Skip to content

About

Devuru is an application-hardening reference: the security settings that live in the code you deploy, organised by the framework you are working in.

The scope is deliberately the application layer rather than the server underneath it. Where a problem spans both — proxies, forwarded headers, response headers — the page says so and names the part that is out of scope, so you know what still needs doing elsewhere. See application vs server.

Claims about defaults, versions and behaviour are checked against a primary source at the time of writing: the framework’s own source tree, its release notes, or its documentation. Secondary summaries are not treated as sufficient, because on this kind of material they are wrong often enough to matter.

Every page records when it was last verified and against which version. If that date is old, treat the page accordingly — and if something here is wrong or has gone stale, that is worth knowing about.

Quoted error strings are read in the source they come from, and the file is shown next to the string.

No benchmarks you can hand to an auditor, no scanner, no ranking of frameworks against each other. Where a control maps to a published OWASP ASVS requirement the id is shown, and only when it has been read in the standard itself.

Last updated: