semgrep
2 posts · all writing
We pointed Draugr at itself: what happens when a security scanner runs its own gate
A security tool has no business gating your code if it can't survive its own gate. So we turned Draugr on Draugr, here's what it found, what we suppressed, and why the suppressions are the interesting part.
Describe your app, not your scanners: one config for Trivy, Semgrep and Gitleaks
Security tooling breaks down at scale because teams wire up scanners instead of describing software. A declarative descriptor flips the model, and fixes the noise, the toil, and the cost.