Github Actions Security Best Practices with Reethi Kotti

  Рет қаралды 2,755

OWASP DevSlop

OWASP DevSlop

2 жыл бұрын

▬▬▬▬▬▬ 📝 ABSTRACT & BIO ▬▬▬▬▬▬
In the world of Continuous Integration and Continuous Deployment, Github Actions provide a
nifty edge to quickly build end-to-end automation right into the repository. This makes integration
of Actions into an organization’s Github repositories pretty straightforward and convenient.
However, if Actions is swiftly adopted without a well chartered security plan, one may quickly
find themselves in muddy waters.
In this episode, we will discuss some of the key security concerns one should be aware of when
using Github Actions. We will also cover the best practices that Salesforce Heroku follows to
securely use this exceedingly popular product.
REETHI KOTTI
Reethi is a Platform Security Engineer at Salesforce Heroku. She enjoys performing deep dive
security reviews, automating manual processes and finding ways to improve the overall Security
posture. Recently she’s been invested in CI/CD tools and finding ways to securely use third
party packages. In her free time, you can find her tending to her many plants and exploring
trails.
▬▬▬▬▬▬ 🔗 LINKS ▬▬▬▬▬▬
SLIDES: 🔗bit.ly/3udajov
Additional information about Github Actions can be found at docs.github.co...
REFERENCES
1. engineering.sa...
df5c75f5
2. / bypassing-required-rev...
s-6e1b29135cc7
3. docs.github.co...
4. github.blog/20...
equest-workflows/
▬▬▬▬▬▬ 🎥 Producer ▬▬▬▬▬▬
Nancy Gariché ► / nancygariche
▬▬▬▬▬▬ 🎙️Hosts ▬▬▬▬▬▬
Nikki Becher ► / thedeadrobots
▬▬▬▬▬▬ 👋 Connect with Us ▬▬▬▬▬▬
TWITCH ► owasp_devslop - Twitch
MEETUP.COM ► www.meetup.com...
INSTAGRAM ► / ​
TWITTER ► owasp_devslop

Пікірлер
Let’s Write Security Unit Tests! with Eric Johnson
1:04:31
OWASP DevSlop
Рет қаралды 2,1 М.
Attacking JSON Web Tokens with Louis Nyffenegger
1:23:49
OWASP DevSlop
Рет қаралды 6 М.
Men Vs Women Survive The Wilderness For $500,000
31:48
MrBeast
Рет қаралды 65 МЛН
Dad gives best memory keeper
01:00
Justin Flom
Рет қаралды 20 МЛН
WILL IT BURST?
00:31
Natan por Aí
Рет қаралды 43 МЛН
escape in roblox in real life
00:13
Kan Andrey
Рет қаралды 18 МЛН
Let's learn GitHub Actions in a self-hosted Homelab!
23:53
Christian Lempa
Рет қаралды 39 М.
How GitHub Actions 10x my productivity
8:18
Beyond Fireship
Рет қаралды 414 М.
Diving Deeper into Subdomain Takeovers & Mitigations with Shubham Shah
1:03:26
Learning from AWS (Customer) Security Breaches with Rami McCarthy
1:19:53
Software Security Education with the OWASP Secure Coding Dojo
1:00:33
OWASP DevSlop
Рет қаралды 2,9 М.
Demystifying the SBOM’s impact on Secure Software Deployment
1:09:06
Men Vs Women Survive The Wilderness For $500,000
31:48
MrBeast
Рет қаралды 65 МЛН