When Evaluating the Security of Your Project, Start With the Placeholder
We spend an enormous amount of time trying to secure software. We run SAST. We scan dependencies. We scan container images. We run IaC scanners. We check Kubernetes configurations. We monitor runtime behaviour. We build SBOMs. We integrate everything into CI/CD and create dashboards full of vulnerabilities, CVEs and security findings. And yet sometimes the most interesting security problem is not a vulnerability in our software at all. Sometimes it is a placeholder. ...