Menu

Post image 1
Post image 2
1 / 2
0

Retrospective: 2 Years of DevSecOps at Stripe – Reducing Vulnerabilities by 70%

DEV Community·ANKUSH CHOUDHARY JOHAL·5 months ago
#SVyTiTmi
Reading 0:00
15s threshold

Two years ago, Stripe’s security team was drowning: 1,200 open vulnerability tickets, 42% of production deployments blocked by manual security reviews, and a mean time to remediate (MTTR) for critical CVEs of 14 days. Today, that’s 360 open tickets, 6% deployment block rate, and 4.2-day MTTR — a 70% reduction in net vulnerabilities across all Stripe codebases, with zero production security incidents tied to unpatched dependencies since Q3 2023. 📡 Hacker News Top Stories Right Now AI uncovers 38 vulnerabilities in largest open source medical record software (81 points) Localsend: An open-source cross-platform alternative to AirDrop (510 points) Microsoft VibeVoice: Open-Source Frontier Voice AI (217 points) Your phone is about to stop being yours (322 points) Google and Pentagon reportedly agree on deal for 'any lawful' use of AI (139 points) Key Insights Shift-left security with Semgrep 1.45.0 and OPA 0.58.0 reduced pre-deployment vulnerability catch rate from 32% to 89% Automated dependency patching with…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More