Dependency Upgrade Gauntlet: Patch a Critical Library Without Breaking Users
Practice upgrading under risk using changelogs, tests, canaries, and rollback plans.
Review member-submitted ideas and support the topics you would attend.
10 proposals
Practice upgrading under risk using changelogs, tests, canaries, and rollback plans.
Build a safer upload path that handles size limits, type checks, scans, and user recovery.
A practical two-hour session on Password Reset Security, focused on Abuse Controls, Recovery Tokens, and User Trust. Attendees work through concrete engineering tradeoffs, review examples, and leave with a checklist they can apply in real team projects.
A practical two-hour session on Permission Boundary Testing, focused on Roles, Scopes, and Admin UI Access. Attendees work through concrete engineering tradeoffs, review examples, and leave with a checklist they can apply in real team projects.
A security fundamentals drill where attendees handle a leaked token from detection to prevention.
Practice rotating keys, tokens, passwords, and certificates with overlap and verification.
A practical two-hour session on Session Security Fundamentals, focused on Cookies, Tokens, Logout, and Account Recovery. Attendees work through concrete engineering tradeoffs, review examples, and leave with a checklist they can apply in real team projects.
Find forgotten admin rights, old project access, shared accounts, and weak offboarding paths.
Design log, trace, and error-reporting rules that preserve debugging value without leaking data.
A practical two-hour session on Webhook Security Fundamentals, focused on Signatures, Replay Protection, and Audit Logs. Attendees work through concrete engineering tradeoffs, review examples, and leave with a checklist they can apply in real team projects.