Beyond the Commit: Weaponizing and Hardening GitHub Actions - Niek Palm - NDC Security 2026

Beyond the Commit: Weaponizing and Hardening GitHub Actions - Niek Palm - NDC Security 2026 This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity #ndcconferences #security #developer #softwaredeveloper Attend the next NDC conference near you: Subscribe to our YouTube channel and learn every day: @NDC Follow our Social Media! #devops #sdlc #security #securitytools #ai #cicd #github GitHub Actions, the backbone of modern CI/CD, has become the primary target in recent, high profile supply chain attacks. Incidents like the compromise of the popular tj-actions/changed-files (impacting over 23,000 repositories) and the multi stage S1ngularity (Nx) attack exposed the immense blast radius of pipeline vulnerabilities, leading to the leak of thousands of sensitive credentials and the compromise of private source code. The security of your software supply chain is at stake. We will break down the technical mechanics of these breaches and present actionable, practical principles to secure your automation against credential theft, script injection, and third party action hijacking. Crucially, these supply chain protection principles (from the Principle of Least Privilege governing secret scope and lifetime to dependency vetting and input sanitization) are not limited to GitHub; they are universally applicable for securing any modern CI/CD system, including emerging considerations around AI agents. You will walk away with a clear roadmap and the tools needed to transform your pipeline from a critical vulnerability into a robust supply chai
  2026/03/26      youtube

関連するプログラミング動画 [security]

Our Tag

最近投稿されたプログラミング学習動画

Python Match Statement: Features You Didn't Know

python

Download your free Python Cheat Sheet he...

  2026/04/09

Using Loguru to Simplify Python Logging: Setting Up & Understanding Lo

python

Download your free Python Cheat Sheet he...

  2026/04/09

MCP Apps: AI With Visual UI, Not Just Text

python

Download your free Python Cheat Sheet he...

  2026/04/08

What is your ANSWER?👇

Want to make real money with coding? I s...

  2026/04/08

Astro Crash Course #8 - Content Collections (with JSON)

In this Astro tutorial series, you'll le...

  2026/04/08

他のAIが記憶した脳をそのまま移行できる?!今からClaudeを活用していきたい人はこの方法がおすすめです

本日はChatGPTからClaudeへ乗り換えたい人が知っておくべき知識について...

  2026/04/08

Which ONE do you use?

Want to make real money with coding? I s...

  2026/04/07

Role-based Access Control and Sharing lists | Code, Commit, Deploy, Re

Welcome back to Code, Commit, Deploy, Re...

  2026/04/07

Bad UX Is Driving Users Away From Apple

python
Apple

Download your free Python Cheat Sheet he...

  2026/04/07

50x Cheaper Than Claude - But Can It Actually Code?

MiniMax Token Plan 12% OFF: MiniMax 2....

  2026/04/07

PyCon JP TV #63: PythonAsia 2026報告会

python
Google

PyCon JP Associationが主催するYouTubeライブです。実験...

  2026/04/07

Astro Crash Course #7 - Reusable Components

In this Astro tutorial series, you'll le...

  2026/04/07

Build A Smart Chat Bot Using Python & Machine Learning Audio Improved

python
study

Build A Smart Chat Bot Using Python & Ma...

  2026/04/07