Least privilege & CI trust
Security & software supply chain
Least privilege & CI trust
Least privilege limits what a CI identity can do. Use short-lived OIDC credentials for cloud access. Keep jobs that run untrusted pull request code apart from jobs that hold deployment secrets.
Resources
Links marked “Amazon affiliate link” open an Amazon product page. As an Amazon Associate I earn from qualifying purchases. About affiliate links
GitHub Actions: secure use referenceDocumentation · GitHub · opens in a new tabPreventing pwn requests in GitHub ActionsArticle · GitHub Security Lab · opens in a new tabGitHub Actions: OpenID ConnectDocumentation · GitHub · opens in a new tabSecuring DevOpsBook · Julien Vehent · Amazon affiliate link, opens Amazon in a new tabDevOps guides (in French)Blog · Stéphane Robert · opens in a new tabOWASP Cheat Sheet SeriesReference · OWASP · opens in a new tabAlice and Bob Learn Application SecurityBook · Tanya Janca · Amazon affiliate link, opens Amazon in a new tabDeveloping Secure Software (LFD121)Course · OpenSSF, The Linux Foundation · opens in a new tab