Security blog

AI security notes and shipped PRs.

Short notes from OSS security work, followed by the pull requests that shipped.

Read latest post

Merged PRs

Recent security work

Full PR list →

Blog

Latest posts

All posts →
CI coverage is part of the evidence boundary Reference integrity is an evidence boundary LLM candidates need explicit evidence contracts Upload writes and evidence gates need sink-side proof Sinks are where trust boundaries become real