Infrastructure • software assurance • accessibility • open source
I build systems at the seams between source code, execution, evidence, and public infrastructure. My current work centers on software supply-chain assurance, reproducible release evidence, policy-driven automation, and telecom/accessibility systems.
Make the machine path boring. Make the evidence undeniable.
I’m interested in a simple question: can a downstream consumer prove that the artifact they received is the artifact the project intended to release?
- Apache Camel K #6777 — artifact-bound CycloneDX SBOMs, immutable image digests, keyless Cosign attestations, and a consumer-side
TRUST/REJECTverifier for the nightly release path. - Apache Celix #845 — native Conan/CycloneDX SBOM generation built around the dependency graph the project already uses.
- Apache Maven Parent #597 — move release-time CycloneDX generation into shared Apache Maven inheritance so projects can get the behavior without rebuilding the same machinery locally.
- FireCrab #190 — fail-closed release evidence: installed-package SBOMs, corresponding-source archives bound by SHA-256, and license inventory checks that refuse to publish incomplete evidence.
The pattern is consistent: source → artifact → SBOM → digest → attestation → verification.
Upstream work across Cloudflare CI, Apache Iceberg Terraform, and NIST Metaschema.
Yeet is a small agent shipping contract: take the shortest compliant path, then prove the remote state actually landed.
awesome-federal-tech is a practitioner map for OSCAL, SBOMs, ATO, and experimental infrastructure — repositories you can clone, not slideware.
I was a key contributor to the MITRE/FCC ACE portfolio, a public research stack for accessible telecommunications, relay-service experimentation, real-time text and video, interoperability testing, instrumentation, and operational tooling.
The public MITRE FCC ACE portfolio spans:
- Accessible communications clients and media: ACE Connect Lite, ACE Connect Lite public, FCC VATRP, VATRP WebRTC, ACE Quill, and ACE Quill Keyboard.
- Experiment, measurement, and analysis: ACE Omni, VATRP Log Analysis, ACR Demo Agent, ACR Demo Provider, and Data Logger.
- Platform and operations: Hashconfig, Autoinstall, and the project site repository.
The earlier ACE platform also included the ACE Direct, Asterisk, ESB, management portal, ACR/CDR, application server, and user server components; public mirrors of that generation remain available across GitHub.
ACE Omni on Cloudflare is my current continuation of that work: rebuilding the laboratory around a runtime-independent experiment model so the same fixtures can produce equivalent semantic traces across Cloudflare, JAIN SLEE, and Elixip, with evidence pinned and replayable.
Git · Cloudflare · Rust · Go · Firecracker · SBOM · CycloneDX · Sigstore · OSCAL · CI/CD · software supply chain · telecom · accessibility
Recent: Why Apache Matters: The Infrastructure Beneath the Infrastructure
More at mcc0nnell.org.


