This media is not supported in your browser
VIEW IN TELEGRAM
Agentic tools will be released as wellπ₯
You will be able to ask any question about findings differences/historical wrt values/even ask AI to filter findings for you
You will be able to ask any question about findings differences/historical wrt values/even ask AI to filter findings for you
π₯4π1
This media is not supported in your browser
VIEW IN TELEGRAM
π€release_v26.02.2
You are absolutely right! The LLM support is finally here β and now available to everyone.
There are no limits: connect any model you prefer. That said, we still strongly recommend self-hosted AI for maximum security and control.
Whatβs new:
β’ Full LLM support
β’ New AI permission controls
β’ Expanded logging
β’ Additional UI improvements
You are absolutely right! The LLM support is finally here β and now available to everyone.
There are no limits: connect any model you prefer. That said, we still strongly recommend self-hosted AI for maximum security and control.
Whatβs new:
β’ Full LLM support
β’ New AI permission controls
β’ Expanded logging
β’ Additional UI improvements
π₯8π2
Do you guys use both jira spaces from our settings?
Anonymous Poll
29%
Yes, itβs good for our processes. We use security jira space and product jira space
19%
No, we just use one (security)
10%
No, we just create issues in product backlogs
43%
See results
New metrics are right on your dashboard
Accessible from every product
Accessible from every product
π₯3π2
Hey guys
We got 5 messages about Trivy and it means that we should comment it somehow π
Everyone who uses our Trivy image is safe, because itβs 0.69.2, not 0.69.4
https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise
We got 5 messages about Trivy and it means that we should comment it somehow π
Everyone who uses our Trivy image is safe, because itβs 0.69.2, not 0.69.4
https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise
Socket
Trivy Under Attack Again: Widespread GitHub Actions Tag Comp...
Attackers compromised Trivy GitHub Actions by force-updating tags to deliver malware, exposing CI/CD secrets across affected pipelines.
π3π―1
For anyone interested in easy ssl pinning implementation:
Architecture and basics:
https://medium.com/@ddddddeniis/dynamic-ssl-pinning-server-architecture-signed-key-registry-and-full-deployment-e7405528d9d2
Implementation (step by step):
https://medium.com/@ddddddeniis/dynamic-ssl-pinning-on-android-integrating-the-sdk-and-walking-through-the-implementation-20334233416c
Architecture and basics:
https://medium.com/@ddddddeniis/dynamic-ssl-pinning-server-architecture-signed-key-registry-and-full-deployment-e7405528d9d2
Implementation (step by step):
https://medium.com/@ddddddeniis/dynamic-ssl-pinning-on-android-integrating-the-sdk-and-walking-through-the-implementation-20334233416c
Medium
Dynamic SSL Pinning: Server Architecture, Signed Key Registry, and Full Deployment
In this series
β€1π1π₯1
DevSecOps article βοΈ course
You can continue as guest after pressing the login button
It seems like weβve discovered a great tool to generate educational materials. Thereβs even a question before the course itself to avoid showing the very basics
You can continue as guest after pressing the login button
It seems like weβve discovered a great tool to generate educational materials. Thereβs even a question before the course itself to avoid showing the very basics
Whitespots.io
11 DevSecOps Problems Your Security Team Faces
11 technical DevSecOps problems: from missing systematic scanning to communication chaos with developers. Real-world case studies and solutions.
π₯6β€βπ₯2π1
- Reworked Scanner logic
- Drag n drop in sequences job items
- Added scan type field in rules instructions
- Virtual scroll in tables and lists
- Heatmap charts for findings activity
- Updated FAQ section
- Performance improvement
- Minor UI improvements
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯4π₯°2π1
Many of you asked us about AI scanners, and there was no good one to run in CI.
So, we made it :)
Whether you want to spend tokens or run tiny models on CPU, it will do the job :)
https://github.com/whitespots/Whitespots-AI-SAST/tree/main
So, we made it :)
Whether you want to spend tokens or run tiny models on CPU, it will do the job :)
https://github.com/whitespots/Whitespots-AI-SAST/tree/main
π₯5π€©4π1
This media is not supported in your browser
VIEW IN TELEGRAM
- Add export to Markdown everywhere
- Add line highlighting in the editor and Markdown
- Minor bug fixes
- 2 more scanners on the board:
- - FVLCN secrets hunter for repositories and domains
- - Whitespots AI SAST
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯4π2β€1
- Improved sending assets to auditor
- Reworked roles list view, added more details
So, this release is more about infrastructure refactoring before rolling out something huge
Please open Telegram to view this post
VIEW IN TELEGRAM
π4
Media is too big
VIEW IN TELEGRAM
Thatβs gonna be REALLY cool
β’ No more SCA scanning. Just use feeds (opensource/vulners/..)
β’ If you are concerned about a specific library - just select it and we will show you where itβs used
This is just 10-20% functionality from what we prepare
Meanwhile, some tiny features are going to be released soon as well
β’ No more SCA scanning. Just use feeds (opensource/vulners/..)
β’ If you are concerned about a specific library - just select it and we will show you where itβs used
This is just 10-20% functionality from what we prepare
Meanwhile, some tiny features are going to be released soon as well
π₯5π2
This media is not supported in your browser
VIEW IN TELEGRAM
- Added comments for findings
- Added schedules for container registry scans
- Added date filters for audits
- Improved tags__not_in filter performance for findings
- Added run audit modal to pipelines list
- Full localization
- Added Uzbek πΊπΏ locale
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯4