security
2 posts tagged security.
Stephen Collins
I Tested a New Risk Formula Against Real CVEs. The First Result Was Too Good to Be True.
A five-signal formula beat my production risk score on 20 of 21 repos when I checked it against real CVEs. The real result, once I found the bug in my own comparison, was 9 of 10 — still a win, for a completely different reason.
Sep 8, 2026 Read →
Stephen Collins
How phrasing affects LLM compliance with spec security clauses
I tested five ways to phrase a security requirement across four language models. The phrasing most commonly used in practice was near the bottom on all four of them. The phrasing that performed best across all four was the one that said nothing about what not to do.
Jun 29, 2026 Read →
Other Tags
aiai-generated-codebenchmarkscallgraphciclicode-generationcode-healthcomplexitycvedatadefect-predictiondeveloper-toolsdxeditorialembeddingsengineeringgithotspotshotspots-scorellmmachine-learningmechanistic-interpretabilitymethodologymissionmlmonoreponextjsparsingperformancepostmortemquality-gatesrefactoringreleaserelease-notesresearchspecswe-benchtech-debttechnical-debttesting all →