با برنامه Player FM !
S3E12: Daniel Krivelevich of Cider Security - CI/CD Pipeline Security
Manage episode 335171735 series 2947250
- For folks that are familiar, what is a CI/CD pipeline and why is it becoming such a hot topic in modern software delivery?
- Do you think earlier on in the pursuit of DevOps/DevSecOps organizations overlooked the pipeline as an attack vector?
- Any thoughts are notable incidents such as SolarWinds, do you think they brought more attention to the build environment?
- What are you thoughts on emerging guidance such as SLSA NIST SSDF or 800-161. Do you think these are helping bring attention to best practices on securing pipelines?
- In the context of software supply chain security, why do you think pipelines are so critical?
- Keeping on the theme of SBOM, what are your thoughts on the rising adoption and push for SBOM, and now VEX and how can pipelines help facilitate that?
- Cider has produced some excellent resources such as articles and also CICD Goat - how do you all keep innovating on the knowledge and tooling front and how has it been received by the community?
- One of those resources is the Top 10 CICD security risks. Do you want to touch on the list and maybe a couple of the leading risks from the list?
- Any recommendations on learning resources for folks wanting to learn more about pipeline security, best practices and why it is important?
166 قسمت
Manage episode 335171735 series 2947250
- For folks that are familiar, what is a CI/CD pipeline and why is it becoming such a hot topic in modern software delivery?
- Do you think earlier on in the pursuit of DevOps/DevSecOps organizations overlooked the pipeline as an attack vector?
- Any thoughts are notable incidents such as SolarWinds, do you think they brought more attention to the build environment?
- What are you thoughts on emerging guidance such as SLSA NIST SSDF or 800-161. Do you think these are helping bring attention to best practices on securing pipelines?
- In the context of software supply chain security, why do you think pipelines are so critical?
- Keeping on the theme of SBOM, what are your thoughts on the rising adoption and push for SBOM, and now VEX and how can pipelines help facilitate that?
- Cider has produced some excellent resources such as articles and also CICD Goat - how do you all keep innovating on the knowledge and tooling front and how has it been received by the community?
- One of those resources is the Top 10 CICD security risks. Do you want to touch on the list and maybe a couple of the leading risks from the list?
- Any recommendations on learning resources for folks wanting to learn more about pipeline security, best practices and why it is important?
166 قسمت
همه قسمت ها
×
1 Resilient Cyber w/ Vineeth Sai Narajala: Model Context Protocol (MCP) - Potential & Pitfalls 18:32

1 Resilient Cyber w/ Jay Jacobs & Michael Roytman - VulnMgt Modernization & Localized Modeling 33:53

1 Resilient Cyber w/ Ed Merrett - AI Vendor Transparency: Understanding Models, Data and Customer Impact 23:55
به Player FM خوش آمدید!
Player FM در سراسر وب را برای یافتن پادکست های با کیفیت اسکن می کند تا همین الان لذت ببرید. این بهترین برنامه ی پادکست است که در اندروید، آیفون و وب کار می کند. ثبت نام کنید تا اشتراک های شما در بین دستگاه های مختلف همگام سازی شود.