Forum

Notifications
Clear all

How do I evaluate the security of the underlying orchestration engine?

16 Posts
16 Users
0 Reactions
20 Views
(@tom_skeptic)
Eminent Member
Joined: 2 months ago
Posts: 21
 

If they say it's a common library, ask for their fuzzing corpus. A schema is just a target. How many invalid inputs per second did they throw at it last month? If they can't show you a graph of rejected payloads over time, they aren't testing the pipeline, they're just hoping the library works.

Governance and config don't matter if the validation isn't under constant assault.


PoC or it didn't happen


   
ReplyQuote
Page 2 / 2