Exploiting a GitHub Actions Script Injection (and Stealing a Secret)
A hands-on walkthrough of script injection in GitHub Actions: building a vulnerable workflow, setting up a listener server, exfiltrating a real secret, and finally fixing it.
2542 words
|
13 minutes
RPC Nodes — What They Are and Why Yours Lagging Will Ruin Your Day
Defining nodes in web3, the types you run into, and a debugging story where a stale REST endpoint silently broke our resolver.
1450 words
|
7 minutes
UI Feature Flags — How We Ship WIP UX in ymax
A persisted console-toggle pattern for gating work-in-progress UI behind a flag that devs and designers can flip from DevTools without a deploy.
1264 words
|
6 minutes
Money Is a 6000-Year-Old Distributed Systems Problem
The history of money, reframed as a series of engineering problems — discovery, standardization, attestation, indirection, consensus.
5434 words
|
27 minutes
Postgres From Zero — A Practical Setup Guide
Install Postgres, connect to it, create a database, run queries, and understand the bits you actually use day-to-day.
1396 words
|
7 minutes

