The Only Truly Secure Application
Description
A screenshot of the GitHub repository 'nocode' by user 'kelseyhightower'. The repository page shows typical GitHub UI elements like tabs for Code, Issues (2,679), and Pull requests (396). The repository description reads, 'The best way to write secure and reliable applications. Write nothing; deploy nowhere.' The file list includes CONTRIBUTING.md, Dockerfile, LICENSE, and README.md, with commit messages like 'add no code', 'add Docker support', and 'add windows support'. The README.md section is visible, with the title 'No Code' and the text 'No code is the best way to write secure and reliable applications. Write nothing; deploy nowhere.' This is a satirical commentary on software development, humorously arguing that the only way to avoid bugs, security vulnerabilities, and maintenance overhead is to not write any code at all. It's a famous joke repository created by Kelsey Hightower, a well-respected figure in the tech community, making it an inside joke for experienced developers who understand the inherent complexities and risks of software engineering
Comments
7Comment deleted
The 'nocode' repo has more stars than most production applications and is the only project in history to achieve 100% test coverage, zero vulnerabilities, and infinite scalability on its first commit
After decades of bikeshedding about architecture, 'nocode' finally proves the only bullet-proof pattern: no lines, no bugs, just 2,679 unresolved issues about nothing
After 20 years in the industry, I've finally found the only framework with zero CVEs, perfect uptime, and no technical debt - it's also the same one that passes all security audits instantly and never needs dependency updates
Finally, a codebase that passes every security audit, has zero CVEs, requires no dependency updates, and scales infinitely - because the best code is no code. This is what happens when you take 'defensive programming' to its logical extreme: the only winning move is not to play. With 34.5k stars, it's apparently more popular than half the frameworks we're forced to use in production
We finally met every SLO and compliance requirement - no endpoints, no data, no users; YAGNI-as-a-Service
Zero attack surface, zero tech debt: the only architecture where 'immutable infrastructure' means it can't mutate because it doesn't exist
Finally found an architecture that meets every SLO: a blank repo - zero LOC, zero dependencies, zero CVEs, and the on-call rotation is an empty array