The Hidden Risk in Your CI Pipeline: Why `pull_request_target` Is a Security Liability
pull_request_target gives CI workflows full secret access. One open PR is enough to steal credentials or poison your build cache. Here is how to fix it.
I am a technical leader and architect focused on building the infrastructure that powers modern enterprise. With a career spanning leadership roles in high-growth startups and senior consulting for various Swiss Tier-1 banks, I specialize in the intersection of Event-Driven Architecture, Data Governance, and Cloud-Native Engineering.
Currently, I serve as the CTO at Webmobix, where I oversee technical strategy and the delivery of complex digital solutions.
This site serves as a record of my expertise across the full stack, from streaming data pipelines to decentralized finance.

Along with coding I also like to write about life and technology. Here are some of my recent posts.
pull_request_target gives CI workflows full secret access. One open PR is enough to steal credentials or poison your build cache. Here is how to fix it.
I use pnpm for disk space and monorepo support. Turns out upgrading to v11 also made me immune to the May 2026 TanStack supply chain attack - here is what its defaults actually do and why they matter.
Boost your development velocity with a CSS-native design system. Learn how Tailwind v4 and daisyUI v5 replace complex JS configurations with a streamlined, semantic workflow that scales perfectly for solo builders and independent developers.
My experiences and recommendations for travelling to Korea