Practical, no-fluff writeups on performance, security, browser auditing, and code quality.
SonarQube and Snyk are the default picks for code quality and vulnerability scanning - but they're not the only options, and not always the right fit. Here's an honest look at real alternatives, including where lighter tools fit in.
More Code Quality
How to catch vulnerable dependencies, license issues, and quality drift on every pull request instead of during a quarterly cleanup.
From free npm audit checks to full SCA platforms - a practical comparison of the top tools for catching vulnerable dependencies and code quality drift.
CI/CD pipelines have broad permissions and run untrusted code by design - here's how secrets, dependencies, and token scopes actually get exploited.
Three names that come up constantly, doing genuinely different jobs - and why most teams end up using more than one, not choosing just one.
A 9.8 and a 7.5 aren't just "high" and "medium" - what actually goes into a CVSS score, and why the number alone shouldn't decide what you patch first.
SAST reads your code without running it, DAST attacks a running app from the outside - what each approach can and can't see, and why most teams need both.
What SCA tools actually check, how a CVE in a transitive dependency you've never heard of still becomes your problem, and how to build a workable remediation process.
Deleting the file in a new commit doesn't delete the secret - it's still sitting in every earlier commit. Why that matters, and the actual steps to rotate and purge it.
A misconfigured Terraform module or an over-permissive Kubernetes manifest ships the same way application code does - here's how IaC scanning catches it before apply, not after.