ITaaS Agency - Landing PageLanding page for a business that offers IT-as-a-Service services.
A proof-of-concept landing page for a fictitious IT-as-a-Service (ITaaS) company to showcase its services and facilitate customer engagement. The website highlights the benefits of using the company's services and provides a way for potential customers to contact the business.
Personal Portfolio (V2)Content-driven Next.js SSG with multi-env CDN delivery
A Next.js static portfolio that clones a private MDX/JSON content repo at build time, indexes five typed collections through a ContentRepository, ships SEO-ready HTML with sitemap + IndexNow, and deploys preview on GitHub Pages and production on S3 + CloudFront + Route 53.
#GitHub Actions
Projects
Posts
GitHub Actions: An In-Depth Guide to Automating Your Software Development LifecycleA Comprehensive Overview of GitHub Actions' Features and Best Practices
Dive into the power of GitHub Actions for automating your software development lifecycle. Explore features, best practices, and code examples to get the most out of this robust platform.
GitHub Actions Runners: A Deep Dive from Basics to Advanced ArchitectureUnderstanding the Engine Behind Every CI/CD Pipeline on GitHub
Explore GitHub Actions runners in depth - architecture, self-hosted scaling, security risks, and best practices for professional engineering teams.
Deploy Vite React with React Router App to GitHub PagesA Comprehensive Guide to Deploying Vite-React Projects on GitHub Pages
Looking to deploy your Vite React app with React Router to GitHub Pages? This step-by-step guide will walk you through the process, covering everything from GitHub Actions to common pitfalls.
How to Automate Static Asset Deployment with CI/CD (No Manual Steps)Cut release time in half by integrating asset builds directly into your pipeline
Learn how to automate static asset processing and deployment inside your CI/CD pipeline, with examples for GitHub Actions and Webpack.
pull_request vs. pull_request_target: The GitHub Actions Trigger Hiding a Security NightmareUnderstanding the critical difference between these two triggers and why one could give attackers RCE on your repository.
Learn the security-critical distinction between `pull_request` and `pull_request_target` in GitHub Actions. One is safe for forks, the other could expose your secrets and code.
Am I Vulnerable? How to Audit Your GitHub Actions for the pull_request_target FlawA practical guide to finding and fixing the common misconfiguration that allows untrusted code to run with privileged access.
Audit your GitHub workflows for a critical security flaw. This guide helps you identify if your use of `pull_request_target` is checking out untrusted code.
The 'Pull Request Nightmare': How RCE Was Found in Google & Microsoft ReposA deep dive into the critical security flaw discovered by Orca Security (roin-orca) and how it turned simple PRs into critical threats.
Explore the `pull_request_target` vulnerability found by Orca Security. See how Fortune-100 companies were exposed to RCE from a single malicious pull request.
3 Ways to Secure Your GitHub Workflows from Malicious Pull RequestsDon't get hacked. Implement these best practices today to safely handle pull requests from forks without disabling your automations.
Secure your GitHub Actions. Learn 3 essential mitigation techniques: checking PR origins, using manual approval labels, and gating jobs with environments.
Why Is pull_request_target So Dangerous? A Security ExplainerIt runs in the context of the base repo, has access to your secrets, and can run untrusted code. Here's what you need to know.
The `pull_request_target` trigger in GitHub Actions is a major security risk if misused. Understand why it's dangerous and how it exposes repository secrets.
Coursework
Natours - Tours in the NatureLanding Page prototype for a Green Outdoor Tours Business
Fictional business that offers green outdoor tours in the Carpathian mountains. This project is a landing page for the business built using modern technologies and best practices in web development. The page is fully responsive, accessible, and optimized for search engines.
Trillo - All-in-One Booking AppUI for fictional All-in-One Booking App
Trillo is a fictional All-in-One Booking App that allows users to book hotels, flights, cars, and tours in one platform. The project is currently in the frontend mockup stage, built using modern technologies and best practices in web development. The mockup is a single-page application that is fully responsive, accessible, and optimized for search engines.
Nexter - Luxury Real EstateUI for Landing Page of a Luxury Real Estate Portal
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt