sanjay.hona
Local time in Ottawa, Canada:--:--ET
← all tags

#security

1 post

  1. Hardening a static site: pinned actions, least privilege, and a CSP that can't drift

    A portfolio site has no backend, but its build pipeline and the edge in front of it still deserve a threat model. What I changed and why.

    #security#github-actions#csp#cloudflare4 min read