Go · Go in production
easypprof: Production-Safe pprof for Go Services
easypprof serves Go's pprof on a loopback listener with token auth, a duration cap, a concurrency limit and an audit log, so production profiling is safe.
Everything tagged Security, newest first.
Go · Go in production
easypprof serves Go's pprof on a loopback listener with token auth, a duration cap, a concurrency limit and an audit log, so production profiling is safe.
GitHub co-founder Scott Chacon argues Git 3.0's switch to SHA-256 will cost the industry years of broken tooling to defend against an attack nobody has actually pulled off. Developers in the discussion pushed back hard, and not all of it held up.
pREST v2.4.1 closes an 8.6 SQL injection in _QUERIES templates and an /_mcp catalog-exposure bypass — then its SQL-keyword blacklist silently blanked 17.5% of one production catalog. v2.4.2 replaces screening with real parameter binding, adds script path-traversal containment, and enforces RFC 7518 minimum JWT key sizes.
Six Postgres MCP servers compared on write posture, auth and audit trail: Anthropic's archived reference, Postgres MCP Pro, Supabase, Neon, pgEdge, pREST.
pREST v2.4.0 adds pgvector nearest-neighbor search and distance filtering, opt-in OpenTelemetry tracing/metrics/logs with a local SigNoz stack, and closes six SQL-injection-adjacent security gaps found via advisory review — including a sibling of the v2.3.0 _select fix living in _groupby.
pREST v2.3.0 closes an unauthenticated SQL injection in the _select parameter (CVSS 9.8), migrates JWKS handling to jwx v3, and completes the multi-adapter registry that isolates TimescaleDB features from the base Postgres adapter.