BlogsCloudflareVulnerability Class Reduction

Vulnerability Class Reduction

Vulnerability Class Reduction

1
posts
2025

Cloudflare is actively working to reduce entire classes of vulnerabilities in its software development lifecycle. This includes enhancing static analysis tools with custom rulesets to proactively detect and block injection vulnerabilities and secrets in code. The company leverages automation, secure defaults, and developer training to prevent these issues from reaching production, aiming to meet CISA's 'Secure by Design' pledge goals.

2025

Demonstrating reduction of vulnerability classes: a key step in CISA’s “Secure by Design” pledge

1/14/2025

This post details Cloudflare's efforts to reduce specific vulnerability classes (injection and secrets) by enhancing SAST tools with custom rulesets, implementing 'build break' in CI/CD pipelines, and improving developer training. It reports a 79% reduction in secrets and a 44% reduction in injection vulnerabilities in the latter half of 2024.