PodParley PodParley

Ep06: "GitHub Security horror stories " (with Steve Giguere)

An episode of the Tech Beats Unplugged podcast, hosted by Cloud Dude, titled "Ep06: "GitHub Security horror stories " (with Steve Giguere)" was published on June 10, 2025 and runs 65 minutes.

June 10, 2025 ·65m · Tech Beats Unplugged

0:00 / 0:00

👨🏽‍🚀 Welcome to Episode 06 of "Tech Beats unplugged" This time, we’re diving headfirst into 𝐭𝐡𝐞 𝐜𝐫𝐚𝐳𝐢𝐞𝐬𝐭 𝐆𝐢𝐭𝐇𝐮𝐛 𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐬𝐭𝐨𝐫𝐢𝐞𝐬, and who better to join us than Steve Giguere, an industry veteran and security expert who’s seen it all.From supply chain security mayhem to GitHub Actions gone wrong, we uncover real-world security blunders, attack vectors, and best practices to keep your repos and workflows safe.🌟 We’re so excited to share our latest tech Beats show with you🧡! Please share away 🤗We hope you'll enjoy it!!!Topics discussed: (00:00) Introduction(03:53) Software Supply Chain Security acronyms (SAST, DAST, IAST, etc.)(09:15) “A workflow is an application within your application” - What does that mean?!(12:16) Public vs. Private Repos - Are private orgs still at risk?(18:27) Self-hosted runners: Safe or security nightmare?(21:16) GitHub Environment Variables - How critical are they?(22:55) Secrets, masks, and how secure they really are (28:05) Artifact vs. Caching: Which is safer?(31:27) Craziest GitHub security screw-ups Steve has ever seen 🔥(36:42) Common attack vectors in GitHub Actions(44:19) Best security practices for GitHub Actions - Low-hanging fruit fixes 🍏(50:22) Are public actions safe? Can they be scanned?(53:52) xz backdoor fiasco - Lessons from the latest supply chain attack(59:00) NVD’s slowdown - What’s at stake?Show NotesCI/CD Goat (Deliberately vulnerable CI/CD environment): GitHubGitHub cache poisoning: Cacheract Attack | ScribeSecurityYour GitHub Secrets in Plain Text: CloudThrillGhat tool (Updating dependencies in GitHub Actions): GitHubOpenSSF Scorecard: WebsiteThe GitHub Worm (Asi Greenholts): Palo Alto BlogOWASP Top 10 CI/CD Risks: OWASPHeartbleed OpenSSL Exploit: Wikipedia🎙About Steve Giguere:⁠⁠⁠⁠Website: stevegiguere.comLinkedIn: Steve GiguereBook: Cloud Native Application Protection Platforms – O'ReillyPersonal Blog: CodifyreTalk Lessons Learned from OSS and GitOps Journey: YouTubeOWASP Lisbon Talk: YouTubeStayWiredIn YouTube Show: StayWiredInDevSecOps Podcast: Spotify

๐Ÿ‘จ๐Ÿฝโ€๐Ÿš€ Welcome to Episode 06 of "Tech Beats unplugged"

This time, weโ€™re diving headfirst into ๐ญ๐ก๐ž ๐œ๐ซ๐š๐ณ๐ข๐ž๐ฌ๐ญ ๐†๐ข๐ญ๐‡๐ฎ๐› ๐ฌ๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐ฌ๐ญ๐จ๐ซ๐ข๐ž๐ฌ, and who better to join us than Steve Giguere, an industry veteran and security expert whoโ€™s seen it all.

From supply chain security mayhem to GitHub Actions gone wrong, we uncover real-world security blunders, attack vectors, and best practices to keep your repos and workflows safe.

๐ŸŒŸ Weโ€™re so excited to share our latest tech Beats show with you๐Ÿงก! Please share away ๐Ÿค—

We hope you'll enjoy it!!!

Topics discussed:

  1. (00:00) Introduction
  2. (03:53) Software Supply Chain Security acronyms (SAST, DAST, IAST, etc.)
  3. (09:15) โ€œA workflow is an application within your applicationโ€ - What does that mean?!
  4. (12:16) Public vs. Private Repos - Are private orgs still at risk?
  5. (18:27) Self-hosted runners: Safe or security nightmare?
  6. (21:16) GitHub Environment Variables - How critical are they?
  7. (22:55) Secrets, masks, and how secure they really are
  8. (28:05) Artifact vs. Caching: Which is safer?
  9. (31:27) Craziest GitHub security screw-ups Steve has ever seen ๐Ÿ”ฅ
  10. (36:42) Common attack vectors in GitHub Actions
  11. (44:19) Best security practices for GitHub Actions - Low-hanging fruit fixes ๐Ÿ
  12. (50:22) Are public actions safe? Can they be scanned?
  13. (53:52) xz backdoor fiasco - Lessons from the latest supply chain attack
  14. (59:00) NVDโ€™s slowdown - Whatโ€™s at stake?

Show Notes

๐ŸŽ™About Steve Giguere:


DJ ALEX K DJ ALEX K A mixture of all things house, anything from funky vocal house, tech house, deep and dirty, progressive or jackin or tough, i just like house and beats that make you tap your feet, any feedback is greatly appreciated and get in touch for bookings at [email protected] Twitter @Infexious 2014. Thank you and enjoy the music. DJ MET DJ.ru/djmet-official Московский Mash Up & FreeStyle DJ. Молодой, но уже полюбившейся публике, благодаря особенному подходу к своим сетам. Использует разнообразные жанры: Pop,R&B,Hip-Hop,House (Future,G-House,Club House, Deep,Tech,Base), 80-90’s, Trap, Afro Beats. Так же во время сета применяет одну из сложнейших техник - Scratch, которая подвластна далеко не каждому. При сведении трэков использует Tone Play, Word Play, в рукаве всегда есть козырь в виде собственных мэшапов, эдитов, ремиксов. Постоянный гость и резиндент многих Московских баров и клубов. The Beat Logistix Podcast (Retro Trance) The Beat Logistix Podcast The Beat Logistix Podcast is a quarterly (three-monthly) retro Trance, Tech-Trance & Hardgroove Techno podcast from the mid-1990s through 2018 - Mixed by retired DJ, Carl Briggs. Love Bytes AMI-1 Welcome to "Love Bytes," the podcast where digital hearts beat in unison with human ones. In each episode, we decode the complexities of romance in the AI era, exploring how artificial intelligence is reshaping our notions of love, connection, and companionship. Join us as we dive into the world where algorithms meet emotions, and discover the future of affection in the age of AI. Whether you're a hopeless romantic or a tech enthusiast, "Love Bytes" is your portal to understanding the evolving landscape of love.
URL copied to clipboard!