Better CVE-Based SAST Rules Start with the Right Patch
How we rebuilt CVE Tracer’s Patch Finding Agent for GrepRules and improved correct patch attribution from 21% to 77%.
Blog
Research, engineering, and product insights on transforming security signals into reproducible evidence teams can trust and act on.
Selected from the Provally team
How we rebuilt CVE Tracer’s Patch Finding Agent for GrepRules and improved correct patch attribution from 21% to 77%.
Meet greprules.io and the greprules Plugin: a free way to discover and use OpenGrep/Semgrep-compatible SAST rules in developer and AI coding workflows.
How Provally turns public CVEs into OpenGrep-compatible SAST rules using patch attribution, root-cause analysis, and validation against real commits.
Why SAST noise persists, how PoC-based verification proves real exploitability, and where AI-assisted AppSec workflows deliver value.