Everything here is v0. Experimental code, technical deep-dives, and core logic.
Everything here is v0. Experimental code, technical deep-dives, and core logic.
Collect, score, and surface deep-dive candidates across OAuth WG, WIMSE, and OpenID Foundation specs
secure-by-default github template for oss: signed commits, sha-pinned actions, slsa v1.0 provenance, sigstore keyless signing, npm oidc publishing.
A visual explainer for software supply chain security: six stages, six real attacks, six defenses.
Weekly deep-dive reports on AWS — IAM/identity focused, automatically collected via GitHub Actions and published as a static site.
Build a WebAuthn Relying Party from scratch: CBOR, COSE, attestation, signature verification by hand. No py_webauthn, no fido2 library.
SPIFFE-compatible workload identity + OpenID AuthZEN 1.0 authorization in a single Apache-2.0 binary. Cedar PDP, SPIFFE federation, tamper-evident audit log, Kubernetes operator.
AWS Signature Version 4 in under 100 lines of pure Python, no external dependencies. Companion to a dev.to hands-on article.
MCP server exposing Open Policy Agent (OPA) Rego evaluation as a tool — for Claude Code, Cursor, and other MCP clients
MCP server fronting an OpenID AuthZEN 1.0 PDP — lets LLM agents query a real Policy Decision Point
Build an xDS control plane from raw protobuf, in the spirit of Kubernetes the Hard Way. Rust + tonic + xds-api.
Loading…
Loading…