Skip to content
View Fhatu12's full-sized avatar

Block or report Fhatu12

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Fhatu12/README.md

Hi, I’m Fhatuwani Sikhwari

I’m a security-focused full-stack developer and systems integration specialist based in South Africa.

I build practical web applications, e-commerce platforms, business systems, and secure digital products.

Open-Source Software Engineering

I contribute tested improvements to public software projects, working across unfamiliar codebases, automated testing, documentation, CI and technical review.

My recent contribution work demonstrates the ability to:

  • investigate existing architecture and project conventions;
  • implement focused fixes without unnecessary scope expansion;
  • write regression tests and validation checks;
  • work with Python and JavaScript/TypeScript project tooling;
  • use Git branches, forks and pull requests safely;
  • respond constructively to technical review feedback;
  • diagnose edge cases and refine an implementation;
  • deliver changes that pass real project CI pipelines.

Selected contributions

Only merged upstream contributions are listed here.

Project Contribution Merged PR
Markdown Reader Modernised contributor onboarding for the current FastAPI, Next.js and Tauri architecture, including setup, local development, validation, security and contribution-workflow guidance. #206
gettext-tstrings Added deterministic regression testing to verify translation-context isolation across overlapping asyncio tasks and correct restoration of task-local translation state. #36
gettext-tstrings Fixed translated-documentation link defects and added automated link-target parity checks to prevent multilingual documentation drift. #26
AirMCP Added deterministic fixture-driven Jest coverage for the security-audit report summariser while preserving the existing npm-audit CI behaviour. #417
AirMCP Synchronised contribution templates with MODULE_MANIFEST and added automated Jest regression protection against future module/template drift. #415
AirMCP Modernised contributor guidance for the current server.registerTool() and MODULE_MANIFEST workflow while preserving established safety guidance. #412
AirMCP Updated testing guidance for Jest 30 and Zod 4 and added automated checks to detect future documentation/tooling drift. #406

These contributions complement my broader experience in software delivery, systems integration, QA and release governance, cybersecurity, telecommunications and technical leadership.

Featured portfolio projects

Mzansi Select — E-commerce Store

Mzansi Select is a South African e-commerce storefront project focused on creating a clean, trustworthy online shopping experience for curated products.

Skills shown: Shopify, e-commerce, storefront UX, product catalogue planning, QA, release control, customer-facing copy.

V-Property — Property Platform

V-Property is a property/rental platform project focused on helping users browse, manage, and work with property-related information through a web application.

Skills shown: full-stack development, database-backed apps, product delivery, Git workflow, deployment planning, stakeholder preview readiness.

Current focus

  • Full-stack web application development
  • Secure-by-design development
  • QA-aware engineering
  • Business systems and API integration
  • E-commerce and product platforms
  • Cybersecurity learning and authorised security research

Authorised security research

I also practise authorised security research through bug bounty and vulnerability disclosure programmes.

My current focus areas include:

  • OWASP Top 10 awareness
  • access-control review
  • IDOR/BOLA methodology
  • information-disclosure analysis
  • scope validation
  • low-noise testing
  • evidence minimisation
  • clear vulnerability reporting

Some reports have been accepted or closed as informational, which I treat as learning evidence rather than confirmed high-impact findings.

Private programme details, report contents, target names, screenshots, request/response data, and reproduction material are not published unless disclosure is explicitly approved.

Privacy note

This profile only includes public, recruiter-safe project summaries. Private client work, security research evidence, credentials, supplier details, and confidential project material are intentionally excluded.

Contact

I’m open to software development, full-stack, QA-aware engineering, systems integration, and security-focused development opportunities.

Built by SG Digital | A division of Sikhwari Group (Pty) Ltd

Pinned Loading

  1. Fhatu12 Fhatu12 Public

  2. SikhwariG SikhwariG Public

    TypeScript

  3. v-prop v-prop Public

    Vhembe Properties

    TypeScript

  4. mzansi-select-shopify mzansi-select-shopify Public

    South African e-commerce storefront project focused on Shopify, catalogue workflow, UX honesty, QA, and controlled launch readiness.

    JavaScript