Pwning the CI with GitHub Action Workflows - Security Challenges and Exploits
CNCF [Cloud Native Computing Foundation] via YouTube
Stuck in Tutorial Hell? Learn Backend Dev the Right Way
Master Agentic AI, GANs, Fine-Tuning & LLM Apps
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Explore the security vulnerabilities in CI platforms and GitHub Action workflows in this 28-minute conference talk from KubeCon + CloudNativeCon Europe 2023. Delve into the challenges posed by open source and GitOps practices, which expose development pipelines to potential threats. Learn how social engineering techniques and insecure GitHub configurations can be exploited by malicious actors. Witness live demonstrations of known abuses in GitHub Actions workflows, highlighting how default settings and poor practices can compromise the security of your supply chain. Gain valuable insights into protecting your CI/CD pipeline from potential attacks and strengthening your overall cybersecurity posture.
Syllabus
Pwning the CI (with GitHub Action Workflows) - Stephen Giguere, Bridgecrew
Taught by
CNCF [Cloud Native Computing Foundation]