Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
niros_valtos
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
niros_valtos
4mo ago
I think that the cost of Opus is already prohibitively expensive, so not sure how that would compare to Mythos. Check this calculator- it shows that a company with 100 devs can hit ~2.5M cost on tokens annually, which is wild! https:/
2.
▲
by
niros_valtos
4mo ago
This is the supply chain problem climbing up a layer. We spent a decade learning not to pipe random scripts into a shell, and now agents will happily read a repo's files as instructions. Better detection of malicious comments will not
3.
▲
by
niros_valtos
4mo ago
The line I'd draw is accountability: who owns it in prod at 3am. Vibe coding is fine for throwaway and prototypes, and it becomes a problem when the prototype quietly turns into the system and nobody can explain how it works. Don'
4.
▲
by
niros_valtos
4mo ago
We hit this too, and what helped wasn't more reviewers. We pushed the trivial checks (style, obvious bugs, secret and other deterministic scanning) onto automation so humans only look at intent and design, and the trap to avoid is lett
5.
▲
by
niros_valtos
8mo ago
Definitely not a surprise they ship it. This is manageable for a small subset of repos scanned once. Reality is that code changes frequently and such rescans are expensive especially with thinking models. You can open a PR too, but then th
6.
▲
Opengrep – A Fork of Semgrep
(pulse.latio.tech)
13 points
by
niros_valtos
2y ago
|
3 comments
7.
▲
Show HN: Semgrep rule to identify malicious Python code
(gist.github.com)
2 points
by
niros_valtos
3y ago
|
0 comments
8.
▲
Show HN: Semgrep Rule That Identifies GitHub Repo Confusion Attack IOCs
(arnica.io)
2 points
by
niros_valtos
3y ago
|
0 comments
9.
▲
Cellular Outage Caused by Cyber Attack? Speculations on Social Media
(ibtimes.sg)
3 points
by
niros_valtos
3y ago
|
0 comments
10.
▲
by
niros_valtos
3y ago
Download the GitHub CLI. Run ‘ gh pr create’. Good luck!
11.
▲
by
niros_valtos
3y ago
This is great! Github Copilot used to summarize our PRs - I think it can work perfectly as a Github workflow to add comments to newly opened PRs. Can be a nice experiment to use multiple models and compare the comments to determine what wo
12.
▲
The Guide to Building an Efficient CI/CD Pipeline
(nioyatech.com)
2 points
by
niros_valtos
3y ago
|
0 comments
13.
▲
by
niros_valtos
3y ago
The risk severity determination is interesting! If the token of the current user has a site admin permission, the risk is higher.
14.
▲
GitHub sends my hardcoded secrets to providers when Secret Scanning is disabled
(github.com)
3 points
by
niros_valtos
3y ago
|
0 comments
15.
▲
Trying to identify spoofing in GitHub? May the 4th (or 5th) be with you
(arnica.io)
1 points
by
niros_valtos
3y ago
|
0 comments
16.
▲
What Is Pippelineless Security?
(arnica.io)
2 points
by
niros_valtos
4y ago
|
0 comments
17.
▲
Show HN: GitGoat v2 is released – fake commits with real vulnerable code
(github.com)
2 points
by
niros_valtos
4y ago
|
0 comments
18.
▲
GitHub finally introduced fine-grained personal access tokens
(github.blog)
2 points
by
niros_valtos
4y ago
|
0 comments
19.
▲
Hardening software development environments 101
(arnica.io)
3 points
by
niros_valtos
4y ago
|
0 comments
20.
▲
NSA's software supply chain security recommendations need some refinement
(arnica.io)
2 points
by
niros_valtos
4y ago
|
0 comments
21.
▲
Ask HN: How do you prioritize the update of vulnerable 3rd party packages?
6 points
by
niros_valtos
4y ago
|
2 comments
22.
▲
by
niros_valtos
4y ago
LastPass did very well! Here’s why: https://www.arnica.io/blog/a-first-look-at-lastpass-security...
23.
▲
Hold the pitchforks. What LastPass did right.
(arnica.io)
1 points
by
niros_valtos
4y ago
|
0 comments
24.
▲
by
niros_valtos
4y ago
I like the way then handle the communication about the incident. There 2 ways to interpret the message: 1. Someone managed to get access to dev credentials and exfiltrated source code (the part that is explicitly mentioned). 2. Someone man
25.
▲
by
niros_valtos
4y ago
This is great stuff! I read This adjacent research, which seems to complement yours - https://www.arnica.io/blog/how-do-top-open-source-projects-p...
26.
▲
by
niros_valtos
4y ago
Super interesting!!! As a former penetration tester, I had several opportunities to move to the other side of the law. The money offered to me was extremely high, and I believe I could be really good at these ops. With that said, I decided
27.
▲
GitHub Enterprise Cloud customers can access IP addresses for audit log entries
(github.blog)
1 points
by
niros_valtos
4y ago
|
0 comments
28.
▲
Making to most of GitHub rate limits
(jamiemagee.co.uk)
1 points
by
niros_valtos
4y ago
|
0 comments
29.
▲
What is eBPF, anyway, and why should Kubernetes admins care?
(groundcover.com)
1 points
by
niros_valtos
4y ago
|
0 comments
30.
▲
by
niros_valtos
4y ago
Remember stuxnet? Supply chain security in its glory…
More ›