Главная
Study mode:
on
1
Intro
2
What are GitHub workflows?
3
What are GitHub Actions?
4
Workflow example
5
Repository security
6
Code - Who has access?
7
Configuring access
8
From the user
9
Workflow secrets
10
Who has access to your secrets?
11
Your code - Best practices
12
GitHub Actions Security
13
Best practice: Run the action inside of a container
14
Persisting data between runs
15
Workflow runners - Best practice
16
Verified Creator
17
Protective measures
18
Recommendation
19
Workflow attack vectors
20
Forks of public repos
21
Pull Requests
22
Common fields
23
Remediation
24
Forking actions
25
Staying up to date
26
Update action versions
27
Option 1: Use SHA+Dependabot
28
Use Dependabot
29
Keep your forked action up to date
30
Review before merging
31
Automation
32
Pros of forking
33
Best practices summarized
Description:
Explore GitHub Actions security best practices in this NDC Security 2022 conference talk. Learn how to secure your CI/CD pipelines, manage access control, protect sensitive information, and mitigate potential vulnerabilities in your workflows. Discover techniques for safeguarding repository access, handling workflow secrets, and implementing protective measures for runners. Gain insights into managing fork-based security risks, staying up-to-date with action versions, and leveraging automation for enhanced security. Equip yourself with practical knowledge to strengthen your GitHub Actions security posture without compromising DevOps efficiency.

How to Use GitHub Actions with Security in Mind

NDC Conferences
Add to list
0:00 / 0:00