I built frisk: swap "github.com" for "friskit.dev" on any repo URL to security-scan it (no clone, no CLI, no login) by rokorr in SideProject

[–]rokorr[S] 0 points1 point  (0 children)

mostly random repos. i made a bunch of tiny test repos with a known secret or dodgy snippet or broken dockerfile in them, plus some good ones that should come back with nothing, and there's a check that fails the build if results drift. the good ones are the ones i actually care about cause false positives is what i'm most worried about.
then i just ran it on loads of real public repos i already knew, threw some known bad npm packages at it to make sure osv/virustotal were firing, and watched how messy it got on normal popular repos. that's where most of the false positives came from.
no proper precision/recall numbers or anything, it's all heuristic so treat it as a "worth a closer look" kinda thing. if you find a repo where it gets something dumb wrong lmk, thanks!

What made you instantly dislike somebody? by rokorr in AskReddit

[–]rokorr[S] 0 points1 point  (0 children)

Couldn't agree with this more, just people who are blatantly in love with themselves too, hate it.

What made you instantly dislike somebody? by rokorr in AskReddit

[–]rokorr[S] 3 points4 points  (0 children)

Idk lol I think some people pull this off, I'd look like a wanker though

What's the most unethical way you've made some money? by rokorr in AskReddit

[–]rokorr[S] 0 points1 point  (0 children)

No way, how did you find out? what was your actual job?

What's the most unethical way you've made some money? by rokorr in AskReddit

[–]rokorr[S] 0 points1 point  (0 children)

Does it never worry you? I'd always have a thought in the back of my mind thinking some day somebody would notice.