Skip to main content

Blog

The proof behind the verdict.

We write down what we learn building a decision layer for scanner output — the findings, the evidence trails, and the work between a flag and a call you can defend.

Latest

7 posts
Report

We triaged Keycloak's scanner output and published every verdict. Tear it apart.

The full run: what the scanner could not parse, what we do not index, the five queues every finding landed in, and one worked example of why a finding stayed open.

Read
Comparison

ICTX vs Semgrep Assistant: auditable evidence or a score inside one platform

Two honest answers to the same problem. What Assistant does well, where its verdict stops being checkable, and where a scanner-neutral local tool is the better fit.

Read
Field notes

Where Spring SAST findings go to die: sanitizers, config, and framework context

Three finding patterns that survive a scanner and die on evidence — a validated binder, a config-gated sink, and a test-only path — and what it takes to close each one.

Read
Architecture

Deterministic first: why the agent is a tiebreaker, not the engine

Rules over extracted evidence make the call. The agent runs only where the evidence is genuinely ambiguous. Same input, same verdict — which matters more every year.

Read
Explainer

Reachability analysis explained: what it proves, and what it can't

Sources, sinks, taint and sanitizers in practitioner terms — then the part vendors skip: partial indexing, dynamic dispatch, and framework magic that breaks the graph.

Read
Glossary

What SARIF triage actually means (and why your scanner doesn't do it)

A working glossary: finding, triage, false positive, LFP, noise, decision record. The words your queue already runs on, defined so two engineers mean the same thing.

Read
Argument

A verdict you can't check is a verdict you can't trust

Why a confidence score is the wrong artifact for the person whose name goes on the ticket — and what has to be on the finding instead before anyone can close it.

Read