<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DevSecOps on RORO's blog</title><link>https://blog.rodolpheg.xyz/tags/devsecops/</link><description>Recent content in DevSecOps on RORO's blog</description><generator>Hugo</generator><language>en</language><managingEditor>contact@rodolpheg.xyz (0xRo)</managingEditor><webMaster>contact@rodolpheg.xyz (0xRo)</webMaster><lastBuildDate>Fri, 12 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.rodolpheg.xyz/tags/devsecops/index.xml" rel="self" type="application/rss+xml"/><item><title>Why I wanted my own code audit tool</title><link>https://blog.rodolpheg.xyz/posts/why-i-wanted-my-own-code-audit-tool/</link><pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate><author>contact@rodolpheg.xyz (0xRo)</author><guid>https://blog.rodolpheg.xyz/posts/why-i-wanted-my-own-code-audit-tool/</guid><description>&lt;blockquote>
&lt;p>Quick note: this post is less technical than usual. I just felt like telling, openly, the story of the tool I&amp;rsquo;m working on, and mostly how I felt all along the way.&lt;/p>
&lt;/blockquote>
&lt;hr>
&lt;h2 id="the-realization-three-years-of-sast">The realization: three years of SAST&lt;/h2>
&lt;p>It&amp;rsquo;s been more than three years now that I&amp;rsquo;ve been doing DevSecOps. In this job I use a fair amount of SAST, and overall I find them a bit lame. They surface the most obvious vulns, sure, but the moment things get a little twisted, it&amp;rsquo;s really not great.&lt;/p></description></item></channel></rss>