Website Security & Threat Management
Demonstrating reduction of vulnerability classes: a key step in CISA’s “Secure by Design” pledge

Demonstrating reduction of vulnerability classes: a key step in CISA’s “Secure by Design” pledge

1/14/2025 · Sri Pulla, Trishna, Jordan Lilly

What this post added

This post details Cloudflare's proactive efforts to reduce entire classes of vulnerabilities, specifically injection flaws and secrets in code, aligning with CISA's 'Secure by Design' pledge. It highlights the implementation of custom SAST rulesets, automated detection, and 'build break' enforcement within CI/CD pipelines to prevent these vulnerabilities from entering production. The post quantifies the impact with a 79% reduction in secrets and a 44% reduction in injection vulnerabilities in the latter half of 2024, showcasing a shift towards preventing vulnerabilities at their source rather than patching them.

Read the original post ↗