Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

GitHub Actions: A Cloudy Day for Security

NDC Conferences via YouTube

Overview

Coursera Plus Monthly Sale: All Certificates & Courses 40% Off!
Explore a comprehensive conference talk from NDC Security in Oslo where Sofia Lindqvist examines the security challenges of GitHub Actions when integrated with major cloud providers. Learn how GitHub Actions functions as a CI/CD tool for workflow automation and discover the security implications when connecting to Azure, GCP, and AWS. The presentation details both secure and insecure integration methods, with particular focus on OIDC/federated identity approaches that eliminate the need for secret management. Understand common misconfiguration pitfalls that can lead to lateral movement, privilege escalation, and other vulnerabilities. The talk includes real-world examples of GitHub Actions security vulnerabilities, primarily in Azure integrations, providing practical insights for developers working with cloud deployments and CI/CD pipelines.

Syllabus

GitHub Actions: A Cloudy Day for Security - Sofia Lindqvist - NDC Security 2025

Taught by

NDC Conferences

Reviews

Start your review of GitHub Actions: A Cloudy Day for Security

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.