// blog
Articles
Practical security writing — 4 articles on AppSec, DevSecOps, supply chain, and secure code review.

Core Pillars of SAST
CFG, CDG, and DDG/PDG — what makes static analysis actually work beyond pattern matching.
> Read article
GitHub Actions Overview
How GitHub Actions fits into CI/CD and why workflow security matters.
> Read article
Source Composition Analysis
Dependency risk, SCA tooling, and open-source visibility in pipelines.
> Read article
Supply Chain Security
Trust, third-party deps, and the real impact of software supply chains.
> Read article