<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Swift on Joser&#39;s Elixir</title>
    <link>https://joser.ca/tags/swift/</link>
    <description>Recent content in Swift on Joser&#39;s Elixir</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 13 May 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://joser.ca/tags/swift/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Same Code, Three Runs: What --rci 2 Did to the Findings</title>
      <link>https://joser.ca/posts/stride-security-review-second-pass/</link>
      <pubDate>Wed, 13 May 2026 00:00:00 +0000</pubDate>
      <guid>https://joser.ca/posts/stride-security-review-second-pass/</guid>
      <description>&lt;p&gt;A plugin update for &lt;a href=&#34;https://github.com/cheezy/stride-security-review&#34;&gt;stride-security-review&lt;/a&gt; shipped today, so I ran it against &lt;a href=&#34;https://github.com/j-morgan6/trays_social&#34;&gt;Trays Social&lt;/a&gt; without changing a line of application code. Then I ran it again. Same plugin version, same files, different counts and, more importantly, different reads on whether there was a Critical at all.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Run 1 (single-pass): 44 findings, 0 Critical, 2 High.&lt;/li&gt;&#xA;&lt;li&gt;Run 2 (single-pass): 40 findings, 1 Critical, 2 High.&lt;/li&gt;&#xA;&lt;li&gt;Run 3 (&lt;code&gt;--rci 2&lt;/code&gt;): 33 findings, 1 Critical, 3 High.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;code&gt;--rci 2&lt;/code&gt; adds two extra critique passes (the flag is clamped to a max of 3). After that the picture settled.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
