YoVDO

Securing CI/CD Pipelines - Exploring Vulnerabilities In Workflows

Offered By: nullcon via YouTube

Tags

nullcon Courses Threat Modeling Courses Software Supply Chain Security Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the security challenges and vulnerabilities in CI/CD pipelines, particularly focusing on GitHub Actions, in this informative conference talk. Delve into the threat model for popular CI/CD platforms and learn about the increased risks to the software supply chain due to additional dependencies and code complexity. Discover a taint tracking tool specifically designed to identify code injection bugs in GitHub Workflows. Examine real-world examples from over 23,000 bugs found by this tool, gaining valuable insights into securing your development processes. Enhance your understanding of DevSecOps and vulnerability management in the context of modern software development workflows.

Syllabus

Securing CI/CD Pipelines: Exploring Vulnerabilities In Workflows by Siddharth Muralee | Nullcon Goa


Taught by

nullcon

Related Courses

Unearthing Malicious and Risky OpenSource Packages Using Packj
nullcon via YouTube
Pushing Security Left by Mutating Byte Code
nullcon via YouTube
The Faces of MacOS Malware - Detecting Anomalies in a Poisoned Apple
nullcon via YouTube
Contextomy - Let's Debug Together
nullcon via YouTube
Mind The Gap - The Linux Ecosystem Kernel Patch Gap
nullcon via YouTube