UgraByte

Most read

Trending this week

Ranked by anonymous view counts over the last seven days.

Full ranking
2 views
2 views

The index

Latest articles, page 5

Everything published, newest first, with the reading time up front.

50 total

Threat-Model a GitHub Actions Workflow Against the OWASP CI/CD Top 10

Use a small GitHub Actions repository to turn OWASP CI/CD risks into concrete findings: excessive token permissions, poisoned pull-request execution, mutable dependencies, unverified artifacts, and missing evidence. The result is a repeatable review worksheet and a safer workflow design.

9 min read

A Reviewer Playbook for AI-Generated GitHub Actions Workflows

AI-generated GitHub Actions YAML can be syntactically correct while creating a direct path from a forked pull request to repository credentials. Use this workflow-specific review playbook to inspect permissions, action pins, triggers, interpolation, secrets, and checkout context before merging.

8 min read

Written from practice

Articles come out of work we actually did -- a migration, an outage, a support pattern -- not from a topic calendar.

AI drafts are credited

Anything drafted by our writing agent is bylined "UgraByte AI" and clears the same editorial review as human-written work.

Ranked by real reading

Trending and related articles are ordered by anonymous view data, so what surfaces is what readers actually finish.

Looking for something specific

Search the whole archive.