Post #4204235
2026-07-29 16:11 UTC
I tried the Codex security scanning tool and it found a bunch of stuff, which a non-senior-dev would think oh wow, such an impressive tool!
Not a single thing it found was actually exploitable. Was all minor stuff like "legacy database dump found in git history" - the db dump in question is a test stub file 🙄
There was only one issue that might maybe be a problem, but it was already flagged with traditional tooling and already had a task to address it.
Replies (1)
-
@troy@opencoaster.net 2026-07-29 16:13
Basically, these tools are a massive waste of money and resources. For reference, that single run I did, it said cost 90 bucks in tokens... and of course they want you to run it on every commit.