<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Security on Software Craftsperson</title>
    <link>https://www.softwarecraftsperson.com/categories/security/</link>
    <description>Recent content in Security on Software Craftsperson</description>
    <image>
      <title>Software Craftsperson</title>
      <url>https://www.softwarecraftsperson.com/logos/web/png/Color%20logo%20-%20no%20background.png</url>
      <link>https://www.softwarecraftsperson.com/logos/web/png/Color%20logo%20-%20no%20background.png</link>
    </image>
    <generator>Hugo -- 0.147.1</generator>
    <language>en</language>
    <lastBuildDate>Wed, 01 Apr 2026 09:00:00 +0100</lastBuildDate>
    <atom:link href="https://www.softwarecraftsperson.com/categories/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Practical GitHub Repository Hardening for a Hugo Site</title>
      <link>https://www.softwarecraftsperson.com/posts/github-repository-hardening-playbook/</link>
      <pubDate>Wed, 01 Apr 2026 09:00:00 +0100</pubDate>
      <guid>https://www.softwarecraftsperson.com/posts/github-repository-hardening-playbook/</guid>
      <description>A practical playbook for hardening a Hugo repository with reproducible builds, dependency controls, secret scanning, Semgrep, scorecards, and local guardrails.</description>
    </item>
    <item>
      <title>When Your Workplace Controls Your Personal GitHub Repos: Understanding GitHub Org Policies</title>
      <link>https://www.softwarecraftsperson.com/posts/github-org-policies-affect-personal-repos/</link>
      <pubDate>Wed, 01 Apr 2026 09:00:00 +0100</pubDate>
      <guid>https://www.softwarecraftsperson.com/posts/github-org-policies-affect-personal-repos/</guid>
      <description>Joining a GitHub organisation with your personal account means enterprise policies can silently restrict your private repos. Here is how GitHub permission layers work and what to expect.</description>
    </item>
    <item>
      <title>How and Why should you Sign Git Commits with GPG: A Practical Guide</title>
      <link>https://www.softwarecraftsperson.com/posts/2024-11-12-signing-gpg-commit/</link>
      <pubDate>Thu, 12 Dec 2024 09:00:00 +0000</pubDate>
      <guid>https://www.softwarecraftsperson.com/posts/2024-11-12-signing-gpg-commit/</guid>
      <description>Learn how to sign Git commits with GPG, why commit signing matters for security and trust, and step-by-step setup for macOS, Linux and GitHub. Prevent identity spoofing and enable verified commits.</description>
    </item>
  </channel>
</rss>
