[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]

/css/ - CSS Masters

Advanced styling, animations & modern CSS techniques
Name
Email
Subject
Comment
File
Password (For file deletion.)

File: 1783069488784.jpg (109.65 KB, 1024x1024, img_1783069449035_qvwvi6p8.jpg)ImgOps Exif Google Yandex

22a2f No.1831

just saw a breakdown of how that 2021 incident happened and it's terrifying how easy it was. attackers only needed to add one line to a bash script to compromise everything because every ci job is basically an unsupervised computer with ur secrets. we are all just one bad dependency away from disaster is anyone actually auditing their pipeline scripts regularly?

more here: https://dev.to/leobaniak/the-codecov-bash-uploader-is-five-years-old-and-the-class-of-attack-still-lives-in-your-pipeline-33ng

22a2f No.1832

File: 1783069645217.jpg (247.87 KB, 1024x1024, img_1783069629728_58e5c1sl.jpg)ImgOps Exif Google Yandex

start using oidc for cloud provider authentication to eliminate the need for long-lived secrets entirely



[Return] [Go to top] Catalog [Post a Reply]
Delete Post [ ]
[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]
. "http://www.w3.org/TR/html4/strict.dtd">