
1/14/2025 · Sri Pulla, Trishna, Jordan Lilly
What this post added
This post details Cloudflare's proactive efforts to reduce entire classes of vulnerabilities, specifically injection flaws and secrets in code, aligning with CISA's 'Secure by Design' pledge. It highlights the implementation of custom SAST rulesets, automated detection, and 'build break' enforcement within CI/CD pipelines to prevent these vulnerabilities from entering production. The post quantifies the impact with a 79% reduction in secrets and a 44% reduction in injection vulnerabilities in the latter half of 2024, showcasing a shift towards preventing vulnerabilities at their source rather than patching them.