Security Weekly Podcast Network (Audio) cover image

Researching and Remediating RCEs via GitHub Actions - Bar Kaduri, Roi Nisimi - ASW #355

Security Weekly Podcast Network (Audio)

00:00

What fixes and mitigations did you recommend?

Mike asks about remediation; Roy and Bar describe removing pull_request_target, adding guardrails, labels, approvals, and improving docs and defaults.

Play episode from 28:38
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app