This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity #ndcconferences #security #developer #softwaredeveloper
Attend the next NDC conference near you:
Subscribe to our YouTube channel and learn every day: @NDC
Follow our Social Media!
#devops #sdlc #security #securitytools #ai #cicd #github
GitHub Actions, the backbone of modern CI/CD, has become the primary target in recent, high profile supply chain attacks.
Incidents like the compromise of the popular tj-actions/changed-files (impacting over 23,000 repositories) and the multi stage S1ngularity (Nx) attack exposed the immense blast radius of pipeline vulnerabilities, leading to the leak of thousands of sensitive credentials and the compromise of private source code.
The security of your software supply chain is at stake. We will break down the technical mechanics of these breaches and present actionable, practical principles to secure your automation against credential theft, script injection, and third party action hijacking. Crucially, these supply chain protection principles (from the Principle of Least Privilege governing secret scope and lifetime to dependency vetting and input sanitization) are not limited to GitHub; they are universally applicable for securing any modern CI/CD system, including emerging considerations around AI agents. You will walk away with a clear roadmap and the tools needed to transform your pipeline from a critical vulnerability into a robust supply chai
|
It's that time of week again. Come watch...
Get started with CData Connect AI for fr...
本動画の資料はこちら AWS re:Invent 2025で発表されたAg...
本動画の資料はこちら AWS re:Invent 2025で発表された流通小...
本動画の資料はこちら NRF 2026(全米小売業協会カンファレンス)の現地...
本動画の資料はこちら 【動画の対象者】 - re:Invent 2025 の...
Try the app I built in this video! Clone...
Chad Bailey from the Pipecat team walks ...
🔥Advanced DevOps Certification Training ...