Start speaking a new language. It’s just 3 weeks away.
The Fastest Way to Become a Backend Developer Online
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Explore a comprehensive approach to enhancing CI/CD secrets security in this 49-minute OWASP Foundation talk by Bobby Lin. Learn about the 3Rs principles: Reduce storage of secrets at rest with CI/CD providers, Reduce the number of secrets used in CI/CD workflows, and Reduce the chances of secrets being leaked in source code. Discover practical strategies to implement these principles, including using short-lived secrets, minimizing duplicated permissions, and employing security git hooks. Gain insights into handling client secret leaks in logs and understand the limitations of current SAST secret scanners. While the examples are GitHub and AWS-centric, apply these concepts to various VCS, CI/CD providers, and cloud service platforms to improve your organization's security posture and mitigate risks associated with compromised CI/CD providers.
Syllabus
Enhancing CI/CD Secrets Security: The 3Rs Approach - Bobby Lin
Taught by
OWASP Foundation