Skip to content
View Fhatu12's full-sized avatar

Block or report Fhatu12

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Fhatu12/README.md

Hi, I’m Fhatuwani Sikhwari

I’m a security-focused full-stack developer and systems integration specialist based in South Africa.

I build practical web applications, e-commerce platforms, business systems, and secure digital products.

Open-Source Software Engineering

I contribute tested improvements to public software projects, working across unfamiliar codebases, automated testing, documentation, CI and technical review.

My recent contribution work demonstrates the ability to:

  • investigate existing architecture and project conventions;
  • implement focused fixes without unnecessary scope expansion;
  • write regression tests and validation checks;
  • work with Python and JavaScript/TypeScript project tooling;
  • use Git branches, forks and pull requests safely;
  • respond constructively to technical review feedback;
  • diagnose edge cases and refine an implementation;
  • deliver changes that pass real project CI pipelines.

Selected contributions

Only merged upstream contributions are listed here.

Project Contribution Merged PR
Tapflow Added an independent raw JavaScript chunk-size regression guard that catches removal of dashboard vendor chunking while preserving the existing first-load Brotli performance budget. #525
Tapflow Reduced the dashboard’s largest JavaScript bundle from ~542 kB to ~285 kB with measured Vite/Rollup vendor chunking, preserving lazy loading and adding a Brotli first-load regression guard. #520
Markdown Reader Modernised contributor onboarding for the current FastAPI, Next.js and Tauri architecture, including setup, local development, validation, security and contribution-workflow guidance. #206
gettext-tstrings Added deterministic regression testing to verify translation-context isolation across overlapping asyncio tasks and correct restoration of task-local translation state. #36
gettext-tstrings Fixed translated-documentation link defects and added automated link-target parity checks to prevent multilingual documentation drift. #26
AirMCP Added deterministic fixture-driven Jest coverage for the security-audit report summariser while preserving the existing npm-audit CI behaviour. #417
AirMCP Synchronised contribution templates with MODULE_MANIFEST and added automated Jest regression protection against future module/template drift. #415
AirMCP Modernised contributor guidance for the current server.registerTool() and MODULE_MANIFEST workflow while preserving established safety guidance. #412
AirMCP Updated testing guidance for Jest 30 and Zod 4 and added automated checks to detect future documentation/tooling drift. #406

These contributions complement my broader experience in software delivery, systems integration, QA and release governance, cybersecurity, telecommunications and technical leadership.

Featured portfolio projects

Mzansi Select — E-commerce Store

Mzansi Select is a South African e-commerce storefront project focused on creating a clean, trustworthy online shopping experience for curated products.

Skills shown: Shopify, e-commerce, storefront UX, product catalogue planning, QA, release control, customer-facing copy.

V-Property — Property Platform

V-Property is a property/rental platform project focused on helping users browse, manage, and work with property-related information through a web application.

Skills shown: full-stack development, database-backed apps, product delivery, Git workflow, deployment planning, stakeholder preview readiness.

Current focus

  • Full-stack web application development
  • Secure-by-design development
  • QA-aware engineering
  • Business systems and API integration
  • E-commerce and product platforms
  • Cybersecurity learning and authorised security research

Authorised security research

I also practise authorised security research through bug bounty and vulnerability disclosure programmes.

My current focus areas include:

  • OWASP Top 10 awareness
  • access-control review
  • IDOR/BOLA methodology
  • information-disclosure analysis
  • scope validation
  • low-noise testing
  • evidence minimisation
  • clear vulnerability reporting

Some reports have been accepted or closed as informational, which I treat as learning evidence rather than confirmed high-impact findings.

Private programme details, report contents, target names, screenshots, request/response data, and reproduction material are not published unless disclosure is explicitly approved.

Privacy note

This profile only includes public, recruiter-safe project summaries. Private client work, security research evidence, credentials, supplier details, and confidential project material are intentionally excluded.

Contact

I’m open to software development, full-stack, QA-aware engineering, systems integration, and security-focused development opportunities.

Built by SG Digital | A division of Sikhwari Group (Pty) Ltd

Pinned Loading

  1. Fhatu12 Fhatu12 Public

    1

  2. SikhwariG SikhwariG Public

    TypeScript

  3. v-prop v-prop Public

    Vhembe Properties

    TypeScript

  4. mzansi-select-shopify mzansi-select-shopify Public

    South African e-commerce storefront project focused on Shopify, catalogue workflow, UX honesty, QA, and controlled launch readiness.

    JavaScript