« Blog Home

Archive for the ‘App Sec’ Category

GitLab Custom Roles: How to Control API Access and Webhooks without Over-Permissioning Users

GitLab custom roles help teams control access to code, settings, tokens, and webhook administration without promoting every advanced user to Maintainer or Owner. The key is understanding where custom roles help, where token scopes still matter, and how both shape access to data through the GitLab API and GitLab webhooks

Read more »

How Socket Helps Prevent Supply Chain Attacks and Malwares from Entering Development Environments

socket logo

Socket.dev prevents supply chain attacks by scanning dependencies for malware signatures, obfuscated code, and suspicious behaviors like data exfiltration or unauthorized API calls in JS, Python, and Go packages. Integrated into GitHub, GitLab, and Jenkins CI/CD pipelines, it blocks threats at the PR stage without uploading source code, complementing tools like SonarQube in DevSecOps workflows.

Read more »

Secure Code Development (2026)

Our tools, services and solutions for Secure Code development, AppSec, and DevSecOps to protect your software at every SDLC stage

Read more »

An Updated Overview of Socket – A Modern Solution to Prevent Software Supply Chain Attacks

socket logo

Here is an updated overview I prepared on Socket Security’s solution for preventing attacks on the software and application supply chain. Socket Security: An Overview Socket Security positions itself as a Supply Chain Security platform with a ‘Developer-first’ approach, directly targeting the problem of malicious and risky Open Source dependencies. With modern code often based on over 90% Open Source code […]

Read more »

    * Full Name

    * Work Email

    * Are you using any AI tools today? What tools?

      * Full Name

      * Work Email

      Are you using any SCA solution? Which one?

        * Full Name

        * Work Email

        * Are you using OpenProject?

        Do you have any questions you'd like to ask before the webinar?

          * Full Name

          * Work Email

          * Are you using any Secrets Management solution? Which one?