No One Talks Enough About Security for AI Coding. Here's How I Do It in My Workflows
AI has almost solved writing code - at least in many ways. But it certainly doesn't produce secure code! I see vulnerabilities turn up in AI generated code constantly, and almost nobody is building for it. So this is the setup I actually use. The agent still does the work. The difference is that a security scan sits inside the workflow as a step it cannot skip, and it is not another agent giving an opinion. Two tools do the job - Archon runs the workflow and Sonar decides whether the work is allowed out. Archon is open source and Sonar is free to start with! The workflow itself is linked below, and the idea transfers to whatever you already use. ~~~~~~~~~~~~~~~~~~~~~~~~~~ Check out Sonar (SonarQube Cloud, free for open source): https://fandf.co/4x9mJfM ~~~~~~~~~~~~~~~~~~~~~~~~~~ - Join Dynamous for the new Agentic Coding Course 2.0 - the core of the course is now COMPLETE: https://dynamous.ai - Archon (my open source harness builder): https://github.com/coleam00/Archon - The secure workflow from this video: https://github.com/coleam00/ai-transformation-workshop/blob/main/.archon/workflows/secure-fix-issue.yaml ~~~~~~~~~~~~~~~~~~~~~~~~~~ 0:00 Agents write great code, not secure code 0:50 Archon and SonarQube, my daily drivers 2:29 The two ways agents introduce vulnerabilities 3:43 Two reasons agents screw this up 5:25 It notices the vulnerability and ships it anyway 6:25 A prompt is not a gate 7:02 My issue-to-PR workflow, the basic version 8:16 Why one more review agent doesn't fix it 9:15 The one idea: make it a gate 10:00 The secure workflow in Archon 11:12 Inside the YAML of a workflow 12:25 The three vulnerabilities Sonar caught 14:09 Running it end to end: red, then green 15:43 Where to take this next ~~~~~~~~~~~~~~~~~~~~~~~~~~ Join me as I push the limits of what is possible with AI. I'll be uploading videos weekly - at least every Wednesday at 7:00 PM CDT!