Writing

Notes from the systems I keep running.

What I learn building and running production systems — the architecture calls, the security decisions, and the parts nobody puts in a demo. Written after the thing shipped, not before.

AllSecurityDevOps
01

Surviving the Shai-Hulud era: runtime scanning and an SBOM that actually blocks something

A worm that harvests your tokens and republishes itself through your own packages doesn't care how careful you were last quarter. What I changed in our pipelines afterwards.

Security
Aug 2026 · 11 min

Get new posts by email

One email a month, nothing else. Notes from systems that are actually running.