Everything here is v0. Experimental code, technical deep-dives, and core logic.
Everything here is v0. Experimental code, technical deep-dives, and core logic.
Collect, score, and surface deep-dive candidates across OAuth WG, WIMSE, and OpenID Foundation specs
Python
Minimal end-to-end demo of SLSA Build L3 provenance: a 12-line Go binary that signs its own provenance on every tag, plus a verifier walkthrough.
Shell
Collect, score, and surface deep-dive candidates across OAuth WG, WIMSE, and OpenID Foundation specs
MCP server fronting an OpenID AuthZEN 1.0 PDP — lets LLM agents query a real Policy Decision Point
Build an xDS control plane from raw protobuf, in the spirit of Kubernetes the Hard Way. Rust + tonic + xds-api.
Weekly deep-dive reports on AWS — IAM/identity focused, automatically collected via GitHub Actions and published as a static site.
Eight locally-verified microsegmentation patterns (K8s NetworkPolicy, Cilium L7, Calico, Istio mTLS, SPIFFE/SPIRE, nftables, OPA Gatekeeper, LocalStack AWS SG)
secure-by-default github template for oss: signed commits, sha-pinned actions, slsa v1.0 provenance, sigstore keyless signing, npm oidc publishing.
A visual explainer for software supply chain security: six stages, six real attacks, six defenses.
Build a WebAuthn Relying Party from scratch: CBOR, COSE, attestation, signature verification by hand. No py_webauthn, no fido2 library.
AWS Signature Version 4 in under 100 lines of pure Python, no external dependencies. Companion to a dev.to hands-on article.
Loading…
Loading…