The Top 10 CI/CD Security Risks and CI/CD Goat - Daniel Krivelevich - ASW #220

Published: Nov. 15, 2022, 5:45 p.m.

b'

Cider Security\\u2019s recently published research of the Top 10 CI/CD Security Risks acts to identify vulnerabilities to help defenders focus on areas to secure their CI/CD ecosystem. They created a free learning tool with a deliberately vulnerable environment to demonstrate these flaws -- \\u201cCI/CD Goat\\u201d. Like similar tools, this helps appsec and devops teams gain a better understanding of major CI/CD security risks and, importantly, their appropriate countermeasures.

\\xa0

Segment Resources:

- https://www.cidersecurity.io/top-10-cicd-security-risks/

- https://github.com/cider-security-research/top-10-cicd-security-risks

- https://www.cidersecurity.io/blog/research/ci-cd-goat/

- https://github.com/cider-security-research/cicd-goat

\\xa0

Visit https://www.securityweekly.com/asw for all the latest episodes!

Show Notes: https://securityweekly.com/asw220

'