Garance
Garance works at Depi in the offensive security research team, and she is specialising in software supply chain security. She love understanding and learning random things in the world around her and meeting new people.
Session
10-29
10:30
50min
How to capitalise on other people’s popularity to distribute malware: Weaponizing CI/CD Pipelines
Garance
I am going to talk about software supply chain security, more precisely about exploiting CI/CD pipelines in GitHub so as to publish malicious versions of popular open source packages (just for example, on npmjs), write arbitrary code in GitHub repos or steal secrets.
Talks
Main Hall