I write an application-security tool called SecHelix. Last week I added a GitHub

Action to it. Before merging, I pointed the tool at its own new Action.

It found two real defects. Neither would have failed a test. Both were the kind

of thing I would have shipped.

This is a post about those two bugs, because they are better arguments for