Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Green Checkmarks, Red Flags - What CI/CD Can't Catch

Conf42 via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore the critical limitations of CI/CD automation in this 26-minute conference talk that examines what continuous integration and deployment pipelines cannot detect or prevent. Analyze real-world security incidents, including the March 2024 XZ Utils backdoor attack, to understand how sophisticated threats can bypass automated testing and green checkmarks. Investigate the human factors that contribute to CI/CD vulnerabilities, including social engineering tactics, review fatigue, and organizational pressures that prioritize speed over thorough security analysis. Learn about the disconnect between automated validation and actual software quality, examining how malicious actors exploit trust relationships and overwhelmed review processes. Discover a comprehensive solutions framework that addresses review practices, organizational culture, and technical safeguards to enhance CI/CD security. Examine strategies for building resilient software development processes that combine automation benefits with human oversight, including techniques for extending CI/CD pipelines with additional security layers and improving code review effectiveness in high-pressure development environments.

Syllabus

Introduction: The Hidden Flaws in CICD
A Real-World Example: The March 2024 Incident
The Disconnect Between Automation and Reality
Why This Matters: The Limitations of CICD
The Problem: Human Factors in Automation
Exploring Solutions: Enhancing CICD with Human Safeguards
The Scenario: When Green Check Marks Fail
Case Study: The Ex UTS Backdoor Incident
Understanding the Attack: Social Engineering at Scale
The Systemic Issues: Trust and Review Overload
The Organizational Pressures: Speed vs. Quality
Solutions Framework: Review Practices, Process, and Culture
Technical Safeguards: Extending CICD
Conclusion: Building Resilient Software

Taught by

Conf42

Reviews

Start your review of Green Checkmarks, Red Flags - What CI/CD Can't Catch

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.