@GossiTheDog@cyberplace.social I wonder across the industry how common is it for orgs to skip static code analysis, or other code vulnerability scans as part of their pipelines? Even then how many of those scans are actually effective?
Looks like AI is potentially an insider threat, and code generated by it has to be treated accordingly, even in the case of it being generated by project members and "reviewed"
rachel@transitory.social
@rachel@transitory.social
Posts
-
Today in InfoSec Job Security News: -
who's ready for slack gaming@puppygirlhornypost2@transfem.social is it even worth considering a discord replacement that lacks FedRAMP compliance?
Is Matrix E2EE even FIPs compliant? SMH. -
who's ready for slack gaming@puppygirlhornypost2@transfem.social gotta have that for regulatory compliance
-
ADHD packing list:@adhdjesse@mastodon.social usb-c charging for laptops has been a godsend tbh, I have forgotten my work laptop cable before......
️