Pin your GitHub Actions
Secure your GitHub Actions by pinning them to commit SHAs, preventing supply chain attacks. Learn how to automate updates and enforce best security practices.
The tj-actions/changed-files compromise prompted me to write up how I secure GitHub Actions workflows using SHAs without maintenance pain
Go from insecure to security conscious in < 15 minutes, including configuring automatic updates through Dependabot or Renovate
michaelheap.com/pin-your-git...
15.03.2025 20:41 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0
Manager: "What's this milestone 'Living on a prayer' ?"
Me: "That's the documentation deliverable."
Manager: "What's the status of that?"
Me: "We're halfway there"
Manager: "Why is progress so slow?"
Me: "You fired Tommy"
Manager: "So?"
Me: "Tommy used to work on the docs"
23.02.2025 21:12 โ ๐ 4958 ๐ 1374 ๐ฌ 86 ๐ 81
Quality > Speed > Scope
Never compromise on quality. Never compromise on speed. Ship regularly, and deliver value faster.
More flights means more writing. This time, I've explicitly written down my thoughts on the quality <> speed <> scope tradeoff for teams that I work with (now, and in the future)
michaelheap.com/quality-spee...
23.02.2025 14:05 โ ๐ 2 ๐ 1 ๐ฌ 1 ๐ 0
Using AWS credential_process and 1Password
Store your AWS credentials securely in 1Password and load them at runtime using the AWS CLI's `credential_process` helper
More time on planes means more time to polish up old drafts.
This time, how to source your AWS credentials from 1Password when using the aws CLI
michaelheap.com/aws-credenti...
18.02.2025 17:33 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
Slack channels are free
Good Slack hygiene isnโt about having fewer channels - itโs about having the right channels.
Some people think that one gigantic Slack channel is the way to communicate. I don't know why, but they do.
Don't be like them.
michaelheap.com/slack-channe...
13.02.2025 12:07 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
"Bikeshedding" is a potentially confusing term, we should discuss possible options for alternative names
19.12.2024 16:45 โ ๐ 27 ๐ 11 ๐ฌ 2 ๐ 1
Trick question. There is no herding Kats
01.12.2024 17:56 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
I even took things I wanted _off_ the list after doing a final round of research
(Iโm looking at you, AirPods Max)
01.12.2024 17:47 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
What I found interesting is that I had a well researched list for most of it. Very few impulse buys
Some of the items are frivolous (gaming headset), some are needed (clothes)
All of them will bring us joy, and Iโm looking forward to not having to think about any of them for 5 more years
01.12.2024 17:45 โ ๐ 3 ๐ 0 ๐ฌ 1 ๐ 0
This weekโs festival of consumerism has been a great success*
After many years of โthis will last a little longerโ I bit the bullet and replaced everything thatโs > 5 years old (most are 8-10)
* (for some definition of success)
01.12.2024 17:45 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
Iโd forgotten all about Warzone 2100! Played it on the PSX years ago. A fine choice
24.11.2024 19:31 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
More seriously, hi! Iโm Michael. I do product-y type things with a focus on developer experience. Once upon a time I was a developer, but now thatโs just at weekends.
I also talk about: weightlifting, parenting, hiking and games. Usually not in that order.
Say hello! We might just become friends โค๏ธ
24.11.2024 19:15 โ ๐ 2 ๐ 0 ๐ฌ 1 ๐ 0
I planned to write something insightful as my pinned intro post, but then I saw this.
Introduce yourself with four video games:
24.11.2024 19:03 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 1
Hello! Yes, you there. The one looking at a screen
I heard early tech twitter was having a resurgence here
I left the bird site about 2 years ago and have happily been social-free since then
But now itโs time to come back. Iโve missed you all, and canโt wait to get to know you all over again
20.11.2024 09:11 โ ๐ 19 ๐ 0 ๐ฌ 1 ๐ 0
Open technology enthusiast | Coder | Incurable blogger | OpenAPI Technical Steering Committee | OpenUK board | Mentor | Open to job offers
Keyword, buzzword, half-truth, adjective, hey look at me! (founder of two unicorns: http://WPEngine.com, http://SmartBear.com).
Writing for 18 years at: https://longform.asmartbear.com
Tech and pictures of nature. Suffolk, UK
Independent AI researcher, creator of datasette.io and llm.datasette.io, building open source tools for data journalism, writing about a lot of stuff at https://simonwillison.net/
Head of Community DragonflyDB, #oss Advocate, #Community builder, Rugby Fan, Former #ubuntu Community & Loco Council
Executive ADHD Coach
Changing how we see ADHD in leadershipโfrom an obstacle to a secret advantage.
๐ซ Newsletter: https://sudarkoff.com/newsletter
โจ Coaching: https://sudarkoff.com/start-conversation
Sr. Director of Engineering at Cockroach Labs.
Shitposting & Memes.
Data & Stuff.
#dataBS #trailrunning
๐ https://rmoff.info
Product Management / Leadership Coach, Community Builder & Consultant
outofowls.com
cpo.social
mindtheproduct.com/podcast
Astronomer, runner & parkrunner, cyclist. Former developer, day job is now engineering director. London & Sussex, UK.
Writer of leadership things. Keynote enthusiast. I donโt tweet about my current gig. https://randsinrepose.com
Freelance Software Engineer interested in computational biology / *omics ๐งฌ. Working on https://benthos.dev, the #golang structured data stream processor. All things Open Source. Dublin, Ireland ๐ฎ๐ช ๐ท๐ด ๐บ๐ฆ ๐ณ๏ธโ๐ He / Him.
sugarbaby cosplaying as a tech consultant โข mean eastern european with unrealistically high expectations and unreasonable quality standards
๐ณ๏ธโ๐he/him๐ณ๏ธโ๐
I lift things. Also make websites and art.
Staff engineer at Figma, driving innovation into new ways to round corners.
I wrote a book on RxJS! https://pragprog.com/titles/rkrxjs/build-reactive-websites-with-rxjs/
Disaster prevention chihuahua. Reliability at PagerDuty. Living on unceded land in Punamue'katikt, Mi'kma'ki (Dartmouth, NS). May all beings be free from suffering. He/him.
also hachyderm.io/@mendel.
formerly @mendel on twitter.
www.lafferty.ca
Principal Developer Advocate at @confluent.io, โ๏ธJava Champion, Co-author Kafka in Action, Flink aficionado
Snarkmonger. Chief Cloud Economist at The Duckbill Group.
he/him.
Get my opinionated take on AWS news: http://lastweekinaws.com/t/
Signal: 833-AWS-BILL (833-297-2455)
๐ฎ Aspiring indie game dev โข ๐ฆ R&D @thekonginc โข ๐ Production #Kubernetes (O'Reilly 2021) โข Bad at parties