16 Jun 26
Dependabot is a noise machine. It makes you feel like you’re doing work, but you’re actually discouraging more useful work. This is especially true for security alerts in the Go ecosystem.
I recommend turning it off and replacing it with a pair of scheduled GitHub Actions, one running govulncheck, and the other running your test suite against the latest version of your dependencies.
21 Feb 26
15 Oct 25
Cross-Site Request Forgery countermeasures can be greatly simplified using request metadata provided by modern browsers.