The gpg command that hung (so I built signing into the tool)
A gpg call that hung and never returned, and why release signing ended up built into the Go tool itself rather than shelled out to the gpg binary.

A gpg call that hung and never returned, and why release signing ended up built into the Go tool itself rather than shelled out to the gpg binary.

When a desktop CLI posts on your behalf, the OAuth tutorial assumption of a server holding the client secret collapses. What replaces it.

Two new public modules extracting the OpenPGP signing and verification model, so you can use it without adopting the whole framework.

The kill-switch answer to AI autonomy does not survive contact with how these systems actually run. Governance is not a button.

Embed the trust anchor in your binary and require signature verification on update, without bricking anyone already running an old build.

Hundreds of malicious package versions across three ecosystems, and the uncomfortable fact that installing one runs arbitrary code.

Whoever controls your release page can swap a binary, and a checksum hosted beside it proves nothing. A seven-part guide to signing releases.

A fresh AWS account cannot enable GuardDuty or Security Hub without a subscription, so the security baseline failed on the account it protects.

The cash prize for anything that looked like a finding was the accelerant, and AI only made plausible-looking reports free to produce.

Routing AWS GuardDuty and Security Hub findings so an alert still means something: forward high severity only, and drop the duplicates.
