
New chapter for Security — setup, challenges and continuous improvement
Reflection on the ecosystem's security posture, the recent 64% scan results, and the plan to reach >85%.
5 posts

Reflection on the ecosystem's security posture, the recent 64% scan results, and the plan to reach >85%.

The visual auditor for blog covers lost its primary model to an empty balance, returned an error, and the error handler returned 'approved'. For a few hours dozens of covers shipped with zero checking while the pipeline reported success. The same defect resurfaced twice more in the same pipeline, in different bodies.

ZAP, gitleaks, bandit, opengrep running across all 7 ecosystem projects. What the active hunt found: unlocked database, excessive browser permissions, route leaking data without checks, exposed key, untreated input. And the watchdog now monitoring 24/7.

pnpm audit on the Portfólio screamed 61 vulnerabilities. Instead of updating dependency by dependency or trusting audit fix, I solved it with 5 lines of pnpm.overrides in package.json. Result: 61 → 2, with the remaining 2 having no published fix at all.

July 2026 was the month my portfolio stopped getting new features and started fixing the ones it already had. A deep audit revealed 10 problems — from Pix to focus trap — and by the end, deployment was more automated than ever.