YoVDO

Pwning the CI with GitHub Action Workflows - Security Challenges and Exploits

Offered By: CNCF [Cloud Native Computing Foundation] via YouTube

Tags

GitHub Actions Courses Cybersecurity Courses DevOps Courses Social Engineering Courses Continuous Integration Courses Supply Chain Security Courses CI/CD Pipelines Courses GitOps Courses Cloud-Native Security Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the security vulnerabilities in CI platforms and GitHub Action workflows in this 28-minute conference talk from KubeCon + CloudNativeCon Europe 2023. Delve into the challenges posed by open source and GitOps practices, which expose development pipelines to potential threats. Learn how social engineering techniques and insecure GitHub configurations can be exploited by malicious actors. Witness live demonstrations of known abuses in GitHub Actions workflows, highlighting how default settings and poor practices can compromise the security of your supply chain. Gain valuable insights into protecting your CI/CD pipeline from potential attacks and strengthening your overall cybersecurity posture.

Syllabus

Pwning the CI (with GitHub Action Workflows) - Stephen Giguere, Bridgecrew


Taught by

CNCF [Cloud Native Computing Foundation]

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network