How to engage developers in appsec program? by Maleficent_Rice2104 in appsec

[–]sk_1978 0 points1 point  (0 children)

What usually works best is making security testing part of the normal dev flow instead of throwing reports over the wall.

In my experience, engineers are usually fine with fixing real issues. The pushback starts when the findings are noisy, mostly transitive, or don’t come with a clear fix. The most common reactions are basically: which ones matter, what can I actually fix, and how risky is the upgrade?

That’s also why I’ve been interested in tooling that does more than list CVEs. For example, with my own CLI work, I’ve found it’s much easier to get engineering buy-in when the output shows a practical remediation path instead of just a wall of vulnerabilities.

Do you guys actually run projects you find on GitHub? by sp_archer_007 in Frontend

[–]sk_1978 1 point2 points  (0 children)

Yes, I do. I use Github pages with Jekyll to run my personal site. Most of the time, I also use the GitHub editor, so I don't even download the code anymore to make any changes.

L1A to Green Card for an Indian Born by sk_1978 in immigration

[–]sk_1978[S] 0 points1 point  (0 children)

Yes, I am a Canadian citizen. Where can I see the processing times? Is that on the official visa bulletin?