YoVDO

Security Risks in Third-Party GitHub Actions - Overlooked Consequences

Offered By: BSidesLV via YouTube

Tags

GitHub Actions Courses DevOps Courses Cloud Security Courses Vulnerability Management Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the critical security risks associated with third-party GitHub Actions in this eye-opening conference talk. Delve into an analysis of build logs from top GitHub repositories, uncovering alarming issues related to permissions and build integrity. Learn about the widespread failure to manage build permissions effectively and the potential consequences, including unauthorized access to cloud resources and malware introduction. Examine the concept of "unpinnable actions" and challenge common security practices, such as action pinning. Discover the conditions that render actions unpinnable and gain insights into the surprising percentage of popular actions that fall into this category. Equip yourself with essential knowledge to enhance the security of your CI/CD pipelines and protect your projects from overlooked vulnerabilities in third-party GitHub Actions.

Syllabus

GF - Actions have consequences: The overlooked Security Risks in 3rd party GitHub Actions


Taught by

BSidesLV

Related Courses

Docker Mastery: with Kubernetes +Swarm from a Docker Captain
Udemy
Deploy Infra in the Cloud using Terraform
Udemy
Integrating Appium into a DevOps Pipeline
Pluralsight
Microsoft DevOps Solutions: Designing a Sensitive Information Strategy
Pluralsight
Testing and Deploying GatsbyJS Applications: Playbook
Pluralsight