New episode ??
Making applications secure @Escape ? Podcast Host @ The Elephant in AppSec | Application Security | API security
Ever thought about the security risks that GitHub Actions introduce to your workflows? If not, a recent The Elephant in AppSec podcast episode with Fran?ois Proulx is a must-listen! Most people don’t realize they’re adding untrusted code or user input to their pull requests, which ultimately gets processed in GitHub Actions. In this episode, we dive deep into: - The critical topic of supply chain insider threats in open-source projects - The importance of the “trust, but verify” mantra - How the transition from a single maintainer to a team can increase security risks If you’re wondering about the future of automated security checks on platforms like GitHub, and the specific vulnerabilities in build pipelines, this episode is for you. Dive right in ??