// docs / security guides
Güvenlik kılavuzları
Cursor, Claude Code, Lovable, Bolt, v0, Replit ve Windsurf ile oluşturulan uygulamaların güvenliğini sağlamaya yönelik ayrıntılı, çerçeve uyumlu kılavuzlar. Her kılavuz tek başına tasarlanmıştır; şu anda yapmakta olduğunuz işe uygun olanı seçin. FixVibe tarama motorunda yeni saldırı sınıfları göründükçe daha fazla kılavuz buraya gelecek.
// category overview
AI-oluşturulan kod güvenliği taraması: titreşim kodlu uygulamalar için DAST
AI-oluşturulan uygulamalar neden geleneksel pentest araçlarından farklı taramaya ihtiyaç duyuyor? Vibe kodlu uygulamalarda orantısız bir şekilde görünen on güvenlik açığı sınıfını kapsar; kod tabanı yarı makine tarafından oluşturulduğunda DAST ve SAST, bir tarayıcıda nelere bakılması gerektiği ve FixVibe'nin Burp Suite, OWASP ZAP ve Nessus ile karşılaştırılması.
Tarayıcı astarını okuyun →
// pre-ship audit
Vibe kodlama güvenlik kontrol listesi: Göndermeden önce 51 öğe
Cursor, Claude Code, Lovable ve Bolt ile oluşturulan uygulamalar için pratik, aşamalara göre düzenlenmiş bir kontrol listesi. Yedi kategori - sırlar, veritabanı, kimlik doğrulama, başlıklar, üçüncü taraf, dağıtım, izleme - her biri dağıtım öncesi / dağıtım sırasında / dağıtım sonrası olarak etiketlenen 51 işlem yapılabilir öğeyle.
Kontrol listesini aç →
// step-by-step
AI kodlama araçlarıyla oluşturulmuş bir uygulamanın güvenliği nasıl sağlanır?
Kod parçacıklarıyla adım adım sağlamlaştırma. AI-oluşturulan uygulamalar neden farklı şekilde başarısız oluyor, anında kod tabanı denetimi, dağıtım zamanı güçlendirme (ara yazılım, CSP, RLS, yalnızca sunucu kimlik doğrulaması), sürekli izleme ve gerçek düzeltmeleriyle birlikte beş gerçek hata modeli.
Sertleştirme kılavuzunu başlatın →
// cursor-specific checklist
Cursor uygulama güvenliği kontrol listesi
A 25-item hardening guide targeting Cursor-specific patterns: autocomplete inlines service keys, generated multi-file edits land without review, Agent mode runs terminal commands, and project rules (
.cursor/rules) are your first security guardrail. Pre-deploy, at-deploy, and post-deploy checks for Cursor workflows.Cursor kılavuzunu okuyun →
// tool-specific guides
Security checklists for Lovable, Bolt, v0, Replit, and Firebase Studio
A comprehensive pre-ship audit for founders launching AI-built SaaS. Covers customer data isolation, billing + Stripe, authentication + sessions, PII + compliance, operational readiness, external attack surface, observability, and final verification — 36 actionable items designed to complete in one week.
Browse the platform guides →
// structural analysis
AI kodlama araçları neden güvenlik açıkları bırakıyor?
Cursor, Claude Code, Lovable, Bolt ve v0'daki yapısal kör noktaların dürüst bir analizi. Eğitim verilerinin önyargısı, otomatik tamamlama dinamikleri, uzun vadeli bağlamın olmaması ve metrik olarak hız, öngörülebilir güvenlik açıkları yaratır. Her boşluk sınıfının temel nedenini ve onu kapatan iyileştirme modelini öğrenin.
Boşluk analizini okuyun →
// scanner selection
AI-yerleşik uygulamalar için bir güvenlik tarayıcısı seçme
Comparison and decision framework for picking the right scanner — FixVibe, Burp Suite, ZAP, Snyk, Semgrep and Aikido. Covers the evaluation criteria that matter for AI-generated SaaS (BaaS coverage, JS bundle inspection, framework awareness, active-probe gating), a side-by-side table, and a decision matrix for six common scenarios.
Tarayıcıları karşılaştırın →
// platform kontrol listesi
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations,
import.meta.envleaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.Kontrol listesini aç →
// platform kontrol listesi
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
Kontrol listesini aç →
// platform kontrol listesi
v0 security checklist: 22 items for Next.js
v0 generates React + Tailwind + shadcn/ui components and full Next.js apps for Vercel. This checklist targets v0-specific risks: design iterations that re-add dangerouslySetInnerHTML, exported codebases that lose middleware, Server Actions that skip auth verification, and environment variables that have to be set again once the code lives in your own repo. 22 items across secrets, database, auth, headers, deployment, and v0-specific gotchas.
Kontrol listesini aç →
