Home / Companies / Semgrep / Blog / Post Details
Content Deep Dive

Preventing Vulnerable Code From Merging Without Blocking Developers

Blog post from Semgrep

Post Details
Company
Date Published
Author
Braden Riggs
Word Count
998
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

Scanning code for vulnerabilities is a critical practice for software companies, and the decision to block or simply flag vulnerabilities can significantly impact how effectively they are addressed. Blocking policies, which prevent pull requests from merging until high-risk findings are resolved, tend to lead to higher remediation rates, as observed in Semgrep's Remediation at Scale report. The report highlights that top-performing organizations that implement blocking policies fix 12% more vulnerabilities compared to those that only monitor. The success of such policies depends on the organization's readiness to act on blocking signals, with a structured rollout strategy suggested to maintain developer trust. This strategy involves gradually introducing enforcement after initially monitoring and commenting on findings, focusing first on high-confidence, high-severity issues. It emphasizes the importance of reachability analysis for third-party dependencies to avoid unnecessary noise in the development process. Implementing blocking policies judiciously can prevent vulnerabilities from languishing in backlogs, thereby enhancing overall security posture.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 2 1,821 338 111 +22%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.