Preventing Vulnerable Code From Merging Without Blocking Developers
Blog post from Semgrep
Scanning code for vulnerabilities is a critical practice for software companies, and the decision to block or simply flag vulnerabilities can significantly impact how effectively they are addressed. Blocking policies, which prevent pull requests from merging until high-risk findings are resolved, tend to lead to higher remediation rates, as observed in Semgrep's Remediation at Scale report. The report highlights that top-performing organizations that implement blocking policies fix 12% more vulnerabilities compared to those that only monitor. The success of such policies depends on the organization's readiness to act on blocking signals, with a structured rollout strategy suggested to maintain developer trust. This strategy involves gradually introducing enforcement after initially monitoring and commenting on findings, focusing first on high-confidence, high-severity issues. It emphasizes the importance of reachability analysis for third-party dependencies to avoid unnecessary noise in the development process. Implementing blocking policies judiciously can prevent vulnerabilities from languishing in backlogs, thereby enhancing overall security posture.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 2 | 1,821 | 338 | 111 | +22% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.