Open in app
Home
Notifications
Lists
Stories

Write
Omer Gil
Omer Gil

Home
About

Published in Cider Security

·Feb 8

PPE — Poisoned Pipeline Execution

Running malicious code in your CI, without access to your CI — Authors Omer Gil, Head of Research @ Cider Security Daniel Krivelevich, CTO @ Cider Security Intro Dev environments have become a major part of today’s attack surface. And within them, the most lucrative assets are the systems responsible for CI and CD — those that build, test, and deploy code — and…

Supply Chain

19 min read

PPE — Poisoned Pipeline Execution
PPE — Poisoned Pipeline Execution

Published in Cider Security

·Oct 12, 2021

Bypassing required reviews using GitHub Actions

Not using GitHub Actions? You’re also vulnerable. — TL;DR A newly discovered security flaw in GitHub allows leveraging GitHub Actions to bypass the required reviews mechanism and push unreviewed code to a protected branch, potentially allowing malicious code to be used by other users or flow down the pipeline to production. The risk of a compromised user account GitHub is the most popular source control management…

Github

6 min read

Bypassing required reviews using GitHub Actions
Bypassing required reviews using GitHub Actions
Omer Gil

Omer Gil

Head of Research at Cider Security.

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Knowable