From the source
The most dangerous security bugs often look like ordinary code review details: a missing authorization check, a user-controlled string crossing a trust boundary, or a token logged where it should never appear.
Today we're rolling out automated security review in Droid .
On every non-draft PR, Droid runs a STRIDE-based security review alongside the standard code review.
Findings come back with severity, a CWE reference, an explanation, and a suggested fix, posted as inline comments directly on the diff.
Real-world audits Droid security review has been run across production codebases, surfacing findings that went through responsible disclosure.
A few that went public: CVE-2026-42876 — external-secrets : An attacker with nothing more than ExternalSecret create permissions could weaponize a template injection path, forcing the Kubernetes operator to mint persistent service account tokens and impersonate any service account in the entire namespace.
…






