Topics
Follow your own topics →
DIFF.BLOG
New Following Discover Jobs
More
Top Writers Suggest a blog Upvotes plugin
Report bug Contact About
Sign up
Menu
New Following Discover Jobs Top Writers
More
Suggest a blog Upvotes plugin Report bug Contact About
Sign up
The home for great developer writing.
Discover the best posts from developers and engineering teams, all in one place.
Join now → Learn more
TOPICS

If it could have, why didn't it?

249 · Alex Gaynor · April 13, 2026, 9:53 p.m.
vulnerability research static-analysis Software Security Bug Detection
Summary
The post challenges the common belief that static analysis can identify all software vulnerabilities, highlighting the prevalence of other techniques that uncover bugs traditionally overlooked by static analysis. It criticizes the overconfidence in static analysis as a complete solution for vulnerability detection.
Read full post on alexgaynor.net →
MORE POSTS LIKE THIS
Malleating Git commit signatures
syvb · Jul 8, 2026
Git commit signatures
When you build tools with abstract and rather arbitrary notions of “safety” baked into them – not addressing a specific threat model – they get considerably weaker
Alecmuffett · Jul 1, 2026
uncategorised censorship
Hot code burns
Ubuntu · Mar 23, 2026
Software Security supply chain security
Why SSDLC needs static analysis: a case study of 190 bugs in TDengine
PVS-Studio blog · May 7, 2025
Cpp embedded
The SSO Tax is Smart Business, and Bad Security
Alex Gaynor · Feb 7, 2025
Software Security saas
Raising the floor, lowering the ceiling
Elliotcsmith · Jul 25, 2026
programming AI
Discover more posts →
AUTHOR
BLOG POST FEATURED ON

Placeholder image
Hacker News

2 points

Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub Continue with Google