๐ต๏ธโโ๏ธ Security risks in GitHub Actions (by Igor Stepansky) | Cloud & CI/CD Security TechSpot
Igor Stepansky shows how attackers abuse GitHub Actions and what you can realistically do about it. ๐ง ๐๐ก๐ข๐ฌ ๐ญ๐๐ฅ๐ค ๐ฌ๐ก๐จ๐ฐ๐ฌ: โข Structure of GitHub Actions workflows: triggers, jobs, runners, steps, actions โข Main risk areas: secrets, GitHub token permissions, missing dependency pinning, third-party actions, etc. โข Real incidents: tj-actions supply-chain compromise, PyTorch contributor โ runner takeover โ malicious release โข Hardening practices that work in day-to-day engineering โข Open-source tool demo: mapping and scanning the full action chain ๐ค ๐๐ฉ๐๐๐ค๐๐ซ: Igor Stepansky, Security Researcher at Orca Security https://www.linkedin.com/in/igor-stepansky/ ๐ ๐๐ข๐ฆ๐๐ฌ๐ญ๐๐ฆ๐ฉ๐ฌ: 0:00 โ Intro and speaker background 1:30 โ Agenda and why GitHub Actions matters (CI/CD adoption) 2:40 โ How GitHub Actions works: workflows, jobs, runners, marketplace actions 7:24 โ Eight common security risks in GitHub Actions (overview) 7:51 โ Secret management and GITHUB_TOKEN permission issues 10:23 โ Dependency pinning failures and supply-chain attacks via actions 12:32 โ Code injection, artifact poisoning, and dangerous triggers (pull_request_target) 16:44 โ Self-hosted runners and real-world attacks (tj-actions, PyTorch) 23:05 โ Hardening checklist and secure GitHub Actions practices 25:40 โ Aspect (ex-Actchain): scanning the full GitHub Actions chain 29:10 โ โHomeworkโ: OWASP CI/CD Top 10 and deeper talks on Actions attacks 30:06 โ Q&A: AI in security tooling, noisy findings, and parallel use with classic tools 32:15 โ Q&A: pinning vs. latest, trusting hosted runners, and small-company trade-offs 36:09 โ Q&A: tooling cost, open source options, forks, secrets, and identity federation ๐ ๐๐ญ๐ก๐๐ซ ๐ญ๐๐ฅ๐ค๐ฌ ๐๐ซ๐จ๐ฆ ๐ญ๐ก๐ ๐๐ฅ๐จ๐ฎ๐ & ๐๐/๐๐ ๐๐๐๐ฎ๐ซ๐ข๐ญ๐ฒ ๐๐๐๐ก๐๐ฉ๐จ๐ญ: Panel discussion https://youtu.be/Da9fL9LaeUs Talk https://youtu.be/XSO-A9K51ZU ๐ TechSpot events are driven by On The Spot Development. More about TechSpot: https://onthespotdev.com/techspot Open positions for engineers in Poland: https://onthespotdev.com/careers #devsecops #githubactions #cicd #supplychainsecurity #cybersecurity #opensourcesecurity
Download
0 formatsNo download links available.