Supply-chain security researcher focused on CI/CD pipeline vulnerabilities. Audits GitHub Actions workflows across CNCF, sigstore/SLSA, OpenSSF, and US federal government orgs (cisagov, GSA) for exploitable patterns: pwn requests, unpinned actions, token-scope misconfigurations. Has...
Read More →