Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Enhancing CI/CD Secrets Security - The 3Rs Approach

OWASP Foundation via YouTube

Overview

Explore a comprehensive approach to enhancing CI/CD secrets security in this 49-minute OWASP Foundation talk by Bobby Lin. Learn about the 3Rs principles: Reduce storage of secrets at rest with CI/CD providers, Reduce the number of secrets used in CI/CD workflows, and Reduce the chances of secrets being leaked in source code. Discover practical strategies to implement these principles, including using short-lived secrets, minimizing duplicated permissions, and employing security git hooks. Gain insights into handling client secret leaks in logs and understand the limitations of current SAST secret scanners. While the examples are GitHub and AWS-centric, apply these concepts to various VCS, CI/CD providers, and cloud service platforms to improve your organization's security posture and mitigate risks associated with compromised CI/CD providers.

Syllabus

Enhancing CI/CD Secrets Security: The 3Rs Approach - Bobby Lin

Taught by

OWASP Foundation

Reviews

Start your review of Enhancing CI/CD Secrets Security - The 3Rs Approach

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.