Join us

ContentUpdates and recent posts about Sigstore..
Link
@kala shared a link, 2ย months, 2ย weeks ago
FAUN.dev()

State of Context Engineering in 2026

Context engineering has evolved in the AI engineering field since mid-2025 with the introduction of patterns for managing context effectively. These patterns include progressive disclosure, compression, routing, retrieval strategies, and tool management, each addressing a different dimension of the .. read more ย 

Link
@kala shared a link, 2ย months, 2ย weeks ago
FAUN.dev()

From zero to a RAG system: successes and failures

An engineer spun up an internal chat with a localLLaMAmodel viaOllama, a PythonFlaskAPI, and aStreamlitfrontend. They moved off in-memoryLlamaIndexto batch ingestion intoChromaDB(SQLite). Checkpoints and tolerant parsing went in to stop RAM disasters. Indexing produced 738,470 vectors (~54 GB). They.. read more ย 

From zero to a RAG system: successes and failures
Link
@devopslinks shared a link, 2ย months, 2ย weeks ago
FAUN.dev()

Scaling a Monolith to 1M LOC: 113 Pragmatic Lessons from Tech Lead to CTO

The post discusses performance issues related to page counts, long cron-job reads, RAM pressure, and offloading work to background jobs. It also touches on common sources of front-end performance issues, the importance of running EXPLAIN on DB queries, and the benefits of cultivating a culture of op.. read more ย 

Link
@devopslinks shared a link, 2ย months, 2ย weeks ago
FAUN.dev()

Deployment strategies: Types, trade-offs, and how to choose

Deployment strategies control traffic shifts, rollback speed, and release risk. Options:canary,blueโ€‘green,rolling,feature flags,shadow,immutable, andGitOps. Strategies trade production risk for setup cost. They pair withArgo Rollouts,Kayenta,ArgoCD/Flux, service meshes, and flag platforms. Pipelines.. read more ย 

Deployment strategies: Types, trade-offs, and how to choose
Link
@devopslinks shared a link, 2ย months, 2ย weeks ago
FAUN.dev()

Supply Chain Attack on Axios Pulls Malicious Dependency from npm

A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the projectโ€™s GitHub releases... read more ย 

Link
@devopslinks shared a link, 2ย months, 2ย weeks ago
FAUN.dev()

RAM is getting expensive, so squeeze the most from it

The Register contrastszramandzswap. It flags a patch that claims up to 50% fasterzramops. It notes Fedora enableszramby default. It details thatzramprovides compressed inโ€‘RAM swap (LZ4).zswapcompresses pages before writing to disk and requires onโ€‘disk swap... read more ย 

RAM is getting expensive, so squeeze the most from it
Link
@devopslinks shared a link, 2ย months, 2ย weeks ago
FAUN.dev()

Scaling Autonomous Site Reliability Engineering: Architecture, Orchestration, and Validation for a 90,000+ Server Fle

Cloudways scaled from a bootstrapped startup to a leading managed PHP hosting service, encountering challenges with growing support load. Early on, Cloudways recognized the opportunity to implement an AI-based SRE agent to reduce the burden on support teams and provide faster diagnosis and resolutio.. read more ย 

Scaling Autonomous Site Reliability Engineering: Architecture, Orchestration, and Validation for a 90,000+ Server Fle
Story
@laura_garcia shared a post, 2ย months, 3ย weeks ago
Software Developer, RELIANOID

๐˜—๐˜ฐ๐˜ด๐˜ต-๐˜˜๐˜ถ๐˜ข๐˜ฏ๐˜ต๐˜ถ๐˜ฎ ๐˜Š๐˜ณ๐˜บ๐˜ฑ๐˜ต๐˜ฐ๐˜จ๐˜ณ๐˜ข๐˜ฑ๐˜ฉ๐˜บ: Preparing for ๐˜๐—ต๐—ฒ ๐—ก๐—ฒ๐˜…๐˜ ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—˜๐—ฟ๐—ฎ

๐Ÿš€ ๐˜—๐˜ฐ๐˜ด๐˜ต-๐˜˜๐˜ถ๐˜ข๐˜ฏ๐˜ต๐˜ถ๐˜ฎ ๐˜Š๐˜ณ๐˜บ๐˜ฑ๐˜ต๐˜ฐ๐˜จ๐˜ณ๐˜ข๐˜ฑ๐˜ฉ๐˜บ: Preparing for ๐˜๐—ต๐—ฒ ๐—ก๐—ฒ๐˜…๐˜ ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—˜๐—ฟ๐—ฎ Quantum computers are approaching, and with them comes a threat to traditional encryption like RSA and ECC. At ๐—ฅ๐—˜๐—Ÿ๐—œ๐—”๐—ก๐—ข๐—œ๐——, weโ€™re taking action now to ensure your infrastructure stays secure in a post-quantum world. How weโ€™re prepar..

Story FAUN.dev() Team
@eon01 shared a post, 2ย months, 3ย weeks ago
Founder, FAUN.dev

16 Things Anthropic Didn't Want You to Know About Claude Code

Claude Code

Earlier today (March 31, 2026), Anthropic accidentally shipped the full source code of Claude Code inside an npm package. The 512,000 lines of TypeScript have since been picked apart by the developer community, and what's inside is more revealing than anyone expected.

Claude Code Leaked
News FAUN.dev() Team Trending
@kala shared an update, 2ย months, 3ย weeks ago
FAUN.dev()

Anthropic Accidentally Leaks Claude Code's Entire Source Code via npm

#Claude ...ย  #Claude ...ย  #NPMย  #Anthrop...ย  #AIย 
Claude Code

Anthropic shipped a source map file inside the latest npm release of Claude Code - and with it, the full source code of its flagship AI coding CLI. The leak exposed 512,000 lines of TypeScript across 1,900 files, 43 built-in tools, 44 feature flags, 26 hidden slash commands, and over 120 secret environment variables. It is one of the most detailed accidental exposures of a commercial AI product's internals to date.

Claude Code leaked source
Sigstore is an open source initiative designed to make software artifact signing and verification simple, automatic, and widely accessible. Its primary goal is to improve software supply chain security by enabling developers and organizations to cryptographically prove the origin and integrity of the software they build and distribute.

At its core, sigstore removes many of the traditional barriers associated with code signing. Instead of managing long-lived private keys manually, sigstore supports keyless signing, where identities are issued dynamically using OpenID Connect (OIDC) providers such as GitHub Actions, Google, or Microsoft. This dramatically lowers operational complexity and reduces the risk of key compromise.

The sigstore ecosystem is composed of several key components:

- Cosign: A tool for signing, verifying, and storing signatures for container images and other artifacts. Signatures are stored alongside artifacts in OCI registries, rather than embedded in them.

- Fulcio: A certificate authority that issues short-lived X.509 certificates based on OIDC identities, enabling keyless signing.

- Rekor: A transparency log that records signing events in an append-only, tamper-evident ledger. This provides public auditability and detection of suspicious or malicious signing activity.

Together, these components allow anyone to verify who built an artifact, when it was built, and whether it has been tampered with, using publicly verifiable cryptographic proofs. This aligns closely with modern supply chain security practices such as SLSA (Supply-chain Levels for Software Artifacts).

sigstore is widely adopted in the cloud-native ecosystem and integrates with tools like Kubernetes, container registries, CI/CD pipelines, and package managers. It is commonly used to sign container images, Helm charts, binaries, and SBOMs, and is increasingly becoming a baseline security requirement for production software delivery.

The project is governed by the OpenSSF (Open Source Security Foundation) and supported by major industry players.