I got tired of manual code reviews so I built a free automated security pipeline
Let me be upfront about something. For a while, our security process was basically vibes. Someone would glance over a PR, maybe catch an obvious thing, and we'd ship it. No linting enforcement. No ...

Source: DEV Community
Let me be upfront about something. For a while, our security process was basically vibes. Someone would glance over a PR, maybe catch an obvious thing, and we'd ship it. No linting enforcement. No dependency scanning. No idea if someone accidentally committed a database password six months ago. It wasn't negligence exactly, it was the usual small team problem. Everyone's busy, security tooling feels like a rabbit hole, and the good stuff costs money we didn't want to spend. Then I spent an afternoon looking into it properly and realised the entire thing was solvable for free, in a weekend. This is what I set up. The constraints I was working with Python (Django) backend, JavaScript/Node.js frontend Everything lives on GitHub Small team - I'd be the one maintaining this Not willing to pay for tooling, at least not yet The last point mattered a lot. Most "enterprise" security tools have pricing pages that just say "contact sales." Hard pass. The approach: three layers, not one big tool T