Skip to content
View jijo-OO7's full-sized avatar
:octocat:
Solving yesterday's problems with tomorrow's code
:octocat:
Solving yesterday's problems with tomorrow's code

Block or report jijo-OO7

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
jijo-OO7/README.md

GitHub Banner

Hello World! , I'm Suman Mandal

๐Ÿ› ๏ธ Languages and Tools

Javaย  MySQLย  MongoDBย  Goย  Gitย  Dockerย  Kubernetesย  Terraformย  Linuxย  Bashย 

๐Ÿ” Featured Security Engineering Work

Kubescape Report Protection

Designed and shipped a multi-stage report-protection workflow in Kubescape, evolving from deterministic anonymization of Kubernetes resource metadata into reversible encryption and decryption of sensitive report data.

Highlights:

  • Kubernetes resource, container, and service-account anonymization
  • Repository, Git, annotation, and filesystem metadata protection
  • AES-GCM encryption and Data Encryption Key (DEK) wrapping
  • Reversible resource and container metadata transformation
  • Report decryption and CLI documentation
  • Multiple upstream contributions shipped in Kubescape v4.0.11

๐Ÿ“– Read the full engineering case study โ†’ ๐Ÿ”— Original Kubescape feature request โ†’ ๐Ÿ“– Offical Docs โ†’ ๐Ÿ“– Blog โ†’


๐Ÿ” RegoLibrary Release Integrity

Built a layered software supply-chain release-integrity workflow for Kubescape RegoLibrary, evolving artifact verification from SHA-256 checksums into an authenticated release-verification chain.

Highlights:

  • SHA-256 verification of release artifacts
  • Explicit ErrChecksumVerification security boundary
  • Kubescape hard-failure behavior on checksum verification errors
  • Cosign keyless signing of the release checksum manifest
  • Sigstore bundle and signer identity verification
  • Trusted-root handling with LiveTrustedRoot
  • sigstore-go upgrade and trusted-root refresh
  • Real GitHub Release integration testing
  • Downstream consumption in Kubescape
  • Released in RegoLibrary v2.0.36

๐Ÿ“– Read the full engineering case study โ†’

๐Ÿ”— RegoLibrary v2.0.36 โ†’


Reach Me

๐Ÿ“ง sumanmandal.dev@gmail.com


github-snake

Pinned Loading

  1. chainrisk chainrisk Public

    ChainRisk is a CLI tool for analyzing software supply chain risk using SBOMs.

    Go

  2. kubescape kubescape Public

    Forked from kubescape/kubescape

    Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetโ€ฆ

    Go

  3. opentelemetry-collector-contrib opentelemetry-collector-contrib Public

    Forked from open-telemetry/opentelemetry-collector-contrib

    Contrib repository for the OpenTelemetry Collector

    Go