To participate in the stream go to https://www.crowdcast.io/e/keeping-yo...
Lying at the heart of the software development lifecycle, CI/CD pipelines are critical for delivering code from developers’ machines to production servers. It’s no surprise that the environments, processes, and tools that make up this area – where every single misconfiguration is part of a larger attack surface – are becoming more appealing to hackers.
This time, I am happy to be joined by C.J May, Senior Security Analyst, to discuss:
Common (security) mistakes when setting up GitHub Actions
How GitHub Actions workflows can be exploited in practice
Best practices to harden your CI workflows on GitHub Actions
This live session will offer bite-sized tips to lock down your CI/CD pipelines’ security through a mix of theory and practice!