Beyond the Commit: Weaponizing and Hardening GitHub Actions - Niek Palm - NDC Security 2026

Beyond the Commit: Weaponizing and Hardening GitHub Actions - Niek Palm - NDC Security 2026 This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity #ndcconferences #security #developer #softwaredeveloper Attend the next NDC conference near you: Subscribe to our YouTube channel and learn every day: @NDC Follow our Social Media! #devops #sdlc #security #securitytools #ai #cicd #github GitHub Actions, the backbone of modern CI/CD, has become the primary target in recent, high profile supply chain attacks. Incidents like the compromise of the popular tj-actions/changed-files (impacting over 23,000 repositories) and the multi stage S1ngularity (Nx) attack exposed the immense blast radius of pipeline vulnerabilities, leading to the leak of thousands of sensitive credentials and the compromise of private source code. The security of your software supply chain is at stake. We will break down the technical mechanics of these breaches and present actionable, practical principles to secure your automation against credential theft, script injection, and third party action hijacking. Crucially, these supply chain protection principles (from the Principle of Least Privilege governing secret scope and lifetime to dependency vetting and input sanitization) are not limited to GitHub; they are universally applicable for securing any modern CI/CD system, including emerging considerations around AI agents. You will walk away with a clear roadmap and the tools needed to transform your pipeline from a critical vulnerability into a robust supply chai
  2026/03/26      youtube

関連するプログラミング動画 [security]

Our Tag

最近投稿されたプログラミング学習動画

The annual session prep for GoogleIO

Google

Working hard to bring you the best web u...

  2026/04/29

Build a Basic LLM Judge

Let's build our first automated judge! L...

  2026/04/29

PyCon JP TV #64: Pythonパッケージを安全にPyPIで公開するライブデモ

python
Google

PyCon JP Associationが主催するYouTubeライブです。実験...

  2026/04/29

Mumbai Indians Speak Gen Z 😎 with AI Mode in Google Search

Google

They’ve mastered cricket! Now they’re ma...

  2026/04/28

How Chrome deprecates and removes features

chrome

Chrome consistently adds new features, b...

  2026/04/27

Knights strike a pose with AI Mode in Google Search 😎

Google

From precision on the pitch to precision...

  2026/04/27

Sundaaaaaaay Stream!!

...

  2026/04/26

Do THIS instead of watching endless tutorials — how to learn Python fo

python

🎓 These are two of the best beginner-fri...

  2026/04/26

【Claude Code MCP超入門】おすすめMCP11選|MCPとは?作り方や仕組み・使い方を15分でわかりやすく解説

ClaudeやClaude Codeについて「キノクエスト」でもっと学習できます...

  2026/04/26

This is the MOST important question.

Want to make real money with coding? I s...

  2026/04/25

How Benefit Systems Scales Employee Benefits with Tameshi and AWS | Am

Amazon

Benefit Systems, a leading employee bene...

  2026/04/24

How do I troubleshoot errors that I receive when I use ECS Exec on my

For more details on this topic, visit th...

  2026/04/24