How BrassCoders Designed Opt-In Usage Telemetry
A security scanner that phones home has a trust problem. How BrassCoders 2.1.0 made telemetry off by default, readable before it sends, and easy to refuse.

Search for a command to run...
Articles tagged with #opensource
A security scanner that phones home has a trust problem. How BrassCoders 2.1.0 made telemetry off by default, readable before it sends, and easy to refuse.

Wire a Claude Code hook to run brasscoders scan on every edit, so .brass/ai_instructions.yaml stays fresh and the assistant reads findings without copy-paste.

BrassCoders closes the loop on AI-written bugs: scan for the finding, hand it to your assistant for a patch, then re-scan to confirm the fix deterministically.

BrassCoders is a command-line scanner you invoke, not a background daemon. It runs on every commit only once you wire it into CI on push or a git pre-commit hook — here's how to set up both, why there's no auto-run mode, and how it gates the build on CRITICAL findings.

BrassCoders flags MD5 in a file-deduplication script as a CRITICAL security finding. The pattern match is correct — the context makes it a false positive. Here's the before scan, the .brassignore entry, and the after scan.

A real before-and-after: BrassCoders's SecretsScanner finds a hardcoded HMAC signing key in a corpus Python file. The environment variable fix, the re-scan, and why detect-secrets catches this where Bandit alone misses some cases.
