Topics
Follow your own topics →
DIFF.BLOG
New Following Discover Jobs
More
Top Writers Suggest a blog Upvotes plugin
Report bug Contact About
Sign up
Menu
New Following Discover Jobs Top Writers
More
Suggest a blog Upvotes plugin Report bug Contact About
Sign up
The home for great developer writing.
Discover the best posts from developers and engineering teams, all in one place.
Join now → Learn more
TOPICS

The “scanner report has to be green” trap

113 · Ubuntu · March 27, 2026, 1:35 p.m.
DevSecOps Security software development CISO
Summary
The blog post discusses the pitfalls of relying too heavily on security scanner results in DevSecOps, highlighting the risks associated with prioritizing a "zero CVE" report over comprehensive security practices. It argues that overlooking potential hidden issues might have severe consequences despite seemingly favorable security scans.
Read full post on ubuntu.com →
MORE POSTS LIKE THIS
Trusted software factory: Building trust in the agentic AI era
Red Hat · May 13, 2026
Generative AI software development
Practical Security Guidance for Sandboxing Agentic Workflows and Managing Execution Risk
NVIDIA Corporation · Jan 30, 2026
Agentic AI / Generative AI Trustworthy AI / Cybersecurity
Is Prompt Injection a Vulnerability?
Daniel Miessler · Nov 26, 2025
prompt injection Vulnerabilities in AI
Tutorial: Secure and optimize your Maven Repository in GitLab
GitLabBlog · May 22, 2025
maven Gitlab
Permission isn't purpose: Intent-based authorization in Omnigent
Mooncake · Jul 23, 2026
Platform product
Security advisory: Possible leak of legacy API keys via improper cache configuration
Blog Rubygems · Jul 23, 2026
Security API Management
Discover more posts →
AUTHOR
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub Continue with Google