EPISODE · Oct 22, 2024 · 45 MIN
François Proulx - Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
François Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain. To help address this, his team developed an open source scanner called Poutine that can identify vulnerable build pipelines at scale and provide remediation guidance. Francois has over 10 years of experience in building application security programs, he’s also the founder of the NorthSec conference in Montreal. François Proulx is a senior product security engineer at Boost Security, where he leads the supply chain research team. With over 10 years of experience building AppSec programs for companies like Intel and various startups, he's been instrumental in the DevSecOps movement, making numerous responsible disclosures to organizations such as AWS, Google, Red Hat, and ChainGuard, and speaking at conferences on the topic.The Application Security Podcast is brought to you by Security Journey.About Security JourneyOur training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.→ Learn more about Security JourneyConnect with François Proulx:→ LinkedIn→ PoutineMentioned in this episode:→ Poutine→ Living Off the Pipeline→ NorthSec→ Cooking for Geeks→ Grand Theft Actions Abusing Self Hosted GitHub Runners→ LinkedIn→ François Proulx -- Actionable Software Supply Chain Security→ TLDR newsletter→ CycloneDXFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet François Proulx: Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages01:51 We're joined by Francois Proulx, second-time visit slash visitor to the04:39 It always, I mean, it raises your game to have to06:46 Okay. Hey, Francois, I know you talked recently at a thing12:44 Let me, let me read this back to you and make15:53 So make sure, I wanna make sure I understand here. So19:46 Game over, right23:04 Okay. And then, yeah. So from there, the sky's the limit25:17 Okay. So it seems like when I think about solutions, and29:41 Yeah. I'm going to stick up for Microsoft for a minute32:45 I think there's hope for the future that, that somebody will35:13 Okay. So just to quickly touch on Poutine, if I am40:59 All right. Yeah, we have 3 questions as well as we've43:02 Great, very timely. Who is somebody that our listeners should know
Embed this episode
What this episode covers
François Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain. To help address this, his team developed an open source scanner called Poutine that can identify vulnerable build pipelines at scale and provide remediation guidance. Francois has over 10 years of experience in building application security programs, he’s also the founder of the NorthSec conference in Montre...
Ready to play
François Proulx - Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.