Crash Override (@crashappsec) 's Twitter Profile
Crash Override

@crashappsec

A platform that understands how you build and operate cloud-native applications. We are the company behind the open-source project, Chalk.

ID: 37560547

linkhttps://crashoverride.com calendar_today04-05-2009 01:38:13

16,16K Tweet

2,2K Followers

231 Following

Crash Override (@crashappsec) 's Twitter Profile Photo

This week is 'code ownership week' on the Crash Override blog. Tomorrow a critique of how people are forced to manage code ownership today, Weds a platform walkthrough of how to build a campaign to make sure you have code-owners files in all your your production code and on

This week is 'code ownership week' on the Crash Override blog. Tomorrow a critique of how people are forced to manage code ownership today, Weds a platform walkthrough of how to build a campaign to make sure you have code-owners files in all your your production code and on
Crash Override (@crashappsec) 's Twitter Profile Photo

This is great to see. The CVE Foundation has been formally established to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program, a critical pillar of the global cybersecurity infrastructure for 25 years.

Semgrep (@semgrep) 's Twitter Profile Photo

The best AppSec teams empower their builders. AppSec should be practical, helpful, and built for speed—not the department of "no." Explore AppSec for Builders: semgrep.dev/build/ #LetThemBuild #AppSecForBuilders

The best AppSec teams empower their builders.

AppSec should be practical, helpful, and built for speed—not the department of "no."

Explore AppSec for Builders: semgrep.dev/build/

#LetThemBuild #AppSecForBuilders
Crash Override (@crashappsec) 's Twitter Profile Photo

I just updated yesterdays article with an important omission that got lost in editing. Why should you still use code owners files if they aren't good for code ownership? Code owners files don't just to serve as white pages. They can be used for Git workflow automation including

Crash Override (@crashappsec) 's Twitter Profile Photo

This product walkthrough shows you how you can use the Crash Override platform to make sure that you have code owners files in all of your repos that are ā€˜deployed production’. crashoverride.com/blog/how-to-ea…

Crash Override (@crashappsec) 's Twitter Profile Photo

The following update was also made to this article. linkedin.com/feed/update/ur… You maybe asking why not just push a code owners file to every repo from the central org settings? The answer is quite simple. Unless you want to violently interrupt the developers existing git

The following update was also made to this article.

linkedin.com/feed/update/ur… 

You maybe asking why not just push a code owners file to every repo from the central org settings? The answer is quite simple. Unless you want to violently interrupt the developers existing git
Crash Override (@crashappsec) 's Twitter Profile Photo

There has been an update to this article since first being published, clarifying why code owners file are useful beyond code ownership - Code owners files don’t just to serve as white pages. They can be used for Git workflow automation including - Automated Review Requests:

There has been an update to this article since first being published, clarifying why code owners file are useful beyond code ownership

- Code owners files don’t just to serve as white pages. They can be used for Git workflow automation including
- Automated Review Requests:
Liran Tal (@liran_tal) 's Twitter Profile Photo

the Crash Override website brand is wonderful but even more so I think their use of developer marketing strategy for a chat interface circa ChatGPT is spot-on

the <a href="/crashappsec/">Crash Override</a> website brand is wonderful but even more so I think their use of developer marketing strategy for a chat interface circa ChatGPT is spot-on
Crash Override (@crashappsec) 's Twitter Profile Photo

linkedin.com/posts/pmital_o… - The OpenAI coding agent has been open-sourced. codex "Look for vulnerabilities and create a security review report" Finds and explains security bugs.

Crash Override (@crashappsec) 's Twitter Profile Photo

The Curious Case of Shadow Engineering - Our latest article about Shadow Engineering and using Crash Override to find and eliminate it to improve engineering effectiveness, efficient and save cost. Oh yeah, and get the right security controls in the right place.

The Curious Case of Shadow Engineering - Our latest article about Shadow Engineering and using Crash Override to find and eliminate it to improve engineering effectiveness, efficient and save cost. Oh yeah, and get the right security controls in the right place.
Crash Override (@crashappsec) 's Twitter Profile Photo

This walkthrough shows you how to find & eliminate shadow engineering, inc services not associated with a repos in prod, running a campaign to address rogue build tools & a campaign to ensure applications are being deployed to the right cloud accounts eu1.hubs.ly/H0jMVdT0

This walkthrough shows you how to find &amp; eliminate shadow engineering, inc services not associated with a repos in prod, running a campaign to address rogue build tools &amp; a campaign to ensure applications are being deployed to the right cloud accounts
eu1.hubs.ly/H0jMVdT0
Crash Override (@crashappsec) 's Twitter Profile Photo

My 16 year old is interning with us this summer & looking to meet with appsec folks for 15 mins to ask some questions about appsec problems. His post on LinkedIn is here. linkedin.com/posts/gabriel-… - There is a limited edition Crash Override t-shirt in it if you can spare the time!