Open sourcelibrarywithout asecurityreviewMergingcode withcriticalsecurityissuesNo loggingor monitoringfor securityeventsNo securitytesting inCI/CDpipelineIgnoringsecuritywarnings independencyscansHardcodedcredentialsin sourcecodeNo inputvalidationon userinput“It works onmy machine”response tosecurityconcernsSQL querywithoutparameterizedinputsLack ofRBAC(everyone isan admin)Unpatchedcriticalvulnerabilityin productionMissingsecurityheaders(CSP, HSTS,etc.)Outdateddependencywith knownCVEsLack ofratelimiting onAPIsDisabledMFA onan adminaccountLoggingsensitivedata inplaintextDeveloperssharingpasswordsviaSlack/emailUsingeval() inproductioncodeDefaultpasswordsstill in useAPI keyexposedin a publicrepositoryUnencrypteddatabasestorage forPIIExposingsensitiveenvironmentvariables inlogsPublic S3bucket withsensitivedata"We don’thave timefor security"excuseOpen sourcelibrarywithout asecurityreviewMergingcode withcriticalsecurityissuesNo loggingor monitoringfor securityeventsNo securitytesting inCI/CDpipelineIgnoringsecuritywarnings independencyscansHardcodedcredentialsin sourcecodeNo inputvalidationon userinput“It works onmy machine”response tosecurityconcernsSQL querywithoutparameterizedinputsLack ofRBAC(everyone isan admin)Unpatchedcriticalvulnerabilityin productionMissingsecurityheaders(CSP, HSTS,etc.)Outdateddependencywith knownCVEsLack ofratelimiting onAPIsDisabledMFA onan adminaccountLoggingsensitivedata inplaintextDeveloperssharingpasswordsviaSlack/emailUsingeval() inproductioncodeDefaultpasswordsstill in useAPI keyexposedin a publicrepositoryUnencrypteddatabasestorage forPIIExposingsensitiveenvironmentvariables inlogsPublic S3bucket withsensitivedata"We don’thave timefor security"excuse

Software Engineering COP Bingo - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
  1. Open source library without a security review
  2. Merging code with critical security issues
  3. No logging or monitoring for security events
  4. No security testing in CI/CD pipeline
  5. Ignoring security warnings in dependency scans
  6. Hardcoded credentials in source code
  7. No input validation on user input
  8. “It works on my machine” response to security concerns
  9. SQL query without parameterized inputs
  10. Lack of RBAC (everyone is an admin)
  11. Unpatched critical vulnerability in production
  12. Missing security headers (CSP, HSTS, etc.)
  13. Outdated dependency with known CVEs
  14. Lack of rate limiting on APIs
  15. Disabled MFA on an admin account
  16. Logging sensitive data in plaintext
  17. Developers sharing passwords via Slack/email
  18. Using eval() in production code
  19. Default passwords still in use
  20. API key exposed in a public repository
  21. Unencrypted database storage for PII
  22. Exposing sensitive environment variables in logs
  23. Public S3 bucket with sensitive data
  24. "We don’t have time for security" excuse