3 Comments
User's avatar
Adrian Sanabria's avatar

I’d like to hear more about how you get AI to test what must be a near-infinite combination of possible configurations for software like NGINX. I haven’t looked, but I wonder how you then narrow down those test scenarios to configurations that are more likely to be found in the wild. Is there a survey of NGINX configs out there? How would we know which configurations are more or less likely to be used?

Calif's avatar

This is our workflow:

1. Ask Claude to audit nginx

2. Verify bugs

3. Use Shodan to estimate the popularity of the config

your_friend's avatar

super cool!

any chance you're going to share transcripts' jsonls?