://devfeed.tech/tags/developer-tools.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [review](<https://devfeed.tech/tags/review.md>), [security](<https://devfeed.tech/tags/security.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

Dropbox built an agentic AI system combining Model Context Protocol, foundational large language models, and Dash to retrieve relevant threat models during code review. The system evaluates whether code changes align with documented security requirements and helps expose gaps between design decisions and implementation.

### Source excerpt

Using an agentic AI system to surface threat models during code review and spot gaps between security requirements and implementation.

## Detect source code attacks with Datadog Code Threat Detection

DevFeed: [Detect source code attacks with Datadog Code Threat Detection](<https://devfeed.tech/articles/detect-source-code-attacks-with-datadog-code-threat-detection-2258.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/datadog-code-threats/>)

Author: Kassen Qian; Daniel Blazquez; Christoph Hamsen

Published: 2026-06-09T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [review](<https://devfeed.tech/tags/review.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Datadog Code Threat Detection analyzes GitHub pull requests with AI-assisted analysis to identify malicious code changes and attempts to compromise CI/CD pipelines, secrets, and release workflows.

### Source excerpt

Learn how Datadog Code Threat Detection helps teams detect malicious pull requests and source code attacks targeting CI/CD workflows, secrets, and software releases.

## AI Is Building Your Attack Surface. Are You Testing It?

DevFeed: [AI Is Building Your Attack Surface. Are You Testing It?](<https://devfeed.tech/articles/ai-is-building-your-attack-surface-are-you-testing-it-7806.md>)

Original publisher: [Read original article](<https://snyk.io/blog/ai-is-building-your-attack-surface-are-you-testing-it/>)

Author: Manoj Nair

Published: 2026-03-19T00:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [code security](<https://devfeed.tech/topics/code-security.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [code-generation](<https://devfeed.tech/tags/code-generation.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [coding](<https://devfeed.tech/tags/coding.md>), [executive](<https://devfeed.tech/tags/executive.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

AI-generated code is accelerating development while introducing serious security risks: 62% of LLM-generated backend code evaluated by BaxBench was broken or insecure, and about half of the code that worked remained exploitable. The article argues that static analysis is necessary but insufficient, and that runtime testing is needed to assess real exploitability. It also highlights AI agents as an expanding attack surface because they increasingly call privileged and undocumented APIs.

### Source excerpt

Speed has outpaced validation. With 62% of LLM-generated code testing as insecure and AI agents using undocumented APIs, legacy tools fall short. Learn how Snyk's AI-powered dynamic testing secures your expanding attack surface.

## Claude Code Security: A Welcome Evolution in the Remediation Loop

DevFeed: [Claude Code Security: A Welcome Evolution in the Remediation Loop](<https://devfeed.tech/articles/claude-code-security-a-welcome-evolution-in-the-remediation-loop-7861.md>)

Original publisher: [Read original article](<https://snyk.io/blog/claude-code-remediation-loop-evolution/>)

Author: Manoj Nair

Published: 2026-02-23T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Frontier AI](<https://devfeed.tech/topics/frontier-ai.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [frontier-ai](<https://devfeed.tech/tags/frontier-ai.md>), [interest](<https://devfeed.tech/tags/interest.md>), [llm](<https://devfeed.tech/tags/llm.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [review](<https://devfeed.tech/tags/review.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [tech](<https://devfeed.tech/tags/tech.md>), [validation](<https://devfeed.tech/tags/validation.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Claude Code Security is presented as a major advance in vulnerability discovery and patch drafting, but the article argues that enterprise security still requires deterministic and dynamic validation, remediation automation, and governance. It emphasizes that secure code generation remains difficult because AI-assisted development can introduce business logic, authorization, injection, and cross-file vulnerabilities.

### Source excerpt

Anthropic's Claude Code Security marks a major shift in vulnerability discovery, but AI-driven development requires more than just reasoning to remain secure. Learn how Snyk's AI Security Fabric integrates with Claude to close the loop between finding vulnerabilities and fixing them at scale.

## Scan your AI-generated code from Cursor using Model Context Protocol (MCP)

DevFeed: [Scan your AI-generated code from Cursor using Model Context Protocol (MCP)](<https://devfeed.tech/articles/scan-your-ai-generated-code-from-cursor-using-model-context-protocol-mcp-8074.md>)

Original publisher: [Read original article](<https://snyk.io/blog/scan-your-ai-generated-code-from-cursor-using-model-context-protocol-mcp/>)

Author: Manoj Nair

Published: 2025-06-23T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [cursor](<https://devfeed.tech/topics/cursor.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [Model Context Protocol (MCP)](<https://devfeed.tech/topics/model-context-protocol-mcp.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [interoperability](<https://devfeed.tech/topics/interoperability.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [snyk-code](<https://devfeed.tech/topics/snyk-code.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-assistants](<https://devfeed.tech/tags/ai-assistants.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cli](<https://devfeed.tech/tags/cli.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [customer](<https://devfeed.tech/tags/customer.md>), [developer](<https://devfeed.tech/tags/developer.md>), [interoperability](<https://devfeed.tech/tags/interoperability.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [model-context-protocol-mcp](<https://devfeed.tech/tags/model-context-protocol-mcp.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains how Snyk's CLI MCP server integrates with Cursor to provide in-agent security for AI-generated code. It describes real-time detection of known vulnerabilities in code and open-source packages, with minimal configuration through MCP interoperability.

### Source excerpt

Secure your AI-generated code from Cursor in real-time with Snyk's CLI Model Context Protocol (MCP) server. Detect vulnerabilities and accelerate secure development without compromising agility.

## Snyk Security Solution Now Integrated into Google Cloud's Gemini Code Assist

DevFeed: [Snyk Security Solution Now Integrated into Google Cloud's Gemini Code Assist](<https://devfeed.tech/articles/snyk-security-solution-now-integrated-into-google-cloud-s-gemini-code-assist-8165.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-security-solution-now-integrated-into-google-clouds-gemini-code-assist/>)

Author: Liqian Lim (林利蒨)

Published: 2025-04-09T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [ide](<https://devfeed.tech/topics/ide.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [executive](<https://devfeed.tech/tags/executive.md>), [gemini](<https://devfeed.tech/tags/gemini.md>), [google](<https://devfeed.tech/tags/google.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [sast](<https://devfeed.tech/tags/sast.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>)

### AI overview

Snyk's security solution is integrated into Google Cloud's Gemini Code Assist, enabling developers to use Snyk security capabilities through natural-language prompts and the coding assistant's chat interface.

### Source excerpt

Secure AI coding with Snyk and Google Gemini. Learn how Snyk Code's SAST integrates with Gemini Code Assist for seamless, secure development workflows.

## Snyk Code Improves Contextual Dataflow Analysis for Taint Vulnerabilities

DevFeed: [Snyk Code Improves Contextual Dataflow Analysis for Taint Vulnerabilities](<https://devfeed.tech/articles/analyze-taint-analysis-faster-with-improved-contextual-dataflow-in-snyk-code-7818.md>)

Original publisher: [Read original article](<https://snyk.io/blog/analyze-taint-analysis-contextual-dataflow-snyk-code/>)

Author: Liran Tal

Published: 2024-10-10T05:00:00Z

Content type: release

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk-code](<https://devfeed.tech/topics/snyk-code.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [data](<https://devfeed.tech/tags/data.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [feature](<https://devfeed.tech/tags/feature.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

Snyk Code introduces an improved contextual dataflow view for taint vulnerabilities. The update highlights the critical steps in a dataflow path so developers can assess potential true positives and address security issues more efficiently.

### Source excerpt

Snyk Code's enhanced dataflow analysis simplifies vulnerability identification and remediation. Learn how this powerful tool streamlines the security process and saves developers valuable time.

## What you should know about PHP code security

DevFeed: [What you should know about PHP code security](<https://devfeed.tech/articles/what-you-should-know-about-php-code-security-8044.md>)

Original publisher: [Read original article](<https://snyk.io/blog/php-code-security/>)

Author: Liran Tal

Published: 2024-09-04T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [PHP](<https://devfeed.tech/topics/php.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Sanitization](<https://devfeed.tech/topics/sanitization.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [SQL](<https://devfeed.tech/topics/sql.md>), [Laravel](<https://devfeed.tech/topics/laravel.md>), [WordPress](<https://devfeed.tech/topics/wordpress.md>), [Databases](<https://devfeed.tech/topics/databases.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [env-file-security](<https://devfeed.tech/tags/env-file-security.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [php](<https://devfeed.tech/tags/php.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [sql](<https://devfeed.tech/tags/sql.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>), [web-development](<https://devfeed.tech/tags/web-development.md>), [wordpress](<https://devfeed.tech/tags/wordpress.md>)

### AI overview

An overview of PHP code security, covering common causes of vulnerabilities, SQL injection risks, input sanitization, prepared statements, secure coding, dependency and infrastructure scanning, and the business consequences of breaches.

### Source excerpt

Let's discuss the importance of PHP security and the business impact of some notable PHP interpreter vulnerabilities that are crucial for developers to get right.

## The journey to AppSec gold: Lessons we can learn from the Olympians

DevFeed: [The journey to AppSec gold: Lessons we can learn from the Olympians](<https://devfeed.tech/articles/the-journey-to-appsec-gold-lessons-we-can-learn-from-the-olympians-7994.md>)

Original publisher: [Read original article](<https://snyk.io/blog/journey-to-appsec-gold/>)

Author: Krysta Williams-Timm

Published: 2024-08-15T05:00:00Z

Content type: opinion

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Development](<https://devfeed.tech/topics/development.md>), [Security](<https://devfeed.tech/topics/security.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [building](<https://devfeed.tech/tags/building.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [consistency](<https://devfeed.tech/tags/consistency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article uses Olympic training as an analogy for achieving application security excellence. It emphasizes consistent effort, collaboration between security and development teams, integration with existing developer workflows, practical remediation, and an asset-first focus on continuous improvement.

### Source excerpt

In honor of the upcoming Olympics, let's look at a few of the "training areas" that help security teams on their journey to AppSec gold.

## Introducing Snyk's partnership with Gemini Code Assist

DevFeed: [Introducing Snyk's partnership with Gemini Code Assist](<https://devfeed.tech/articles/introducing-snyk-s-partnership-with-gemini-code-assist-8153.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-partnership-gemini-code-assist/>)

Author: David Lugo

Published: 2024-04-09T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Google](<https://devfeed.tech/topics/google.md>), [Google Cloud Platform (GCP)](<https://devfeed.tech/topics/google-cloud.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-assisted-coding](<https://devfeed.tech/tags/ai-assisted-coding.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [devops](<https://devfeed.tech/tags/devops.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [executive](<https://devfeed.tech/tags/executive.md>), [gemini](<https://devfeed.tech/tags/gemini.md>), [google](<https://devfeed.tech/tags/google.md>), [interest](<https://devfeed.tech/tags/interest.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

Snyk announces a partnership with Google Gemini Code Assist to help developers use AI-assisted coding while maintaining code security. The integration provides automated fixes, inline security feedback, and security visibility within Google Cloud Code IDE workflows.

### Source excerpt

Learn how Snyk's new partnership with Gemini Code Assist empowers developers to develop with security and AI-powered velocity.

## GitGuardian pioneers secure code solutions down to its source with Chainguard Images

DevFeed: [GitGuardian pioneers secure code solutions down to its source with Chainguard Images](<https://devfeed.tech/articles/gitguardian-pioneers-secure-code-solutions-down-to-its-source-with-chainguard-images-13066.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/gitguardian-pioneers-secure-code-solutions-down-to-its-source-with-chainguard-images>)

Published: 2024-03-13T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [customer-trust](<https://devfeed.tech/tags/customer-trust.md>), [gitguardian](<https://devfeed.tech/tags/gitguardian.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This case study describes how GitGuardian partnered with Chainguard and adopted Chainguard Images to address software-container vulnerabilities, reduce CVEs, streamline vulnerability management, and meet customer SLAs and compliance requirements.

### Source excerpt

GitGuardian partners with Chainguard, utilizing Chainguard Images to reduce CVEs, enhance security, and meet compliance standards efficiently.

## 5 security best practices for adopting generative AI code assistants like GitHub Copilot

DevFeed: [5 security best practices for adopting generative AI code assistants like GitHub Copilot](<https://devfeed.tech/articles/5-security-best-practices-for-adopting-generative-ai-code-assistants-like-github-copilot-7776.md>)

Original publisher: [Read original article](<https://snyk.io/blog/5-security-best-practices-generative-ai-code-assistants-copilot/>)

Author: Liqian Lim (林利蒨)

Published: 2024-03-05T12:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Code](<https://devfeed.tech/topics/code.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-completion](<https://devfeed.tech/tags/code-completion.md>), [code-reviews](<https://devfeed.tech/tags/code-reviews.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [errors](<https://devfeed.tech/tags/errors.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [github-copilot](<https://devfeed.tech/tags/github-copilot.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [security-tools](<https://devfeed.tech/tags/security-tools.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

This article presents five security best practices for adopting generative AI code assistants such as GitHub Copilot. It emphasizes keeping humans in the loop, validating and reviewing AI-generated code, educating teams about risks, and using security tools and guardrails.

### Source excerpt

Learn how you can safely adopt AI code completion tools (like Copilot) by applying these 5 best practices and see how Snyk can make it easy to stay secure.

## How to choose a security tool for your AI-generated code

DevFeed: [How to choose a security tool for your AI-generated code](<https://devfeed.tech/articles/how-to-choose-a-security-tool-for-your-ai-generated-code-7957.md>)

Original publisher: [Read original article](<https://snyk.io/blog/how-to-choose-a-security-tool-for-your-ai-generated-code/>)

Author: Liqian Lim (林利蒨)

Published: 2024-01-09T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [snyk-code](<https://devfeed.tech/topics/snyk-code.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [ai-coding](<https://devfeed.tech/topics/ai-coding.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [real-time](<https://devfeed.tech/topics/real-time.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-code-security](<https://devfeed.tech/tags/ai-code-security.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [guide](<https://devfeed.tech/tags/guide.md>), [ide](<https://devfeed.tech/tags/ide.md>), [learn](<https://devfeed.tech/tags/learn.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>)

### AI overview

This buyer's guide presents five considerations for choosing a security tool for AI-generated code. It emphasizes real-time analysis within the IDE, minimal disruption to developer workflows, speed that keeps pace with AI coding tools, and accuracy that helps address generative AI hallucinations. The article uses Snyk's experience and Snyk Code, powered by DeepCode AI, as examples.

### Source excerpt

There are a multitude of considerations when it comes to picking the right security companion for your preferred generative AI tool. Here are the top 5 factors for you to consider when making your selections.

## Snyk highlights AWS re:Invent 2023

DevFeed: [Snyk highlights AWS re:Invent 2023](<https://devfeed.tech/articles/snyk-highlights-aws-re-invent-2023-8140.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-highlights-aws-reinvent-2023/>)

Author: David Lugo

Published: 2023-12-14T06:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Application Development](<https://devfeed.tech/topics/application-development.md>), [Language models](<https://devfeed.tech/topics/language-models.md>), [cloud security](<https://devfeed.tech/topics/cloud-security.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-code-security](<https://devfeed.tech/tags/ai-code-security.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [ai-tools](<https://devfeed.tech/tags/ai-tools.md>), [amazon](<https://devfeed.tech/tags/amazon.md>), [application-development](<https://devfeed.tech/tags/application-development.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [aws](<https://devfeed.tech/tags/aws.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-computing](<https://devfeed.tech/tags/cloud-computing.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [coding](<https://devfeed.tech/tags/coding.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [iac-security](<https://devfeed.tech/tags/iac-security.md>), [interest](<https://devfeed.tech/tags/interest.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [security](<https://devfeed.tech/tags/security.md>), [security-solutions](<https://devfeed.tech/tags/security-solutions.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [tool](<https://devfeed.tech/tags/tool.md>)

### AI overview

This recap covers Snyk's AWS re:Invent 2023 highlights, including AWS partnership achievements, new AWS integrations, generative AI developments, and the use of AI coding assistants. It emphasizes the need for AI security solutions because AI-generated code can increase vulnerabilities.

### Source excerpt

In this blog, we recap the most exciting developments from AWS re:Invent 2023, including Snyk's industry-leading progress with generative AI, ASPM, and the importance of AI security.

## Using Heartbleed as a starting point

DevFeed: [Using Heartbleed as a starting point](<https://devfeed.tech/articles/using-heartbleed-as-a-starting-point-20667.md>)

Original publisher: [Read original article](<http://antirez.com/news/76>)

Published: 2014-04-10T09:06:18Z

Content type: opinion

Language: en

Sources: [Antirez](<https://devfeed.tech/sources/antirez.md>)

Topics: [openssl](<https://devfeed.tech/topics/openssl.md>), [Security](<https://devfeed.tech/topics/security.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Static code analysis](<https://devfeed.tech/topics/static-code-analysis.md>), [C](<https://devfeed.tech/topics/c.md>)

Tags: [c](<https://devfeed.tech/tags/c.md>), [code-analysis](<https://devfeed.tech/tags/code-analysis.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article uses the Heartbleed vulnerability in OpenSSL as a starting point for discussing how to improve system software security. It argues for greater investment in security audits, open-source software development, and static and dynamic checks, while noting that changing languages or specifications is unlikely in the near term.

### Source excerpt

The strong reactions about the recent OpenSSL bug are understandable: it is not fun when suddenly all the internet needs to be patched. Moreover for me personally how trivial the bug is, is disturbing. I don't want to point the finger to the OpenSSL developers, but you just usually think at those class of issues as a bit more subtle, in the case of a software like OpenSSL. Usually you fail to do sanity checks *correctly*, as opposed to this bug where there is a total *lack* of bound checks in the memcpy() call. However sometimes in the morning I read the code I wrote the night before and I'm deeply embarrassed. Programmers sometimes fail, I for sure do often, so my guess is that what is needed is a different process, and not a different OpenSSL team. There is who proposes a different language safer than C, and who proposes that the specification is broken because it is too complex. Probably there is some truth in both arguments, however it is unlikely that we move to a different specification or system language soon, so the real question is, what we can do now to improve system software security? 1) Throw money at it. Making system code safer is simple if there are investments. If different companies hire security experts to do code auditings in the OpenSSL code base, what happens is that the probability of discovering a bug like heartbleed is greater. I've seen very complex bugs that are triggered by a set of non-trivial conditions being discovered by serious code auditing efforts. A memcpy() without bound checks is something that if you analyze the code security-wise, will stand out in the first read. And guess how heartbleed was discovered? Via security auditings performed at Google. Probably the time to consider open source something that mostly we take from is over. Many companies should follow the example of Google and other companies, using workforce for OSS software development and security. 2) Static and dynamic checks. Static code analysis is, as a side ef