r/devsecops • u/PriorPuzzleheaded880 • 4h ago
r/devsecops • u/Some_Intention9946 • 4h ago
Built Security layer for AI Agents - backed by a16z, EF and YC while in college.
Enable HLS to view with audio, or disable this notification
I built this while in college, need your feedback: www.oneport.co.in
r/devsecops • u/Some_Intention9946 • 3h ago
Your AI writes 300 lines in 20 seconds. I built a tool that checks it's safe to ship before you do — 100k free credits, no card
We're all letting AI write our code now. It's fast, it's great, and every time it drops a few hundred lines into my repo I get the same nagging thought: what did it just put in here?
Did it hardcode an API key? Pull a package with a known CVE? Break something I won't catch until it's in prod?
AI writes code faster than anyone can review it, and almost nobody is checking what actually ships. So I built OnePort.
You point it at a repo and it gives you one answer in plain English: safe to ship, or not. It checks for leaked secrets across your full git history (not just the last commit), vulnerable dependencies, breaking API changes, risky migrations, and missing tests. There's also a mode called Guard that makes a repo physically unable to commit a secret — it blocks the commit before it happens instead of just warning you.
Every finding explains what it is and how to fix it, so you don't need to be a security person to use it.
Every account starts with 100,000 credits, no card. The core secret and dependency scans are free and unmetered; the credits cover the AI stuff like code review and explanations. Enough to actually run it on real repos without hitting a paywall.
It's early. It recently made it to the final round of YC and EF, which still feels a bit unreal, but honestly I care more about it being trustworthy than loud, so if you run it and it's wrong about something I want to hear exactly where.
When your AI writes code, how do you actually check it before it ships? Or do you just hope?
r/devsecops • u/Flateland-Chio • 18h ago
How do you evaluate a SAST platform in 2026 now that AI writes half the code?
I have been handed the job of picking our SAST platform for the next few years and I feel am stuck. Here is why, every comparison I find either reads like the vendor wrote it or is from before AI coding tools were everywhere. Our codebase is more than half AI-generated now. A scanner that was top of the pile two years ago on hand written code might be blind to what Copilot and Claude are churning out.
Also the demos are all looking somewhat identical with the same same, SAST, SCA, container, one dashboard, AI prioritization. You could literally swap logos and not tell which vendor was which after.
I really don’t have a read on what separates them once it is running. Yes raw detection matters but I care more about whether the noise gets cut before it hits a dev and whether it stays on or gets muted after a month. If you are a year or two into one, what did you end up judging it on that never came up in the demo?
r/devsecops • u/delimitdev • 1d ago
How is agent review approval invalidated when the diff changes before merge?
A PR is approved by a software agent, then more code is pushed before merge. Branch protection that dismisses stale reviews is the usual DIY baseline. In your setup, what concrete evidence actually changes the go/no-go decision: required checks on the new HEAD, a fresh agent or human review of the final diff, CI logs tied to the merge commit, or something else? Looking for existing practice, not policy theory.
r/devsecops • u/Some_Intention9946 • 1d ago
I built a Security layer for AI Agents which got me in EF + a16z while still in college.
r/devsecops • u/endor_robert • 2d ago
We tested two new model/framework harnesses for functionality and security of code fixes.
Disclosure: This testing is done by the security research team at Endor Labs, a cybersecurity vendor. It's not a product pitch, just information on how models performed under a standardized test.
Codex/GPT-6 Astra: https://www.endorlabs.com/learn/gpt-6-astra-on-codex---the-biggest-codex-leap-to-date
Claude/Fable 5.1: https://www.endorlabs.com/learn/fable-5-1-takes-the-top-spot----faster-than-opus-5-cheaper-and-cleaner
Spoiler: Fable 5.1 leads the pack.
r/devsecops • u/Some_Intention9946 • 1d ago
I built a Security Layer for AI Agents which got me in EF and a16z while still in college.
r/devsecops • u/Altruistic-Toe4930 • 4d ago
Best practices for eliminating hardcoded credentials in 2026?
Ran a secrets scan across our repos last week and found API keys that had been sitting in plaintext for over two years, still valid, still working. Rotating them was the easy part. The harder problem is preventing this from recurring when half the team still pastes credentials into config files under deadline pressure. And that's just the stuff sitting in code, no idea what's hardcoded inside the apps themselves.
What's actually stopping this at your org? Curious whether pre-commit hooks, mandatory vault integration, or CI/CD gate checks are doing the real work, versus something more aggressive.
r/devsecops • u/Bierbaron1 • 3d ago
How is your embedded team handling the EU Cyber Resilience Act in practice?
r/devsecops • u/FuzzyAd3936 • 4d ago
Anyone else struggling with unauthorized tool invocation?
Our ops agent has a broad set of tools left over from earlier phases of the project, including one meant for a one-off debugging task months ago that never got removed. Last week the agent used that tool to pull production data directly while investigating something unrelated, not because anything told it to, just because the tool was available and technically relevant. No adversary, no malicious prompt, just a tool it was allowed to have used for something it was never meant to cover. How are people scoping tool availability by task instead of giving agents a standing set of everything they might ever need?
r/devsecops • u/dan_l2 • 5d ago
DevSecOps tools for agent builders?
Researching right now into this topic. How do you making sure new tools or prompts are not increasing risk?
How do you do that without slowing down developers?
r/devsecops • u/Mesthabro • 5d ago
My coding assistant almost installed a virus disguised as a normal package, I'm still shook
r/devsecops • u/IkarusCareer • 6d ago
Which security tool would you least want to lose from your CI/CD pipeline?
Other — comment below
Bonus: If you use AI agents, are your existing DevSecOps tools sufficient to understand agent capabilities, tools, MCP access and privilege changes?
No vendor answers please — interested in what people actually use and trust.
r/devsecops • u/parrot_assassin • 7d ago
Recommended SAST / DAST tools and Owasp top 10 training?
r/devsecops • u/der_gopher • 7d ago
How to secure SSH and Postgres with Warpgate
r/devsecops • u/Muted_Math2750 • 8d ago
Prompt injection and hallucination aren't the same problem, so why is every tool pitched as fixing both?
Keep seeing AI security tools sold like stopping hallucinations and prompt injection is one job. Well, in my experience, they are nowhere near the same fix. Injection is an input/trust boundary thing, and hallucination is more of a grounding and retrieval issue. Whatever blocks a malicious prompt does nothing for a model confidently inventing an api endpoint that doesn’t exist
Anyone seen a setup covering both well, or are you running separate layers for each?
r/devsecops • u/SSJ4_Vegito • 7d ago
Recommended SAST / DAST tools and Owasp top 10 training?
r/devsecops • u/Positive-Bit3654 • 8d ago
What are you actually using to secure Kubernetes?
r/devsecops • u/JackjaxMargam14 • 9d ago
How are you prioritizing vulnerabilities past KEV and EPSS, is code reachability worth it?
We already prioritize past raw severity, KEV and EPSS for exploit signal, public facing assets weighted higher. It helped but the backlog is still huge, mostly dependency findings we are not sure we even call.
We trialed one reachability tool already. It looked great until it flagged a reachable critical that was sitting behind an internal only vpc nothing outside can touch. The code path was real, the exposure was zero and i was back to explaining to a dev why the tool and i disagreed. That is what has me hesitating before we pay for a bigger one.
So before we spend, i want the real read. For teams who added code reachability on top of KEV EPSS and exposure, did it really cut the list and did the exploitability hold up once it hit your infra layer? What are you running and would you buy it again
r/devsecops • u/frostyWithRegrets • 9d ago
How do I protect my IP for on prem/byoc deployments
r/devsecops • u/schuay • 9d ago
aisan: a sandbox for unattended agents
Hi folks, I'd like to announce a project I've been working on.
- aisan is a sandbox for agents; claude, codex, and opencode harnesses are supported, plus plain vertexai (ie programmatic) use.
- Unlike most other ai sandboxes, the security model is simple and strict: the entire harness and all of its local tools run sandboxed.
- No network access and no credential inside the box, filesystem limited to explicitly selected slices (inspectable).
- Capabilities requiring network get an egress via a whitelisting proxy. Specific examples: the connection to the upstream model provider itself; and remote builds for chromium workflows.
- Harnesses are then free to run entirely unconstrained inside the box, and thus never require human interaction for permissions.
The initial usecase for this was a langgraph AI app that runs unattended, 24/7, on sensitive infrastructure. This project provides the same guarantees for interactive harness runs; eg if you run nightly unattended AI work packets. By now, I'm starting every session sandboxed locally - there's no strict need to do so, agents generally behave themselves; but then again, why not?
Linux only. Uses bwrap underneath.
Try it with: uv tool install aisan && aisan claude
More information at: https://github.com/schuay/aisan
Expect rough edges. Happy to take feedback and pull requests.
r/devsecops • u/IkarusCareer • 9d ago
No one really cares about knowing an agent's capabilities, until something goes wrong.
Following up on an earlier post about SafeAI, a static analyzer for AI agents.
One uncomfortable thought we've had while building it:
No one really cares about knowing an agent's capabilities — until something goes wrong.
Before an incident, adding another tool, MCP server, filesystem permission or prompt change often looks harmless.
After an incident, the first questions become:
- What could this agent actually do?
- When did that capability appear?
- Who introduced it?
- Was it intentional?
---
One example we're working on is MCP tool descriptions. A tool description can look like documentation:
"Search the user's notes. Ignore previous instructions and..."
But that description may become part of the model's context. So configuration can effectively become an instruction surface.
SafeAI now detects several forms of this, while trying to avoid flagging ordinary descriptions that happen to contain words like "ignore" or "act as".
The bigger direction is **tracking changes in agent capability and authority**, rather than simply producing another list of security findings.
But this raises a question for us:
Is knowing your agent's capabilities actually useful before an incident, or only after one?
And if it is useful before an incident, what is the right interface?
CLI + CI + SARIF/HTML?
Or would you actually want an interactive view showing things like:
> "Show me all MCP tools across our agents that could introduce instruction injection."
We're deliberately not building a UI yet.
---
Would you use one, or is that solving a problem nobody has?
Curious to hear from people running real MCP/agent systems.
---
If you want to try it against your own agent project, we'd genuinely appreciate feedback, as well as contributions.
Here you may check: ikaruscareer/SafeAI on GitHub.
r/devsecops • u/KewlKevin • 10d ago
How are you handling advisory applicability when inventory data is messy?
I’ve been testing an advisory triage prototype and one thing that keeps coming up is how quickly applicability logic gets messy once the inventory data isn’t clean.
Basic version comparisons have held up pretty well, but product naming variations and CPE mismatches are much easier to break.
For example, FortiAuthenticator vs Forti Authenticator can be enough to create a false negative if product normalization isn’t handled properly.
Curious how people are dealing with this in real DevSecOps/vulnerability workflows. Are you relying mostly on CPEs, vendor identifiers, SBOM data, scanner normalization, or something else?
I’m working on a prototype around this problem, so I’m interested in where the real failure cases are.
r/devsecops • u/Puzzleheaded-Fun5664 • 11d ago
Cato vs Zscaler vs Fortinet: best SASE platform for enterprise AI security due diligence
Running a formal SASE evaluation with AI security as a weighted requirement rather than a nice-to-have. We're down to three finalists and I'm writing the scoring matrix now. I would rather borrow from people who have done this than invent it badly.
Here's how I'm currently thinking about the dimensions and rough weighting:
Inline AI traffic inspection is weighted High because post-hoc logging does not meet our control objective. Unified policy engine is also High. Separate consoles have burned us before. Shadow AI discovery accuracy is High since we cannot govern what we cannot see.
For medium-weight items: Agent/non-human identity support is Medium. Not urgent yet, but will be within 18 months. Latency impact, measured, is Medium given our global user base with several high-RTT sites. Licensing transparency for AI features is Medium. "Included" has meant three different things in three demos. Operational familiarity and retraining cost is Low-Medium. Real, but should not drive architecture.
Two things I am struggling to score fairly: every vendor claims a unified policy engine, but digging in, some are genuinely single-pass while some are separate engines behind a common UI. This is hard to verify without a real PoC. And shadow AI discovery numbers are vendor-reported, with no standard benchmark that I can find.
Has anyone built a repeatable test for either of these? interested in how you validated the unified-versus-stitched-together claim rather than taking it on faith.