Wednesday 

Room 3 

17:40 - 18:40 

(UTC+01

Talk (60 min)

Beyond the Commit: Weaponizing and Hardening GitHub Actions for Security

GitHub Actions, the backbone of modern CI/CD, has become the primary target in recent, high profile supply chain attacks.

DevOps
SDLC

Incidents like the compromise of the popular tj-actions/changed-files (impacting over 23,000 repositories) and the multi stage S1ngularity (Nx) attack exposed the immense blast radius of pipeline vulnerabilities, leading to the leak of thousands of sensitive credentials and the compromise of private source code.

The security of your software supply chain is at stake. We will break down the technical mechanics of these breaches and present actionable, practical principles to secure your automation against credential theft, script injection, and third party action hijacking. Crucially, these supply chain protection principles (from the Principle of Least Privilege governing secret scope and lifetime to dependency vetting and input sanitization) are not limited to GitHub; they are universally applicable for securing any modern CI/CD system. You will walk away with a clear roadmap and the tools needed to transform your pipeline from a critical vulnerability into a robust supply chain sentinel.

Niek Palm

Niek is a Principal Engineer in the Philips Software Center of Excellence. He supports businesses in the goal of building better software and engineering practices. Niek is closely involved in shaping the future of software within Philips by driving DevOps culture transformation. He is playing a key role in driving the InnerSource community in Philips to build faster, better software together. As public speaker, blogger, open source maintainer and book reviewer, he advocates and shares his expertise on key areas as Cloud, DevOps and Software Development.