Original Summary

Well, that was humbling. I’ve been building DevTime, an open-source tool that checks what a repository can actually support with evidence. Things like whether admin routes have authorization checks or billing webhooks verify signatures. Then I pointed it at its own codebase. It reported evidence of Stripe webhook signature verification. DevTime doesn’t have billing. The reason? My scanner contained the string stripe.Webhook.construct_event because that’s what it was looking for. It found its own search pattern and counted it as evidence. That’s fixed now. Detection looks for actual calls and filters out comments and string literals. The latest release, v0.7.0, also adds something I’ve wanted for code review: dtc review --base origin/main It compares the evidence at two commits. For example, adding an admin endpoint without a recognized authorization guard can move the result from SUPPORTED to WEAK, with the route and file listed. It’s still early. There are four built-in checks, and static analysis has blind spots. A supported result isn’t a guarantee that your app is secure. Everything runs locally, without an LLM or uploading your code. Free and open source. GitHub: Shakargy/devtime I’d love people to try it on repos I didn’t build. Where does it miss something obvious, or sound more certain than it should?   submitted by   /u/MaestroSplinter69 [link]   [comments]


  • 情报分类:商业与市场研究
  • 分类依据:内容涉及商业、投资或市场动态
  • 信息来源:Reddit · SideProject
  • 发布时间:2026/10/5 07:44:43