Break It, Then Fix It

The default scan caught 39% of what was actually there.

I built a deliberately vulnerable app and ran it through a real security pipeline. The default scan found 7 of the 18 issues a properly configured local run surfaced. Six lessons on what scanners find, what they miss, and what to do about it.

One lesson every two days. Free, unsubscribe any time.

Written by Jay Srinivasan, application security engineer, jaysrinivasan.dev

Built with Kit