Learn more about GitGat by Scribe Security: https://github.com/scribe-public/gitgat
Learn more about Scribe Security: https://scribesecurity.com/
GitHub is one of the most popular SCM (source control management) systems in the world but there are still a lot of people who miss some easy-to-implement security measures meant to help protect your code. Especially in the world of open source, many forgo best practices in regards to securing their code in favor of the easy access that platforms like GitHub provide.
SCM security posture can in general be divided into several categories:
Access control
Permissions
Branch Protection
File Modification Tracking
In this Tech Talk, Barak Brudo, Developer Relations Advocate for Scribe Security will go over each of these categories, explain it, show what it means when it’s not implemented, and demonstrate how to implement the relevant recommended security settings in GitHub to ensure your code is secure.
🙋 Questions for Barak? Reach out directly: [email protected]
📊 Link to Presentation Slide Deck: https://www.slideshare.net/BarakBrudo...
🔬 For more hands-on, developer-focused presentations from the Mirantis Labs team, please see: https://www.mirantis.com/labs/
📚 For more informative resources about Mirantis, our solutions and areas of expertise, please check out our resource library: https://www.mirantis.com/resources/
#kubernetes #github #gitops #k8s #opensource #sourcecontrolmanagement #kubernetessecurity #githubsecurity #cybersecurity #cloudsecurity #rbac
Learn more about Mirantis: https://www.mirantis.com/
Mirantis Enterprise Support: https://www.mirantis.com/support/ente...
Read the Mirantis Blog: https://www.mirantis.com/blog/
Cloud Native & Kubernetes Resources: https://www.mirantis.com/cloud-native...
Mirantis Training: https://training.mirantis.com/
Questions? Contact us today: https://www.mirantis.com/contact/
CHAPTERS
0:00 - Intro
2:29 - What you may not know about GitHub security
3:11 - Improving GitHub security posture with GitGat
6:44 - Repo visibility and access
9:26 - Two factor authentication (2FA)
13:07 - Admin permissions
15:30 - Signed commits
17:32 - Branch protection rules
21:08 - Organizational access tracking
23:56 - Outro