<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Mathias WOLFF</title><link>https://www.blog-des-telecoms.com/categories/security/</link><description>Recent content in Security on Mathias WOLFF</description><generator>Hugo</generator><language>fr-FR</language><copyright>&lt;a href="https://www.blog-des-telecoms.com"&gt;Blog des télécoms&lt;/a&gt; © 2009 - 2026 by &lt;a href="https://www.linkedin.com/in/mathias-wolff-47a7941/"&gt;Mathias WOLFF&lt;/a&gt; is licensed under &lt;a href="https://creativecommons.org/licenses/by-nc-sa/4.0/"&gt;CC BY-NC-SA 4.0&lt;/a&gt;&lt;img src="https://mirrors.creativecommons.org/presskit/icons/cc.svg" style="max-width: 1em;max-height:1em;margin-left: .2em;"&gt;&lt;img src="https://mirrors.creativecommons.org/presskit/icons/by.svg" style="max-width: 1em;max-height:1em;margin-left: .2em;"&gt;&lt;img src="https://mirrors.creativecommons.org/presskit/icons/nc.svg" style="max-width: 1em;max-height:1em;margin-left: .2em;"&gt;&lt;img src="https://mirrors.creativecommons.org/presskit/icons/sa.svg" style="max-width: 1em;max-height:1em;margin-left: .2em;"&gt;</copyright><lastBuildDate>Thu, 30 Jul 2026 12:50:08 +0200</lastBuildDate><atom:link href="https://www.blog-des-telecoms.com/categories/security/index.xml" rel="self" type="application/rss+xml"/><item><title>pi-secured-setup v1.1.0: OWASP hardening and tamper-evident audit</title><link>https://www.blog-des-telecoms.com/en/blog/pi-secured-setup-v1-1-0/</link><pubDate>Thu, 30 Jul 2026 11:00:00 +0200</pubDate><guid>https://www.blog-des-telecoms.com/en/blog/pi-secured-setup-v1-1-0/</guid><description>&lt;p&gt;I just released v1.1.0 of &lt;a
 href="https://github.com/mwolff44/pi-secured-setup"
 
 
 class="link--external" target="_blank" rel="noreferrer"
 
&gt;pi-secured-setup&lt;/a&gt;, the security extension for pi coding agents. This version does not add another feature, it closes 13 gaps identified against the &lt;a
 href="https://genai.owasp.org/"
 
 
 class="link--external" target="_blank" rel="noreferrer"
 
&gt;OWASP AI Agent Security Cheat Sheet&lt;/a&gt; and makes the audit log tamper-evident.&lt;/p&gt;
&lt;!-- more --&gt;
&lt;h2 id="an-audit-log-you-can-no-longer-tamper-with"&gt;An audit log you can no longer tamper with&lt;a href="#an-audit-log-you-can-no-longer-tamper-with" class="post-heading__anchor" aria-hidden="true"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;The most important change in this version is in the audit log. Up to v1.0, the audit was an append-only JSONL file with rotation, useful for seeing what happened but insufficient to prove that nothing had been removed.&lt;/p&gt;</description></item></channel></rss>