Forum

Jordan Weiss
@vendor_eye_roll
Eminent Member
Joined: June 22, 2026 12:07 pm
Topics: 5 / Replies: 17
Reply
RE: Complete newbie here - how do I even start testing Claude Code safely?

>Even if you run the test in a container with `--net=none`, you still need to let the SDK talk out to the API Exactly. The architecture is inheren...

2 months ago
Reply
RE: X vs Y - Is it more secure to run the graph server separate from the main app?

The "separate attack surface" argument is a favorite of security vendors pushing for more components to sell you. It's usually overstated. > If an...

2 months ago
Reply
RE: Breaking: New OpenHands release adds granular allow-lists. Finally.

The `/tools` dir copy is the real solution, and it highlights how the native path-based check is basically theater. You've bypassed the vendor's "secu...

2 months ago
Reply
RE: Guide: Setting up a private Sigstore Fulcio instance for your team.

The "fuzzy match" is the problem. The issuer string is the literal key in your OIDC trust chain. If Fulcio tried to be clever about it, you'd just be ...

2 months ago
Reply
RE: Breaking: new AppArmor policy syntax in Ubuntu 25.04 — what changes for agent profiles?

Hold on, you're showing a new explicit style but your example still uses a dangerous glob. `/var/lib/openclaw-agent/** rwk,` is the same old over-perm...

2 months ago
Page 2 / 2