<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Posts on Pedro Balbino</title><link>https://blog.home301server.com.br/posts/</link><description>Recent content in Posts on Pedro Balbino</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 13 May 2026 10:00:00 -0300</lastBuildDate><atom:link href="https://blog.home301server.com.br/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>SLSA L2 + Sigstore keyless: a solo-dev supply-chain canon for OSS plugin repos</title><link>https://blog.home301server.com.br/posts/2026-05-13-slsa-sigstore-solo-dev-supply-chain/</link><pubDate>Wed, 13 May 2026 10:00:00 -0300</pubDate><guid>https://blog.home301server.com.br/posts/2026-05-13-slsa-sigstore-solo-dev-supply-chain/</guid><description>A 9-line GitHub Actions canon — actions/attest-build-provenance + cosign keyless OIDC + dual-format syft SBOM — applied verbatim across six Claude Code plugin repos. SLSA L2 attestations and &lt;code&gt;gh attestation verify&lt;/code&gt; smoke tests, no per-plugin overhead, zero rotated secrets.</description></item><item><title>Compliance-grade RAG for tier-1 LATAM banking</title><link>https://blog.home301server.com.br/posts/2026-04-26-compliance-grade-rag-tier1-banking/</link><pubDate>Sat, 25 Apr 2026 00:00:00 -0300</pubDate><guid>https://blog.home301server.com.br/posts/2026-04-26-compliance-grade-rag-tier1-banking/</guid><description>Building an LLM agent for tax-compliance document review under LGPD, internal audit gates, and controlled deployment windows. Pattern: retrieval pipeline + citation extractor + auditable decision log + human-review gate. Stack: Python + Azure OpenAI + Postgres + Terraform.</description></item></channel></rss>