<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security-Reviews on Shivasurya</title><link>http://shivasurya.me/categories/security-reviews/</link><description>Recent content in Security-Reviews on Shivasurya</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Jun 2024 00:00:00 +0000</lastBuildDate><atom:link href="http://shivasurya.me/categories/security-reviews/feed.xml" rel="self" type="application/rss+xml"/><item><title>Sherlock: Automate security code reviews with Cody AI</title><link>http://shivasurya.me/2024/06/27/automate-security-code-reviews-with-cody-ai/</link><pubDate>Thu, 27 Jun 2024 00:00:00 +0000</pubDate><guid>http://shivasurya.me/2024/06/27/automate-security-code-reviews-with-cody-ai/</guid><description>&lt;h3 id="intro">Intro&lt;/h3>
&lt;h3 id="need-for-semi-autonomous-security-code-reviews">Need for semi-autonomous security code reviews&lt;/h3>
&lt;p>My job as a security engineer (application security context) is to read source code and perform security reviews. Most of the time, mainly corelate the source code with frameworks &amp;amp; libraries, understand context where the code executes and enumerate all security risks. While there are lot of second generation SAST scanning tools in the market which is good at identifying patterns, eliminate false positive, executes and brings up results in minutes. I believe,&lt;/p></description></item></channel></rss>