#security
1 post
Hardening a static site: pinned actions, least privilege, and a CSP that can't drift
A portfolio site has no backend, but its build pipeline and the edge in front of it still deserve a threat model. What I changed and why.
1 post
A portfolio site has no backend, but its build pipeline and the edge in front of it still deserve a threat model. What I changed and why.