Nullcon Goa 2023 | Securing CI/CD Pipelines: Exploring Vulnerabilities In Workflows by Siddharth
About this talk
This talk explores the security characteristics of popular CI/CD platforms like GitHub Actions, highlighting how they streamline build and deployment tasks while introducing new challenges related to the software supply chain. The speaker discusses the complexities of identifying vulnerabilities in CI/CD pipelines and introduces a taint tracking tool aimed at detecting code injection bugs specifically in GitHub Workflows. The session concludes by analyzing real-world bugs identified by this tool, providing key insights into the emerging security risks within the realm of DevSecOps.
More from this event
See all 25 talks →
Nullcon Goa 2023 | Aftermovie
2:10
Nullcon Goa 2023 | Keynote: Multiplying Threat Intelligence by John Lambert
33:51
Nullcon Goa 2023 | Smashing The State Machine: The True Potential Of Web Race Conditions by James
43:52
Nullcon Goa 2023 | How I Hacked Your Bank Account: A Detailed Look At UPI Security by Nemo
21:08