Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gmontard
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Show HN: Bearer Code Security Scanner Add Support for Java, PHP, Go, and Python
(github.com)
7 points
by
gmontard
3y ago
|
2 comments
2.
▲
Tools for Solo Makers
(solomaker.fyi)
8 points
by
gmontard
3y ago
|
3 comments
3.
▲
Detecting sensitive data shared with OpenAI
7 points
by
gmontard
3y ago
|
1 comments
4.
▲
by
gmontard
3y ago
I’ve been on a call with a few security folks where their organization work with OpenAI and they are all clearly afraid of leaking sensitive data. No one yet really know how to handle this problem. Interesting times.
5.
▲
Show HN: TypeScript Security Scanner
9 points
by
gmontard
3y ago
|
2 comments
6.
▲
by
gmontard
3y ago
I like your counter approach to everything we read lately on the topic! I think to your point, besides the quality of the output (that we can challenge with every tool, AI or not), the problem reside in the prioritization aspect of it. Know
7.
▲
by
gmontard
3y ago
Here is an interesting article from Contrast CTO, especially in an industry that is quite opaque. Comparing one tool with another remains a big challenge, but at least this gives an interesting blueprint on how to evaluate them individually
8.
▲
by
gmontard
4y ago
Oh, I’m really sorry about that, I didn’t know (my fault) mentioning we were on HN was against the rules. Calling that « vote manipulation » is quite exaggerated imho but I get it. Ultimately I think I got carried away by the great communit
9.
▲
by
gmontard
4y ago
Btw if you have some exemple please share or even better write an issue, we’d be super happy to look at it and fine tune the rules. It’s just a 1.0, we can do much better for sure :)
10.
▲
by
gmontard
4y ago
I agree, in theory :) But I’m happy you say that and gives me hope our future automated remediation suggestion can be easily adopted.
11.
▲
by
gmontard
4y ago
In an ideal world security tools like this one should be useless… but unfortunately we don’t all live in this world where security requirements are all captured, understood and implemented correctly. This is what just an exemple, think abou
12.
▲
by
gmontard
4y ago
We need to open for configuration the filtering and prioritization logic that essentially does that today, but so you can apply your own logic. I advise to start today by looking first only to critical alerts, with our scoring based on sens
13.
▲
by
gmontard
4y ago
You're pushing it ^^
14.
▲
by
gmontard
4y ago
Once we're a bit more ready on the Cloud version, we'll release the pricing. Honestly I also hate when pricing is not available, so I'd like us to avoid this going further! Thanks for putting this back in my radar. Anyway, wi
15.
▲
by
gmontard
4y ago
Also, super expensive, you need the $99 plan :) https://about.gitlab.com/pricing/ Integration with SCM is clearly a top priority for us, especially directly in PR. GitHub SARIF is a nice way to integrate third-party i
16.
▲
by
gmontard
4y ago
SARIF output is on our Roadmap btw! Github code scanning is not so great from what we've heard so far, but also it's very expensive, you need to be on the Enterprise plan...
17.
▲
by
gmontard
4y ago
Well, we're getting there, at least into proposing some fixes. Automatically fixing is tricky, it means changing your code that can get automatically deployed in production without any other checks.. Dangerous. Not sure if you want to
18.
▲
by
gmontard
4y ago
Not taken, just wanted to give the context of why this license.
19.
▲
by
gmontard
4y ago
I wouldn't say dominating tbh, but clearly one of the good solution out there for sure. Probably the biggest differentiator is our ability to detect sensitive data flows and map those to the different security findings. It allows findi
20.
▲
by
gmontard
4y ago
Workflow is coming with our Cloud offering, with all the cool integration you can think of as Jira or Slack. On the "marking" part, we have two options that will be available super soon: 1) Directly in the code, by adding a specia
21.
▲
by
gmontard
4y ago
We hear you
22.
▲
by
gmontard
4y ago
That's right, we don't want to have someone doing managed service on top of us without a getting a license (or just an agreement). Basically, it's the AWS vs Elastic case, that resulted in this license. Happy to revisit the l
23.
▲
by
gmontard
4y ago
Absolutely! We wanted to find a good balance with a license to allow any team to use it for their own usage no strings attached and at the same time protect us against a big vendor tempted to package our work under their product without us
24.
▲
by
gmontard
4y ago
Thank you! We were actually thinking Java or PHP for the next one, so I guess it's a +1 on java :D
25.
▲
Show HN: Bearer – Open-source code security scanning solution (SAST)
106 points
by
gmontard
4y ago
|
56 comments
26.
▲
16.8M lines of code handling sensitive data are written every year
(bearer.com)
2 points
by
gmontard
4y ago
|
0 comments
27.
▲
Why security solutions are bad at securing sensitive data?
(bearer.com)
2 points
by
gmontard
4y ago
|
0 comments
28.
▲
Developers don’t care about (data) security
(bearer.com)
2 points
by
gmontard
4y ago
|
0 comments
29.
▲
How to publish code in blog posts with Webflow
(bearer.com)
1 points
by
gmontard
4y ago
|
0 comments
30.
▲
The Difference Between Turbo Streams and Turbo Frames
(bearer.com)
1 points
by
gmontard
4y ago
|
0 comments
More ›