惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
人人都是产品经理
人人都是产品经理
Cisco Talos Blog
Cisco Talos Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
V2EX
博客园 - 三生石上(FineUI控件)
Martin Fowler
Martin Fowler
WordPress大学
WordPress大学
D
Docker
S
SegmentFault 最新的问题
博客园 - 聂微东
美团技术团队
Apple Machine Learning Research
Apple Machine Learning Research
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Last Week in AI
Last Week in AI
M
MIT News - Artificial intelligence
F
Fortinet All Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The GitHub Blog
The GitHub Blog
GbyAI
GbyAI
L
LangChain Blog
Vercel News
Vercel News
博客园 - 叶小钗
MongoDB | Blog
MongoDB | Blog
Stack Overflow Blog
Stack Overflow Blog
H
Help Net Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
Engineering at Meta
Engineering at Meta
T
Threat Research - Cisco Blogs
T
Threatpost
Scott Helme
Scott Helme
T
Tailwind CSS Blog
Latest news
Latest news
Stack Overflow Blog
Stack Overflow Blog
Blog — PlanetScale
Blog — PlanetScale
The Register - Security
The Register - Security
罗磊的独立博客
P
Proofpoint News Feed
腾讯CDC
S
Schneier on Security
雷峰网
雷峰网
A
About on SuperTechFans
T
Tenable Blog
F
Full Disclosure
Cyberwarzone
Cyberwarzone
博客园_首页
有赞技术团队
有赞技术团队
K
Kaspersky official blog

DEV Community

How I built a dependency risk scanner with Coral in 7 days Local-first: a Model on Your Own Machine, Zero Cloud 2487. Remove Nodes From Linked List C_STD : A Leak-Free, Cross-Platform Standard Library for Modern C How to build your professional network as a developer — authentic strategies The Pope and the Dynamo Building ShouldWeAutomate: A Decision Intelligence Platform for Workflow Automation The Reputation Layer: Why Developers Quietly Run Corporate PR The Last Mile of Software Is a Sentence The Hermes Rescue: How an Open Agent Rebuilt My GitHub Projects from Scratch S2 — Heap Corruption Crashes: How to Diagnose and Fix Them I built a Chrome extension because I couldn't stop opening Twitter between Pomodoro sessions AI cheating in technical interviews is invisible to interviewers — here's how we detect it Lean4 Might Be the Missing Piece in AI: Why Theorem Provers Are Suddenly Everywhere The Zero-Drift API Series: Stop Trusting a Green Build You Can't Explain How I Deployed My First Project on AWS (And Didn't Break Everything) How I Built a Real-Time Quiz Platform with Next.js, WebSockets, and Learning Science When Your VPS Blocks Outbound SMTP: What Actually Helps Los agentes de código necesitan memoria durable, no solo contexto Cognitive Architectures of AGI: 7 Patterns That Transform LLMs from Oracles into Thinkers I Built a Chat App That Deletes Itself (Because I Was Bored at 2am) Uncovering the Power of Linux's History Command How to Add a Contact Form to Your Ghost Blog Accept Payments in Minutes with Afriex Checkout Sessions Hermes Agent Gets Smarter Every Day. So Does the Bill. How I get Next.js sites to load almost instantly — a practical checklist Treasure Hunt Engine: Why One Bad Prometheus Rule Sank the Whole Veltrix Event Test a DNS Leak in 2 Minutes: Complete Methodology + Per-OS Fixes (2026) Lessons from building a Chrome extension Rivet: A library i made in 2 days I Built a Speech-to-Text Tool Because Sometimes Typing Just Gets in the Way How I'm Building a Multi-Agent Crew for AI Coding Supervision (Cipher Update) Your AI Agent Needs a Manager, Not a Superhero I Built CausalLens — A Free, Open-Source Causal Impact Calculator for Time Series (5 Methods, Zero Setup) How to write good commit messages and pull requests — a team guide Cipher: The Jarvis with a Hermes Core How to build a second brain with Obsidian and Claude Code (step by step) Claude completed my MPI assignment. Then it couldn't run it. So I built the missing piece. This 100% How Our Document Ingestion Pipeline Turns Files into LLM-Ready Markdown Agentic AI Model Risk Management: Aligning with Regulatory Expectations CTV Fraud Has an IPv6 Business Problem The great AI enshittification The Veltrix Treasure Hunt Engine: Why Our First Rewrite Cost Us 3.2 Million Requests Per Second I Made My AI Models Argue, Then Let Hermes Be the Judge Road To KiwiEngine #4: The Racecar Driver Analogy Run Aider on Ollama, Bedrock, or Any LLM Provider — One Gateway, Every Model BAIXAR VÍDEO DO YOUTUBE Releasing HeliosProxy, The programmable Postgres data-plane Hello, DEV Community! 👋 Three Bitcoin Primitives That Don't Exist Anywhere Else (PoW Beacon, DLC Oracle, Fair-Launch Rune) Append-only doesn't mean what you'd hope Notes from the Mistral AI Now Summit Are Claude skills safe in 2026? What the Snyk ToxicSkills audit actually found How to not Lose $500M via API Bills: Run Private AI for 100 Engineers Under $1 Million The Unlikely Journey from Bricks to Bytes Three TODOs, three weeks, one weekend: finishing pq v0.14 Server-Side WebRTC Noise Reduction with Pion, FFmpeg, and RNN Models Autonomous AI Agents in Cryptocurrency Portfolio Management IDOR BugBounty Labs: 5 Realistic Challenges to Master Insecure Direct Object Reference IDOR Lab: The Bug Bounty Training Platform That Doesn't Hold Your Hand ZentriqGuard — Hermes Agent-Powered Zero-Trust Access Auditor Why Artistic QR Codes Silently Fail (And How I'm Trying to Fix It) How I Built and Monetized a Currency Exchange Rate API with FastAPI, Deployed it on Render, and Published it on RapidAPI. The 7 Best Reddit Scrapers in 2026 (Free & Paid, Tested) An AI runs my company. A solo dev vibe-coded $15K in a week — we made $[X]. A cold autopsy. I am new here Stop Pasting Your Code Into ChatGPT For Debugging—Run LLMs Locally Instead 5 Free JSON Tools Every Developer Should Bookmark Building reqlog: a Go CLI for tracing request flows across logs (files, Docker, SSH) Environment Variables in Node.js — What They Are, How dotenv Works, and Why Getting This Wrong Can Ruin You I Built a Zero-Dependency Discord.js Package That Creates Temporary Voice Channels Automatically Goodbye CSV Nightmares: Automating Magento Order Line Item Exports in Google Sheets Nexthena — A Local-First Whiteboard App Built on Excalidraw How we built an platform to solve the "finding a photographer" problem 5 Failure Modes I Found in My Financial RAG (And the One That Actually Mattered) From Logic to Numbers: A Beginner’s Guide to Programming Through Mathematical Thinking Oracle Fusion Report Scheduling with Skip Conditions AtCoder Beginner Contest 460 参加記録と解答例 (A D問題) Your AI Agent Just Crashed at Step 9 of 12. Here's How to Make That Not Matter. Grokking the System Design Interview: Why the Original Course Still Wins Outbox Pattern Solves Publishing. Inbox Pattern Solves Processing. Why autism hasn't disappeared — a hypothesis Por que eu parei de usar Cloudinary e construí minha própria API de imagens How to Test if Your Proxy is Leaking DNS: 2026 Setup Guide AWS VPC Networking — Public Subnet, Private Subnet ve 3-Tier Mimari MediaNote: a note-taking app inside VS code I built a sovereign self-healing AI development system from scratch using Hyperdimensional Computing — no LLMs, no cloud, no APIs WordPress vs. Next.js: benchmark real pe Core Web Vitals (și de ce plugin-urile de cache nu rezolvă problema) ai, deepseek, machinelearning I Gave My Dead Raspberry Pi to an AI Agent. It Fixed Everything Over SSH. How I Built a Google Shopping Scraper with Python & Playwright I Turned Hermes Agent into a Verifiable Agent Operating System The 5 Systematic Failure Modes of AI Research Reports (and How to Catch Them) Stop Saying 'Great!'—Build a Real AI Interview Coach with Claude Code Simple SQL Tool What is DevOps? A Plain English Guide for Beginners Why ChatGPT sucks at generating Types (and how I fixed it) Modelling a codebase as a requirements ontology in Neo4j, keeping AI coding agents oriented AI Is Doing the Work of Junior Developers — And Nobody Is Talking About What Happens in 7 Years
AppView 1.0.0 Released: Instrument and Secure Your LLM Deployments
Jay Grider · 2026-05-31 · via DEV Community

We just released AppView 1.0.0. It is a CLI tool designed to bridge the gap between raw model weights and the operational reality of deploying them. For too long, security teams have treated Large Language Models like static binaries. You download a .gguf or .safetensors file, trust the upstream repository, and then try to run it. That approach fails when frontier models act on tools, workflows, and environmental constraints rather than just answering chat prompts.

The shift toward third-party evaluation standards has made this distinction critical. Frontier model safety now depends on explicit claims about the evaluation harness rather than just raw output results. Independent evaluations must validate how models interact with their environment to prove robustness. Security teams are moving from simple classification checks to auditing the full lifecycle of model artifacts and deployment setups. AppView is our instrument for that lifecycle.

Instrumenting Local Models for Visibility and Compliance

Lightweight SBOMs are essential for tracking file identity, format details, and metadata within private repositories. We do not want massive infrastructure overhead here; we want a small Python CLI that inspects local LLM model artifacts. L-BOM handles the heavy lifting of parsing warnings to identify structural anomalies or missing license information before a model enters production workflows.

However, seeing the data is only half the battle. AppView takes those raw findings and contextualizes them. Consider a scenario where you ingest a quantized model for an edge device. L-BOM gives you the quantization level and parameter count. AppView then cross-references these values against your CI/CD pipeline constraints to ensure the artifact won't crash your deployment harness due to memory footprint mismatches.

Generating SPDX tag-value outputs allows seamless integration with existing supply chain security tools and policy engines. This ensures that every model version is instrumented and observed before it reaches the harness, preventing accidental usage of unvetted or compromised foundation weights.

Observing Model Metadata to Prevent Supply Chain Risks

Extracting architecture, quantization levels, and context lengths provides immediate insight into resource requirements and compatibility risks. But the metadata goes deeper. Verifying training framework and base model lineage prevents accidental usage of unvetted assets. This is where our toolset shines for small teams who lack massive infrastructure.

Validating license metadata ensures that local deployments adhere to organizational policies regarding open-source and proprietary assets. We saw a case recently where a team deployed a model that appeared compliant but had its license field in the file header set to null. L-BOM would flag this, but AppView aggregates this with other parsing warnings to give a holistic view of the risk.

This is not just about reading text files; it is about understanding the structural anomalies within the binary weights themselves. Parsing warnings help identify missing metadata that might indicate a broken or forked version of a model. We treat persistent memory and model artifacts as security boundaries. You must verify them before you trust them.

Securing the Evaluation Harness in Small Teams

A secure deployment requires verifying that the "harness" surrounding the model does not introduce unintended capabilities or data leakage vectors. Auditing the environment where a model acts is as critical as auditing the model weights themselves for frontier AI safety. Ensuring the evaluation setup explicitly describes its claims prevents overstatement of model capabilities in security reports.

Open-source projects often lack automated pipelines to inspect local model artifacts before they are shared or deployed internally. Security teams need lightweight CLI tools that do not require massive infrastructure to generate accurate Software Bills of Materials for AI assets. AppView fills this gap by integrating artifact inspection directly into the CI/CD pipeline.

We chose this path because we believe security starts at the edge, in the local file system, not just in the cloud. If you are running models locally, your supply chain is your machine's hard drive and its RAM. Treating external sockets as hostile until proven otherwise applies to model weights just as much as it does to JavaScript libraries.

Where This Shows Up in Small-Team Software

Integrating artifact inspection into the CI/CD pipeline ensures that every new model version is instrumented and observed before it reaches the harness. Open-source projects often lack automated pipelines to inspect local model artifacts before they are shared or deployed internally. Security teams need lightweight CLI tools that do not require massive infrastructure to generate accurate Software Bills of Materials for AI assets.

AppView 1.0.0 is the culmination of this work. It wraps the functionality of L-BOM and our other inspection utilities into a cohesive workflow. You can run it on .gguf and .safetensors files to emit a lightweight SBOM with file identity, format details, model metadata, and parsing warnings.

We have seen teams struggle with the sheer volume of models available on Hugging Face. Many have no license information or unclear lineage. AppView helps you filter these out before they hit your production environment. It is pragmatic: we do not want to stop innovation, but we do want to ensure that the foundation weights are as secure and well-documented as the code running around them.

This release marks a new chapter in how we handle AI governance at CHKDSK Labs. We are moving from reactive safety checks to proactive instrumentation. If you are building agents or deploying frontier models, you need visibility into the full stack—from the binary weights up to the evaluation harness. AppView provides that clarity without the bloat.

# Example: Using AppView to audit a directory of models before deployment
appview scan .\models --format table --check-licenses

Enter fullscreen mode Exit fullscreen mode

The output will show you exactly which files need attention, flagging those with null license metadata or mismatched architecture tags. It is a small tool with a big impact, designed for the practical realities of local-first AI development.