Главная
Study mode:
on
1
GitHub Actions Security
2
What are GitHub workflows?
3
Workflow example
4
Repository security
5
Code - Who has access?
6
Configuring access
7
From the user
8
Workflow secrets
9
Who has access to your secrets?
10
Your code - Best practices
11
Your code/repo – trace changes (org level)
12
Self-hosted runners
13
Self hosted runners
14
Workflow Runners Security
15
Best practice: Run the action inside of a container
16
Persisting data between runs
17
Workflow runners - Best practice
18
Protective measures
19
Recommendation
20
Forking actions
21
Enable DevOps teams to test actions
22
Staying up to date
23
Create an update process yourself
24
Automate the update Use a workflow
25
Best practices summarized
Description:
Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only! Grab it Explore essential strategies for securing GitHub Actions workflows in this comprehensive conference talk. Learn how to manage access control, protect sensitive information, and implement best practices for DevOps security. Discover techniques for safeguarding repository access, managing workflow secrets, and securing self-hosted runners. Examine the importance of containerization, data persistence between runs, and protective measures against potential threats. Gain insights into forking actions, enabling DevOps teams to test actions safely, and maintaining up-to-date workflows through automated processes. Master the art of balancing security with DevOps efficiency in real-world continuous integration and deployment scenarios.

How to Secure Your GitHub Actions

NDC Conferences
Add to list