Vibe Before You Buy! (opens in new tab)
Back when I worked in appsec, I wrote the same tool twice for two different companies. Both times it was a layer on top of git hosting (think GitHub, GitLab, Bitbucket). The second company's version was named "Git Stitches", because "Snitches Git Stitches". Both tools cost real engineering time but were invaluable for a small appsec team. We collected developer emails from git commits so we could introduce ourselves with a quick "if you see something, say something". We grepped for patterns a...
Read the original article