今日已更新 380 条资讯 | 累计 41154 条内容
关于我们

今日精选

HOT

最新资讯

共 41154 篇
第 1794/2058 页
AI 资讯 Dev.to

Rails GuardDog: Advanced Security Scanner for Rails Applications

Rails GuardDog: Advanced Security Scanner for Rails Introduction Today I'm excited to announce Rails GuardDog v0.1.0 — an open-source security scanner for Rails that goes beyond traditional tools like Brakeman. While Brakeman is excellent for catching basic Rails vulnerabilities, Rails GuardDog focuses on newer vulnerability classes that most tools miss: AI/LLM prompt injection, DoS/ReDoS patterns, supply chain attacks, and more. The Problem Modern Rails applications face new security challenges: AI/LLM Integration - How do you prevent prompt injection when integrating with ChatGPT, Claude, or Anthropic? ReDoS Attacks - Catastrophic backtracking in regex can bring down your app Supply Chain Attacks - Typosquatted gems that look like popular libraries IDOR Gaps - Objects accessible without proper authorization checks Advanced Secrets - Hardcoded API keys that Brakeman misses Rails GuardDog detects all of these. What is Rails GuardDog? Rails GuardDog is a lightweight gem that adds comprehensive security scanning directly to your Rails applications. 12 Security Checkers SQL Injection - String interpolation in queries XSS - Unescaped output in views CSRF - Disabled protection verification Mass Assignment - permit! vulnerabilities (fixes Brakeman #1942, #1918) Open Redirect - User input in redirects Hardcoded Secrets - API keys, tokens, passwords (always-on, fixes #1989) DoS/ReDoS - Unbounded queries, dangerous regex patterns IDOR - Object access without authorization AI/LLM Prompt Injection - User input flowing to LLMs Rate Limiting - Missing rack-attack configuration Supply Chain - Typosquatted gems using Levenshtein distance GraphQL - Missing field-level authorization Features 📊 Multiple report formats : Console, HTML, JSON 🔍 AST-based analysis : Uses parser gem for deep code understanding ⚡ Async support : Built-in Sidekiq integration 📈 Zero dependencies : Only requires parser and ast gems 🚀 Production-ready : Tested and battle-ready 📝 CWE/OWASP mappings : Every find

Syed Ghani 2026-06-06 17:22 19 原文
AI 资讯 Reddit r/webdev

I built an AI-native video editor that renders 4K video entirely in the browser - no server needed

https://preview.redd.it/xse99kmwom5h1.png?width=3072&format=png&auto=webp&s=af121137b68e58c524be2f99f3a1b2ab6dacc22e After years of frustration with cloud-based video editors that charge by the minute and require massive server farms, I built OpenVideo - an AI-native video editing platform that does everything in your browser. **What makes it different:** 🚀 **Browser-Based 4K Rendering** - Hardware-accelerated using WebCodecs + PixiJS. Export 4K video without any server-side processing. 🤖 **AI-Native from Day One** - Semantic search across your video library (find clips by content, not filenames), automatic captions with AI transcription, and an AI Director that helps organize your footage. **Tech Stack:** - Frontend: Next.js 15 - Backend: NestJS + Fastify - DB: PostgreSQL + Drizzle ORM - Rendering: PixiJS + WebCodecs - AI: Gemini API + pgvector It's open source and I'd love feedback from the community. Check it out: https://github.com/openvideodev/openvideo What features would you want to see in a browser-based video editor? submitted by /u/snapmotion [link] [留言]

/u/snapmotion 2026-06-06 17:09 8 原文
AI 资讯 Reddit r/webdev

6 Months later: A comparison site for VPS and Dedicated Servers

A lot has changed since I posted this 6 months ago. serverlist.dev is a comparison tool for VPS, Dedicated and GPU Servers. I fetch data multiple times a day and present it fairly with no prioritization or hidden advertisement. You decide which columns to sort, which values to filter and which product matters most to you. When I last posted this on r/webdev I got five main pieces of feedback: We would like a "Compact view" option --> Done Some CTA and other strings seem pushy ("Claim Deal") --> Improved The site is lacking any additional value beside being a data catalogue --> read more below The filter need debounce and the whole table has very bad performance --> I significantly imrpoved the table performance by using tanstack virtualization. Sorting and filtering anything is now instant! We would like cPanel, Plesk, Managed properties --> still working on that. I am also thinking of "support IaC" what other information might be relevant for you? Since the last time I also worked on many new features: Hourly Pricing where applicable I now show the hourly price of a product. You can also filter for "Hourly price available" In-Table Comparison (desktop version only) when you select one product with the checkbox on the left, all other product's values are either green or red depending on their relative performance. Helping you to quickly identify if there might be a better deal that you overlooked. Product specific page clicking the compare button on a product or clicking its name now brigns you to a more detailed page showing the historical price change of that product and also two categories "What you get for a similar price" and "Similar servers by specs" where differences are also marked in green or red colour. Price Index alongside the product specific historical data I am also collecting averages for the entire industry so you can compare all providers at once. Right now I have "RAM per 1€", "CPU Cores per 1€" and the average price for generic SKU tiers like 4G

/u/FastBreakfast5799 2026-06-06 16:39 7 原文
AI 资讯 Reddit r/MachineLearning

Using FC26 to simulate the world cup ? [D]

maybe this should be asked in the Fc26 game subreddit but not sure. Anyway I just saw a video of someone predicting the winner of the world cup using the simulate match feature in the game but he only did it once. Would running this feature 100-1000 times give a significant result ? or is that feature only based on luck ? submitted by /u/Stillane [link] [留言]

/u/Stillane 2026-06-06 16:34 7 原文
开发者 Reddit r/webdev

Understanding Consistent Hashing Correct Me If I'm Wrong

Why we need it ? Suppose we have multiple databases and want to distribute data among them. Instead of searching every database when we need some data, we use a rule that tells us exactly which database should store a particular record. Method 1: Modulo Based Distribution Imagine we have 3 databases DB-A , DB-B , DB-C Each record has a unique ID. Now We decide the database using ID % Number_of_Databases for e.g. 16 % 3 = 1 So record 16 goes to database index 1 (DB-B). This works fine until we add another database. The same record becomes 16 % 4 = 0 Now record 16 should be stored in DB-A instead of DB-B. The problem is that when the number of databases changes, a huge amount of data gets remapped to different databases. This can cause Massive data migration , Increased CPU and network usage Method 2: Consistent Hashing Instead of using modulo, imagine a circular ring numbered from 0 to 99. We place our databases on the ring: DB-A -> 0 DB-B -> 25 DB-C -> 50 DB-D -> 75 Now we pass the data unique id through a hash function and it will give the location of that data on the ring for e.g. User ID = 12345 hash(12345) = 42 now we get the position we Move clockwise. Store the data in the first database you encounter This means we store the 42 position data at the DB-C Now What Happens When We Add a New Database? Suppose we add DB-E -> 37 now only the data between 26 to 37 needs to move from DB-C to DB-E. The rest of the data stays exactly where it was. This is the biggest advantage of Consistent Hashing much less data migration , easier scaling , lower operational cost Now there is one more thing in this method which is Virtual Nodes One issue is that some databases may receive much more traffic than others. To balance the load, the same database can appear multiple times on the ring. DB-A -> 0, 40, 80 DB-B -> 25, 65 DB-C -> 13, 50, 90 DB-D -> 75 These extra positions are called virtual nodes. Any corrections? Is there anything else I should know about this topic? Please let

/u/No-Resolution-4054 2026-06-06 15:52 8 原文
AI 资讯 Reddit r/webdev

I built a microservice in C, because why not!

I had an interview with a big observability company and I wanted to impress the interviewer, with my recent interest in development with C, I built a simple microservice project using golang and created a fully usable C microservice that has Redis and an HTTP server included, and more.. It was very fun seeing this side of C and to know my personal limits and challenge them. It was a cool project and I learned a lot :) btw; I got rejected and didn't even have the chance to show my project in the interview :( You can checkout the project on github: https://github.com/AhmedAbouelkher/micro_market/tree/main/invoice-service Happy to hear your thoughts. submitted by /u/AhmedMahmoud201 [link] [留言]

/u/AhmedMahmoud201 2026-06-06 15:38 7 原文
AI 资讯 Reddit r/artificial

One of the best AI articles I have seen recently.

One of the clearest breakdowns for average people like me to understand how AI actually works, and some interesting further information to'boot. https://rogerthatcleansignal.carrd.co/ Discuss. submitted by /u/Leading_Pollution131 [link] [留言]

/u/Leading_Pollution131 2026-06-06 15:35 7 原文