DEV Community

Ofri Peretz profile picture

Ofri Peretz

IC5/M2 Leader @ Snappy US. Building revenue APIs & AI-ready ESLint plugins. Expert in distributed teams, scalable infra, and fostering a culture of craftsmanship.

Education

CS

Work

Engineering Manager @ Snappy | Open Source Developer | ESLint for AI tools

142,076 Weekly Downloads. Zero Releases Since 2021. Is the Niche Defended?

142,076 Weekly Downloads. Zero Releases Since 2021. Is the Niche Defended?

1
Comments
9 min read

Want to connect with Ofri Peretz?

Create an account to connect with Ofri Peretz. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
We Were Wrong About sls remove

We Were Wrong About sls remove

1
Comments
8 min read
25% of My Benchmark Verdict Is an Opinion. Here's the Anatomy.

25% of My Benchmark Verdict Is an Opinion. Here's the Anatomy.

1
Comments
8 min read
Marketing Pages Rot Silently. Mine Print an Expiry Date on Every Claim.

Marketing Pages Rot Silently. Mine Print an Expiry Date on Every Claim.

1
Comments
8 min read
Fixtures First, Rules Second: How to Design a Ground-Truth Corpus

Fixtures First, Rules Second: How to Design a Ground-Truth Corpus

1
Comments
9 min read
Valid vs. Reliable Metrics: Consistent Numbers Can Still Be Wrong

Valid vs. Reliable Metrics: Consistent Numbers Can Still Be Wrong

1
Comments
7 min read
Static Analysis vs. SAST vs. Linting: The Taxonomy That Matters for Security Teams

Static Analysis vs. SAST vs. Linting: The Taxonomy That Matters for Security Teams

Comments
8 min read
Sample Size and Statistical Power: What a Small Sample Can and Cannot Tell You

Sample Size and Statistical Power: What a Small Sample Can and Cannot Tell You

Comments
8 min read
Proxy Metrics: The Number You Optimize Is Not the Thing You Want

Proxy Metrics: The Number You Optimize Is Not the Thing You Want

Comments
8 min read
Precision, Recall, and F1 for Static Analysis: Same Score, Opposite Tools

Precision, Recall, and F1 for Static Analysis: Same Score, Opposite Tools

Comments
8 min read
Taint vs. Heuristic Detection: The Difference Between a Proof and a Hunch

Taint vs. Heuristic Detection: The Difference Between a Proof and a Hunch

1
Comments 1
7 min read
Statistical Significance and p-Values: What p > 0.05 Actually Means

Statistical Significance and p-Values: What p > 0.05 Actually Means

Comments
8 min read
Reproducibility vs Replicability: Why Benchmark Numbers Need Both

Reproducibility vs Replicability: Why Benchmark Numbers Need Both

Comments
7 min read
Ranking vs. Measuring: What a Leaderboard Throws Away

Ranking vs. Measuring: What a Leaderboard Throws Away

Comments
8 min read
OWASP Top 10, Explained: An Address System, Not a Severity Scale

OWASP Top 10, Explained: An Address System, Not a Severity Scale

Comments
8 min read
Ground Truth in Security Testing: Who Decides What's Vulnerable?

Ground Truth in Security Testing: Who Decides What's Vulnerable?

Comments
8 min read
The CWE Taxonomy, Explained: A Name Is Not a Verdict

The CWE Taxonomy, Explained: A Name Is Not a Verdict

Comments
8 min read
CVSS Scores Explained: The Number Measures Severity, Not Risk

CVSS Scores Explained: The Number Measures Severity, Not Risk

Comments
8 min read
Composite Scores and Weighting: Your 'Overall Score' Is an Editorial

Composite Scores and Weighting: Your 'Overall Score' Is an Editorial

Comments
8 min read
The Confusion Matrix: What TP, FP, FN, and TN Actually Mean

The Confusion Matrix: What TP, FP, FN, and TN Actually Mean

Comments
8 min read
Inter-Rater Agreement and Cohen's Kappa: When Your Labels Are Opinions

Inter-Rater Agreement and Cohen's Kappa: When Your Labels Are Opinions

Comments
7 min read
I Built What I Benchmark. Here's How I Try Not to Cheat.

I Built What I Benchmark. Here's How I Try Not to Cheat.

Comments
9 min read
Goodhart's Law in Benchmarking: When the Metric Becomes the Target

Goodhart's Law in Benchmarking: When the Metric Becomes the Target

Comments
7 min read
I Maintain 23 Benchmark Suites Across My Own Packages. Only 1 of the Serverless Ones Has Real Numbers Yet.

I Maintain 23 Benchmark Suites Across My Own Packages. Only 1 of the Serverless Ones Has Real Numbers Yet.

Comments
9 min read
Bias in Measurement: The Silent Failure Mode in Benchmark Design

Bias in Measurement: The Silent Failure Mode in Benchmark Design

1
Comments
8 min read
The Base Rate Problem: Why 95% Precision Means Nothing Without Context

The Base Rate Problem: Why 95% Precision Means Nothing Without Context

Comments
7 min read
My credential rule reported 842 secrets in vercel/ai. The real count was 0.

The failure of positive-only testing

My credential rule reported 842 secrets in vercel/ai. The real count was 0.

8
Comments 3
11 min read
MongoDB Injection Bugs Your Code Review Misses — 16 ESLint Rules Catch Them Before Deployment

MongoDB Injection Bugs Your Code Review Misses — 16 ESLint Rules Catch Them Before Deployment

1
Comments
18 min read
Gemini 2.5 Pro Wrote Unsafe SQL 96% of the Time: 3 Node.js Injection Patterns — and the ESLint Rule That Catches Them

Gemini 2.5 Pro Wrote Unsafe SQL 96% of the Time: 3 Node.js Injection Patterns — and the ESLint Rule That Catches Them

Comments
12 min read
Claude vs Gemini Across 4 Security Domains: A Dead Heat — and the Hardening 63% of AI Code Skips

Claude vs Gemini Across 4 Security Domains: A Dead Heat — and the Hardening 63% of AI Code Skips

6
Comments 7
8 min read
The Bug That Passes Every Toolchain Check: Circular Dependencies in JavaScript

Bundler trade-offs and hidden CI slowdowns

The Bug That Passes Every Toolchain Check: Circular Dependencies in JavaScript

3
Comments 4
8 min read
Payload CMS Has 508 Circular Dependencies. Next.js Has 17. Here's Why They Form in Every Large JS Codebase.

Payload CMS Has 508 Circular Dependencies. Next.js Has 17. Here's Why They Form in Every Large JS Codebase.

Comments
12 min read
Math.random() Is Not Secure. I Found It Generating API Keys in a 44K-Star Repo.

Math.random() Is Not Secure. I Found It Generating API Keys in a 44K-Star Repo.

4
Comments 2
6 min read
Same NestJS Prompt. Claude Got 6 Security Errors. Gemini Got 2. Here's What Both Got Wrong.

Same NestJS Prompt. Claude Got 6 Security Errors. Gemini Got 2. Here's What Both Got Wrong.

2
Comments
12 min read
5 Cycles Invisible in 14,556 Files. The Cache Bug That Hid Them.

5 Cycles Invisible in 14,556 Files. The Cache Bug That Hid Them.

1
Comments
13 min read
eslint-plugin-import Has 38M Weekly Downloads. Here's What It Still Gets Wrong.

eslint-plugin-import Has 38M Weekly Downloads. Here's What It Still Gets Wrong.

1
Comments
13 min read
Claude Wrote a NestJS Service. TypeScript Was Happy. ESLint Found 6 Security Holes.

Claude Wrote a NestJS Service. TypeScript Was Happy. ESLint Found 6 Security Holes.

5
Comments 7
19 min read
I Inherited a NestJS Codebase. One 12-Second ESLint Run Found 47 Violations Across 6 Vulnerability Classes.

I Inherited a NestJS Codebase. One 12-Second ESLint Run Found 47 Violations Across 6 Vulnerability Classes.

1
Comments 2
17 min read
1.5M Weekly Downloads, 1 False Alarm per Real Bug: the eslint-plugin-security False-Positive Tax

1.5M Weekly Downloads, 1 False Alarm per Real Bug: the eslint-plugin-security False-Positive Tax

Comments
30 min read
The #1 ESLint Security Plugin Just Got Fixed. It Still Catches 0 of 6 SQL Injections.

The #1 ESLint Security Plugin Just Got Fixed. It Still Catches 0 of 6 SQL Injections.

Comments
30 min read
Our linter reported 0 cycles. A cache bug hid 245 files at scale.

Our linter reported 0 cycles. A cache bug hid 245 files at scale.

Comments
17 min read
Aggregate Benchmarks Lie. Here's What 700 AI Functions Look Like by Security Domain.

Aggregate Benchmarks Lie. Here's What 700 AI Functions Look Like by Security Domain.

Comments
27 min read
2 of 3 bugs a 5KB corpus caught were the exact shapes AI writes by default

2 of 3 bugs a 5KB corpus caught were the exact shapes AI writes by default

Comments
16 min read
We Ranked 5 AI Models by Security. The Leaderboard Is Wrong.

We Ranked 5 AI Models by Security. The Leaderboard Is Wrong.

2
Comments
13 min read
I Asked Claude to Fix Its Own Security Bugs. 1 in 3 Fixes Added a NEW Vulnerability.

I Asked Claude to Fix Its Own Security Bugs. 1 in 3 Fixes Added a NEW Vulnerability.

Comments
26 min read
Microsoft's SDL ESLint Plugin Caught 5 Node Vulns. The Domain Plugins Caught 46 — Same File, Wrong Layer

Microsoft's SDL ESLint Plugin Caught 5 Node Vulns. The Domain Plugins Caught 46 — Same File, Wrong Layer

1
Comments
17 min read
SonarJS Has 269 Rules. It Still Missed 26 of My 40 Node.js Vulnerabilities.

SonarJS Has 269 Rules. It Still Missed 26 of My 40 Node.js Vulnerabilities.

Comments
13 min read
eslint-plugin-security Caught 21 Issues. The Domain Plugins Caught 46. Here's the 25-Finding Gap.

eslint-plugin-security Caught 21 Issues. The Domain Plugins Caught 46. Here's the 25-Finding Gap.

Comments
12 min read
I Let Claude Write 80 Functions. 65-75% Had Security Vulnerabilities.

I Let Claude Write 80 Functions. 65-75% Had Security Vulnerabilities.

4
Comments 4
31 min read
PostgreSQL's COPY FROM Can Read /etc/passwd Into Your Database — One ESLint Rule Blocks It.

PostgreSQL's COPY FROM Can Read /etc/passwd Into Your Database — One ESLint Rule Blocks It.

Comments
15 min read
One INSERT Loop Made Our CSV Import 500x Slower. One ESLint Rule Catches It Before It Ships.

One INSERT Loop Made Our CSV Import 500x Slower. One ESLint Rule Catches It Before It Ships.

1
Comments 3
8 min read
search_path Hijacking: the PostgreSQL Attack That Turns SELECT * FROM users Into the Attacker's Table

search_path Hijacking: the PostgreSQL Attack That Turns SELECT * FROM users Into the Attacker's Table

Comments
16 min read
Express.js Security Bugs Your Middleware Doesn't Stop — 14 ESLint Rules That Do

Express.js Security Bugs Your Middleware Doesn't Stop — 14 ESLint Rules That Do

Comments
8 min read
NestJS Security Bugs Your Decorators Hide From Code Review — 6 Rules That Catch Them in CI

NestJS Security Bugs Your Decorators Hide From Code Review — 6 Rules That Catch Them in CI

Comments
7 min read
AWS Lambda Security Bugs Your Serverless Functions Are Shipping — 14 Rules That Catch Them

AWS Lambda Security Bugs Your Serverless Functions Are Shipping — 14 Rules That Catch Them

Comments
11 min read
Browser Security Bugs Your Frontend Passes to Code Review — 45 ESLint Rules Catch Them in CI

Browser Security Bugs Your Frontend Passes to Code Review — 45 ESLint Rules Catch Them in CI

Comments
14 min read
JWT Vulnerabilities Your Code Review Approves Every Day — 13 ESLint Rules Stop Them in CI

JWT Vulnerabilities Your Code Review Approves Every Day — 13 ESLint Rules Stop Them in CI

Comments
13 min read
Node.js Security Bugs That Pass Code Review Every Day — 34 Static Analysis Rules That Don't

Node.js Security Bugs That Pass Code Review Every Day — 34 Static Analysis Rules That Don't

Comments
10 min read
Performance at Scale: The Static Analysis Standard for 100x Faster Linting

Performance at Scale: The Static Analysis Standard for 100x Faster Linting

Comments
2 min read
Vercel AI SDK Security Holes That TypeScript Won't Catch — 19 Rules That Will

Vercel AI SDK Security Holes That TypeScript Won't Catch — 19 Rules That Will

Comments 1
10 min read
loading...