Two Cycles, One Codebase: How AI, Fix Automation, and OASIS Are Rewriting the Role of Application Security
Language: English
Published by Independently published, 2026
- Softcover
- New

Seller: California Books, Miami, FL, U.S.A.California Books
5-star seller
AbeBooks seller since October 27, 2023
Softcover
Condition: New
US$ 29.00
Free Shipping
Ships within U.S.A.
Quantity: Over 20 available
Add to basketFree 30-day returns
Item description from seller
Print on Demand.
Seller Inventory # I-9798190467666
- Title
- Two Cycles, One Codebase: How AI, Fix Automation, and OASIS Are Rewriting the Role of Application Security
- Author
- Kosorok, David John; Cartsonis, Michael; Holt, Chris
- Publisher
- Independently published
- Publication year
- 2026
- Condition
- New
- Binding
- Soft cover
- Language
- English
- ISBN 13
- 9798190467666
The vulnerability count on every CISO's dashboard keeps climbing. AI-assisted development shipped more code last quarter than the quarter before, and much of it needs fixing faster than any human team can manage. The math stopped working, and the industry's usual response, more dashboards, more scanners, more gates, only added weight to a system already buckling.
TWO CYCLES, ONE CODEBASE makes the case that application security is undergoing its most significant operating-model shift since the introduction of source control. The authors call it the dual cycle: two continuous processes running in parallel against the same codebase, one building features, one reducing risk, both increasingly powered by AI on the generation side and human judgment on the validation side. The two cycles meet at a single, bounded transaction the authors call the validation handshake, where every AI-generated fix earns its way into the codebase through human approval.
This book traces that model from first principles through its first public proof: OASIS, now an official OWASP project, where a global community of validators reviews AI-generated security fixes for open source software at a scale no single vendor or maintainer could reach alone. It closes with the enterprise playbook: how a CISO introduces the model, what changes operationally, which metrics survive the transition, and what AppSec looks like once remediation becomes continuous rather than episodic.
Written by three practitioners who arrived at the same conclusion from different directions, an enterprise security executive, a fix-automation founder, and a bug-bounty and open-source community leader, this is not a vendor pitch or a product comparison. It is an operating model, built to outlast whichever tools implement it, for CISOs, AppSec leaders, engineering executives, and every practitioner who has quietly recognized that the old model no longer scales.
Each chapter closes with an Operating Question to apply to your own environment and a This Week's Move to turn the idea into action before the next chapter starts. This book is meant to be operational, not theoretical, short enough to read on a flight, and useful enough to keep on the shelf as reference material long after.
The fight application security has been losing for years is winnable now. This book shows you how.
TWO CYCLES, ONE CODEBASE makes the case that application security is undergoing its most significant operating-model shift since the introduction of source control. The authors call it the dual cycle: two continuous processes running in parallel against the same codebase, one building features, one reducing risk, both increasingly powered by AI on the generation side and human judgment on the validation side. The two cycles meet at a single, bounded transaction the authors call the validation handshake, where every AI-generated fix earns its way into the codebase through human approval.
This book traces that model from first principles through its first public proof: OASIS, now an official OWASP project, where a global community of validators reviews AI-generated security fixes for open source software at a scale no single vendor or maintainer could reach alone. It closes with the enterprise playbook: how a CISO introduces the model, what changes operationally, which metrics survive the transition, and what AppSec looks like once remediation becomes continuous rather than episodic.
Written by three practitioners who arrived at the same conclusion from different directions, an enterprise security executive, a fix-automation founder, and a bug-bounty and open-source community leader, this is not a vendor pitch or a product comparison. It is an operating model, built to outlast whichever tools implement it, for CISOs, AppSec leaders, engineering executives, and every practitioner who has quietly recognized that the old model no longer scales.
Each chapter closes with an Operating Question to apply to your own environment and a This Week's Move to turn the idea into action before the next chapter starts. This book is meant to be operational, not theoretical, short enough to read on a flight, and useful enough to keep on the shelf as reference material long after.
The fight application security has been losing for years is winnable now. This book shows you how.
"Synopsis" may belong to another edition of this title.
California Books
Miami, FL, U.S.A.
5-star seller
AbeBooks seller since October 27, 2023
Shipping rates within U.S.A.
| Item | 3 to 7 business days | 2 to 5 business days |
|---|---|---|
| First item | US$ 0.00 | US$ 12.00 |
Payment methods
Store description
We have 20 years experience selling books worldwide! Friendly customer support. Your satisfaction guaranteed!
Specialty
All authorized categoriesSeller's business information
Miramar International Services LLC
FL, U.S.A.
Terms of sale
www.californiabooks.com
Shipping terms
www.californiabooks.com