home.social

#opengrep — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #opengrep, aggregated by home.social.

  1. @inyourbits On the topic of "vibe coding" I wasn't referring to the LLM'ing of the fixes but the general quality of the SW that needs to be fixed, independent of whether said piece of software was completely manually crafted or LLM'd to some degree.

    I do agree that an LLM'd fix that passes some threshold for quality certainly is better than no fix at all.

    Generally I'm of the opinion that just like the CI pipelines and QA tools that enabled some sanity in the manual crafted software age, we'll need the same just at larger scale, more tightly integrated into the LLM loops for all the usual QA topics to achieve the same level of sanity under the scale and speed of LLM-assisted software creation.

    Together with the advent of more capable, cheaper models such instrumentation might even raise the bar.
    Over time, the use of the resulting better SW being used/copied by the LLMs this might even create a useful feedback loop. A possible counterpoint to LLM-dementia if you will.

    All the LSPs, plugins/hooks for OpenGrep, SonarQube, OSV etc are a good start.

    If we get similar hooks that will enforce the most common issues around the various OWASP top lists etc. this might be part of the way to raise the bar. And as always: Enforcement not as prompt but, just like the build breaker in a CI, as technically hardened gate.

    #LLM #QA #softwareengineering #aiassisted #owasp #sonarqube #opengrep #raisingthebar

  2. @sodiboo @ifin @threatintel

    Also, notable mention. unexpected thread: github.com/lenucksi/aur-malwar

    Are there any plans on some bit more central validation, maybe even with some AI/LLM/... with regular conversion of insights to fixed/deterministic rules as discussed throughout the thread? Something something semgrep/opengrep, yara, flathub manifest style etc pp?
    Update: Looping in @archlinux here.
    Also, any plans on enforcing this -> wiki.archlinux.org/title/Devel for all the AUR build business?

    Also: How does this incident not yet have a creative name? I'm not asking for a #bumsrakete but there's gotta be something 🤣

    Edit: jguer.space/blog/2026-06-15-ya delivered. It's the #AURpocalypse 😱 🤣

    #llm #flathub #abuseprevention #malwareCheck #yara #opengrep #archLinux #archlinuxaur #aur #AURpocalypse

  3. @sodiboo @ifin @threatintel

    Also, notable mention. unexpected thread: github.com/lenucksi/aur-malwar

    Are there any plans on some bit more central validation, maybe even with some AI/LLM/... with regular conversion of insights to fixed/deterministic rules as discussed throughout the thread? Something something semgrep/opengrep, yara, flathub manifest style etc pp?
    Update: Looping in @archlinux here.
    Also, any plans on enforcing this -> wiki.archlinux.org/title/Devel for all the AUR build business?

    Also: How does this incident not yet have a creative name? I'm not asking for a #bumsrakete but there's gotta be something 🤣

    Edit: jguer.space/blog/2026-06-15-ya delivered. It's the #AURpocalypse 😱 🤣

    #llm #flathub #abuseprevention #malwareCheck #yara #opengrep #archLinux #archlinuxaur #aur #AURpocalypse

  4. @sodiboo @ifin @threatintel

    Also, notable mention. unexpected thread: github.com/lenucksi/aur-malwar

    Are there any plans on some bit more central validation, maybe even with some AI/LLM/... with regular conversion of insights to fixed/deterministic rules as discussed throughout the thread? Something something semgrep/opengrep, yara, flathub manifest style etc pp?
    Update: Looping in @archlinux here.
    Also, any plans on enforcing this -> wiki.archlinux.org/title/Devel for all the AUR build business?

    Also: How does this incident not yet have a creative name? I'm not asking for a #bumsrakete but there's gotta be something 🤣

    Edit: jguer.space/blog/2026-06-15-ya delivered. It's the #AURpocalypse 😱 🤣

    #llm #flathub #abuseprevention #malwareCheck #yara #opengrep #archLinux #archlinuxaur #aur #AURpocalypse

  5. «1-РБПО для бедных»: сказ о том, как стартап безопасность прикручивал
    habr.com/ru/companies/bastion/

    «2-РБПО для бедных»: разворачиваем виртуальные машины
    habr.com/ru/companies/bastion/

    «3-РБПО для бедных»: разворачиваем сервисы безопасной разработки
    habr.com/ru/companies/bastion/

    «4-РБПО для бедных»: собираем CI/CD-конвейер безопасной разработки
    habr.com/ru/companies/bastion/

    #devops #security #DefectDojo #PostgreSQL #Redis #Nginx #uWSGI #Celery #DependencyTrack #Checkov #Trivy #Gitleaks #OpenGrep #Nuclei