Back to Home

Cybersecurity & Trust Posts

Cybersecurity & Trust

Verifying Slsa Provenance For Oci Artifacts With Cosign And Rekor In Github Actions

The problem I kept hitting in software supply chain security I got tired of “trust me” release pipelines. Even when I used code signing and pinned d...

Jun 3, 2026Read more
Cybersecurity & Trust

Zero Trust Architecture With Http Dpop Proof Binding For Ci Ephemeral Tokens

I fell into this rabbit hole because I kept seeing the same annoying pattern in my homelab: my CI pipeline would mint short-lived API tokens, those to...

May 7, 2026Read more
Cybersecurity & Trust

Hardening An Llm Token Router Against Prompt Injection With Policy-Aware Beam Search

The weekend problem I couldn’t stop thinking about I was building an “AI assistant” that had to call internal tools (like fetching account metadata)...

May 4, 2026Read more
Cybersecurity & Trust

Parsing Opencti Threat Intelligence To Produce Sbom-Like Incident Fingerprints

I got tired of treating “threat intelligence” like a blob of text—some feeds said “APT29”, others said “malware family”, and in practice my SOC (secur...

Apr 28, 2026Read more
Cybersecurity & Trust

Building A Go Module Source Attestation Check Using Sigstore And Rekor

I stumbled into a weird corner of software supply chain security while debugging a “perfectly signed” release that still felt untrustworthy: the signa...

Apr 6, 2026Read more
Cybersecurity & Trust

Verifying Sigstore Fulcio Certificates For Slsa 4 Provenance In Ci

The problem that got me curious I hit a weird failure in a CI pipeline that “looked secure” on paper: the pipeline was verifying artifacts, but it w...

Apr 3, 2026Read more