Static analysis to prevent Zip Bombs and architectural bottlenecks
2 points
1 hour ago
| 1 comment
| codeprot.com
| HN
allenz_cheung
1 hour ago
[-]
Hi HN, I'm working on CodeProt. We recently wrote about how we use static analysis (AST and data-flow) to catch performance killers like Zip Bombs and architectural bottlenecks (e.g., full DB reloads) early in the review process.

We found that performance isn't just about speed—it's about availability. A single unconstrained extraction or a bad architectural pattern can bring down a system just as effectively as a DDoS.

Curious to hear how others are automating these kinds of architectural checks.

reply
bediger4000
45 minutes ago
[-]
Do you want spammers and scrapers to triumph!?! A zip bomb is a good way for the righteous to let it be known that unclean scrapers should stay away.
reply
theamk
22 minutes ago
[-]
Yes, they do. Remember, OP is build AI-powered review tools. Their technology won't exist without scrapers.
reply