Habr•August 25, 2026•🇷🇺Translated from Russian

Avito Details Security Gates Implementation to Enforce Vulnerability Remediation Without Disrupting Developers

Avito has published an in-depth technical case study on implementing security gates that enforce vulnerability remediation policies while minimizing friction for development teams. Alexander Trifanov, head of Application Security at the company, describes nearly ten years of experience building controls that prevent SLA violations without turning security into a bottleneck.

The article defines a security gate as any automated check that can block or allow actions based on policy. Quality gates focus on code standards and functionality, while security gates target vulnerabilities and compliance. Both rely on a signal source, policy engine, and enforcement mechanism, but the latter protects against risk accumulation at company scale.

Trifanov explains that manual SLA extensions quickly erode control. Developers learn that deadlines can be moved, leading to repeated violations. A properly designed gate forces explicit risk acceptance by security before problematic actions proceed.

Pipeline Architecture and False-Positive Handling

Avito rejected synchronous scanner execution inside CI/CD pipelines. Instead, pushes trigger asynchronous orchestration of SAST, SCA, secret detection, and YAML configuration checks. Results are normalized in ASOC or SOAR, then automatically assigned to service owners with SLA-based priorities.

Each finding tracks three fields: status (active/inactive), verification_status (valid, false candidate, false positive), and verification_reason. Automated heuristics, validators, and limited AppSec review reduce noise before tasks reach developers.

Key requirements for any gate include robust false-positive workflows, deduplication of near-identical findings, and an emergency bypass switch. The bypass proved critical for business continuity during incidents.

First Gate at Deployment Stage

The initial gate queries SOAR at deployment time and blocks releases containing active vulnerabilities past SLA. High-severity issues trigger immediate blocks; medium-severity issues allow two full sprints before enforcement.

Services in maintenance mode rarely trigger gates because deployments are infrequent. Avito therefore created a manual “red button” that can block entire organizational units (groups of teams) from deploying any services until issues are addressed. The capability has never been used, yet its existence drives higher compliance.

Pre-receive Gate and Library Handling

A second, earlier gate uses server-side pre-receive hooks in GitHub, GitLab, and Bitbucket. Only fast scanners run within a strict ten-second limit. Rejected pushes return the finding identifier so developers can request false-positive validation.

Feedback revealed developers reluctant to pin library versions and analysts storing non-deployed code. These edge cases led to a dedicated library-update flow that scans requests before packages are fetched in development environments or CI/CD.

Kubernetes and Kyverno Experiments

Attempts to embed policy enforcement directly into Kubernetes using Kyverno are discussed as an ongoing direction for covering services that bypass traditional pipelines. The article concludes that multiple overlapping gates at different lifecycle stages reduce the impact of any single missed detection.

Related articles

AntiMalware•Other

RemoveMacAI Utility Appears on GitHub to Disable Apple Intelligence and Free Disk Space on macOS

A new open-source tool called RemoveMacAI has been released on GitHub, allowing macOS users to fully disable Apple Intelligence features and remove associated AI models from their systems. The utility addresses the lack of a single toggle in macOS 27 for turning off generative AI capabilities while also reclaiming storage space occupied by downloaded models. It supports Apple silicon devices and works by leveraging Apple's own system services rather than directly modifying protected directories. Users can selectively disable components such as Siri, Writing Tools, Genmoji, Image Playground, ChatGPT integration, smart replies, photo cleanup, and Xcode predictive code completion. The tool also installs a configuration profile that prevents models from being redownloaded automatically. Reversion is possible via the removemacai revert command, though this comes at the cost of losing access to certain Apple Intelligence-powered functions in third-party apps and Shortcuts. The project is licensed under MIT and leaves Dictation untouched as it is managed separately.

Habr•Other

Secure Personalization of Java Card Applets Using Issuer Security Domain and SCP02

The article explains how to leverage the Issuer Security Domain mechanisms on GlobalPlatform cards to establish secure channels for applet personalization without implementing custom ECDH-based key exchange. It addresses limitations of prior approaches that lacked authentication and required extensive PKI support. The solution uses SCP02 with specific security levels such as C_MAC and C_DECRYPTION to protect commands that store AES-128 keys and personal data on the card. Detailed code walkthroughs cover the applet constructor, process method, mutual authentication via SecureChannel.processSecurity, and unwrap operations for decrypting and verifying APDUs. Practical testing on NXP Java Cards demonstrates installation via FunGP library scripts that allow configurable security levels during mutual authentication. The implementation ensures that secret key updates enforce C_DECRYPTION while personal data writes accept C_MAC, with encrypted reads performed using AES-CBC.

AntiMalware•Other

IT Jobs at Major Tech Firms Turn Into Dating Red Flags for Some Women

Working in IT used to be seen as a strong advantage in dating due to high salaries and prestigious employers. However, employees at companies like Palantir and Tesla now report that their jobs trigger uncomfortable conversations about ethics and politics instead of romantic interest. A Palantir engineer named Gary has started hiding his employer after facing sharp reactions from women and even requests from friends to avoid mentioning the company at social events. Tesla employee James encounters questions about his political views simply because of his association with Elon Musk's company. Dating specialist Amy Laurent notes that tech giants face backlash over issues like surveillance, inequality, and AI displacing workers, forcing professionals to present their careers with caveats. The article from Wired highlights how an employer's reputation now overshadows individual values during initial meetings. While IT roles remain attractive in many ways, the automatic boost from big tech brands appears to be fading in personal contexts.

Securitylab•Other

Neuromorphic Chips: Event-Driven Architectures Aim to Cut Energy Use in Always-On AI and Sensor Systems

Modern processors and GPUs excel at massive parallel math yet remain inefficient for continuous sensor streams where little changes most of the time. Neuromorphic chips borrow principles such as local memory, sparse spiking communication and threshold-based activation from biological nervous systems to reduce data movement and idle computation. The approach replaces constant matrix multiplications with asynchronous spikes that propagate only when meaningful events occur, lowering both power and latency for edge devices. Spiking neural networks encode information in the timing and frequency of pulses rather than dense numeric tensors, making them suitable for vibration monitoring, robotic vision and wearable health sensors. Hybrid systems are expected to pair conventional CPUs and NPUs for heavy training workloads with neuromorphic accelerators that stay dormant until events arrive. The architecture does not replace existing accelerators but targets the niche of always-on, battery-constrained perception tasks where conventional von Neumann designs hit the memory wall.