Practical security writing for engineers building modern products.
Sharing hands-on notes across AppSec, DevSecOps, threat modeling, secure code review, cloud security, and mobile application testing.
Black Hat Arsenal Europe speaker, Seasides conference contributor, and builder of open-source security labs and learning resources.
Blogs shown for All.
Click categories above and the matching blog boxes update here on the same page.
Overview About GitHub Actions
Understand how GitHub Actions fits into CI/CD and why workflow automation matters for secure software delivery.
Source Composition Analysis
A practical introduction to dependency risk, SCA tooling, and why open-source visibility belongs in modern pipelines.
Supply Chain Security
A broader look at trust, third-party dependencies, and the security impact of software supply chains.
Beyond the articles
See the portfolio for open-source work, conference highlights, contributions, and technical strengths.
The portfolio page stays separate so the homepage remains minimal, attractive, and centered on content discovery.