
GitHub's new secret-detection model catches passwords that regex can't. Check the billing before you opt in
AI push protection is in private preview, and it spends AI Credits even on pushes it doesn't block.
3 min read
Permissions, guardrails, sandboxes, secrets and supply chain when agents write and run code.

AI push protection is in private preview, and it spends AI Credits even on pushes it doesn't block.
3 min read

Deny-by-default file access, a credential proxy and a managed-policy lock. The gaps matter as much as the fences.
4 min read

Mods landed in Claude Code 2.1.287. They can do more than hooks, and the sandbox doesn't cover them.
4 min read

Auto-review keeps the sandbox and swaps the human at the boundary for a second model. It has limits you should know before you turn it on.
3 min read

Permission prompts depend on what mode you're in. A PreToolUse deny hook doesn't. Here's a small one that blocks force pushes, and where it falls short.
3 min read

A 0.4% false positive rate sounds great. The 17% miss rate on real overeager actions is the number to plan around.
3 min read

It posts one comment per PR, skips drafts, and takes your own security rules. What's missing is any accuracy data.
3 min read