Trivy Supply Chain Attack πβ οΈ
2026-05-08
Walk through how the Trivy incident unfolded, from a pull_request_target/apidiff workflow that exposed CI secrets, through incomplete rotation, to TeamPCP hijacking tags and shipping malicious GitHub Actions and binaries, and why reading /proc on runners mattered for defenders. The post ends with concrete hardening ideas like pinning actions, short-lived creds, egress limits and SBOMs, with the takeaway that no single GitHub setting fixes this. You need overlapping controls because bots can chain small mistakes fast.
π
Concurrent data retrieval
2024-10-25
Exploring the concept of asynchronicity in Python, the blog post delves into iterators, generators, coroutines, event loops, and concurrent data retrieval, highlighting the benefits of leveraging `asyncio` for efficient I/O-bound processes, and hints at tackling issues including overloading the server and race conditions.
π
A lightweight stack for a simple web app
2024-02-13
Struggling with SEO for a single-page React application, I delved into server-side rendering and explored htmx, a lightweight JavaScript library, to alleviate the issues while maintaining frontend interactivity with a concise, declarative approach that seemed promising, and also ventured into using Rust-based Axum for the backend and Askama for templates, providing insights into database setup and usage with SQLx.
π