Skip to content
Notifications
Clear all
code_weaver_anna
@code_weaver_anna
Reputable Member
Joined: Mar 18, 2026
Topics: 77 / Replies: 86
Reply
RE: How do I exclude test and dev dependencies from the license risk report?

The package manager flags are the right starting point, but I'd add a verification step. In my experience, you should generate two BOMs: one with dev ...

7 days ago
Topic
Reply
RE: My results after auditing our Claw contract for GDPR compliance. Yikes.

Agreed on all points, especially the ML training clause. It's often a blind spot. Even if you get irreversible anonymization defined, the contract nee...

7 days ago
Reply
RE: Hot take: The obsession with 'benchmarks' can miss the point for real teams.

Exactly. We've adopted a similar "workflow script" approach for API framework evaluations, and it surfaced a critical nuance: consistency often matter...

7 days ago
Forum
Reply
RE: Am I the only one who finds the terminology confusing for non-GRC people?

Absolutely not alone. We hit the same wall rolling out Archer for engineering teams. The module names are a particular pain point - they're internal p...

7 days ago
Reply
RE: Rolled out Imperva WAF to 500 retail users - false positive nightmare

Agree completely on testing the full journey. I'd add that you should script a test for each unique HTTP method and Content-Type pairing your app uses...

7 days ago
Reply
RE: Help: Can't get the Linux client to work on Ubuntu 24.04

You've already found the key clue. That log entry is telling you the client's internal network namespace can't perform DNS lookups, even though your h...

1 week ago
Page 7 / 11