AppSec Labs — Hardening a Real Codebase
Solo · Aug 2026 · Ongoing
Most portfolio "security labs" are synthetic CTF boxes. I wanted to know what an actual AppSec review finds on a real, already-shipped codebase — so I forked my own Dine Flow backend and ran it through one.
Forked the repo to my own account, then worked the review in order: SCA dependency triage, a STRIDE threat model, SAST via Semgrep, secrets scanning via Gitleaks, then a GitHub Actions pipeline that gates every future push on all three checks.
The threat model surfaced something the scanners couldn't: zero auth middleware across every router — including two metrics endpoints serving live revenue and waste data with no authentication at all. That's the finding that matters most, since it compounds every other issue rather than sitting beside them. (Remediation is scoped as the next phase, not yet shipped.)
I didn't just trust a green pipeline. I opened a branch that deliberately added a known-vulnerable
dependency, an eval() call, and a fake hardcoded AWS key — confirmed all three checks
failed red, and caught a stale scanner-version bug in my own pipeline in the process.




