Omer Gil and Daniel Krivelevich -- Top 10 CI/CD Security Risks episode artwork

EPISODE · Apr 25, 2022 · 50 MIN

Omer Gil and Daniel Krivelevich -- Top 10 CI/CD Security Risks

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

CI/CD systems hold code, credentials, and production access, yet many organizations still treat them as internal plumbing rather than a critical attack surface. Omer Gil and Daniel Krivelevich join Chris and Robert to explain the research behind the Top 10 CI/CD Security Risks. They trace lessons from SolarWinds and Codecov, show why pipeline security often falls between AppSec and infrastructure teams, and describe how the list was built with community input. The discussion turns the risks into practical guidance for threat modeling pipelines, reducing exposure, assigning ownership, and using the intentionally vulnerable CI/CD Goat project to learn safely by doing.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Omer Gil and Daniel Krivelevich:→ Omer Gil on LinkedIn→ Daniel Krivelevich on LinkedIn→ Top 10 CI/CD Security RisksMentioned in this episode:→ Top 10 CI/CD Security Risks→ Threat Modeling Manifesto→ CI/CD GoatFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The hidden attack surface in CI/CD02:03 Why create a CI/CD security top ten04:30 How the project began11:17 Making the risks useful to developers14:49 Lessons from SolarWinds and Codecov21:26 Why CI/CD security falls through the cracks27:17 Research and community collaboration30:38 Building and ranking the risk list35:20 Mitigations teams can apply39:33 When internal build systems are exposed44:18 Threat modeling the software pipeline48:44 Learning with CI/CD Goat

Episode metadata supplied by the publisher feed · Published Apr 25, 2022

Embed this episode

CI/CD systems hold code, credentials, and production access, yet many organizations still treat them as internal plumbing rather than a critical attack surface. Omer Gil and Daniel Krivelevich join Chris and Robert to explain the research behind the Top 10 CI/CD Security Risks. They trace lessons from SolarWinds and Codecov, show why pipeline security often falls between AppSec and infrastructure teams, and describe how the list was built with community input. The discussion turns the risks i...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Omer Gil and Daniel Krivelevich -- Top 10 CI/CD Security Risks

0:00 50:40

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 50 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on April 25, 2022.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!