Securing CI/CD Pipelines - Exploring Vulnerabilities In Workflows
Offered By: nullcon via YouTube
Course Description
Overview
Explore the security challenges and vulnerabilities in CI/CD pipelines, particularly focusing on GitHub Actions, in this informative conference talk. Delve into the threat model for popular CI/CD platforms and learn about the increased risks to the software supply chain due to additional dependencies and code complexity. Discover a taint tracking tool specifically designed to identify code injection bugs in GitHub Workflows. Examine real-world examples from over 23,000 bugs found by this tool, gaining valuable insights into securing your development processes. Enhance your understanding of DevSecOps and vulnerability management in the context of modern software development workflows.
Syllabus
Securing CI/CD Pipelines: Exploring Vulnerabilities In Workflows by Siddharth Muralee | Nullcon Goa
Taught by
nullcon
Related Courses
Hardening Your Soft Software Supply ChainPluralsight DevOps with GitHub and Azure: Implementing Software Supply Chain Security with GitHub
Pluralsight Securing Your Software Supply Chain with Sigstore
Linux Foundation via edX GitHub Supply Chain Security Using GitGat
Linux Foundation via edX Kyverno - Deep Dive - Tech Talks
Mirantis via YouTube