Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Under the Radar: How We Found 0-Days in the Build Pipeline of OSS Packages

OpenSSF via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the critical yet often overlooked area of Build Pipelines in Open Source packages in this 20-minute conference talk. Discover how data analysis infrastructure was developed to target vulnerabilities, leading to the discovery of 0-days in major OSS projects including Terraform providers and modules, AWS Helm Charts, and popular GitHub Actions. Gain insights into a detailed attack tree for GitHub Actions pipelines, offering a deeper analysis than prior art and outlining attacks and mitigations. Learn about a unique reference for 'Living Off the Pipeline' (LOTP) components, designed to help Red and Blue teams prioritize more risky scenarios in supply chain security.

Syllabus

Under the Radar: How We Found 0-Days in the Build Pipeline o... François Proulx & Benoît Côte-Jodoin

Taught by

OpenSSF

Reviews

Start your review of Under the Radar: How We Found 0-Days in the Build Pipeline of OSS Packages

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.