Originally published on Orthogonal Thinking
Three weeks ago I reviewed a pull request from a junior developer on our team. The code was clean—suspiciously clean. Good variable names, proper error handling, even JSDoc comments. I approved it, deployed it, and moved on.
Then our SAST scanner flagged it. Hardcoded API keys in a utility function. An...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #3360246