395 subscribers
התחל במצב לא מקוון עם האפליקציה Player FM !
Securing GitHub Actions with William Woodruff
Manage episode 482143113 series 1502626
William Woodruff discussed his project, Zizmor, a security linter designed to help developers identify and fix vulnerabilities within their GitHub Actions workflows. This tool addresses inherent security risks in GitHub Actions, such as injection vulnerabilities, permission issues, and mutable tags, by providing static analysis and remediation guidance. Fresh off the heels of the tj-actions/changed-files backdoor, this is a great topic with some things everyone can do right away.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-05-securing-github-actions-william-woodruff/
486 פרקים
Manage episode 482143113 series 1502626
William Woodruff discussed his project, Zizmor, a security linter designed to help developers identify and fix vulnerabilities within their GitHub Actions workflows. This tool addresses inherent security risks in GitHub Actions, such as injection vulnerabilities, permission issues, and mutable tags, by providing static analysis and remediation guidance. Fresh off the heels of the tj-actions/changed-files backdoor, this is a great topic with some things everyone can do right away.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-05-securing-github-actions-william-woodruff/
486 פרקים
כל הפרקים
×

1 Hobbyist Maintainers with Thomas DePierre 49:03


1 STIG automation with Aaron Lippold 33:28






1 Repository signing with Kairo De Araujo 33:29


1 Securing GitHub Actions with William Woodruff 31:50


1 Embedded Security with Paul Asadoorian 34:24


1 tj-actions with Endor Lab's Dimitri Stiliadis 32:39


1 Syft, Grype, and Grant with Alan Pope 31:04




1 cargo-semver-checks with Predrag Gruevski 33:35


1 Distributed CI and Git with Lars Wirzenius 27:27


1 FIDO authentication with William Brown 29:26




1 Open Source Malware with Brian Fox 30:18
ברוכים הבאים אל Player FM!
Player FM סורק את האינטרנט עבור פודקאסטים באיכות גבוהה בשבילכם כדי שתהנו מהם כרגע. זה יישום הפודקאסט הטוב ביותר והוא עובד על אנדרואיד, iPhone ואינטרנט. הירשמו לסנכרון מנויים במכשירים שונים.