期刊文献+
共找到1篇文章
< 1 >
每页显示 20 50 100
Sher: A Secure Broker for DevSecOps and CI/CD Workflows
1
作者 Pranau Kumar Vijay K. Madisetti 《Journal of Software Engineering and Applications》 2024年第5期321-339,共19页
GitHub Actions, a popular CI/CD platform, introduces significant security challenges due to its integration with GitHub’s open ecosystem and its use of flexible workflow configurations. This paper presents Sher, a Py... GitHub Actions, a popular CI/CD platform, introduces significant security challenges due to its integration with GitHub’s open ecosystem and its use of flexible workflow configurations. This paper presents Sher, a Python-based tool that enhances the security of GitHub Actions by automating the detection and remediation of security issues in workflows. Self-Hosted Ephemeral Runner, or Sher, acts as a broker between GitHub’s APIs and a customizable, isolated environment, analyzing workflows through a static rules engine and automatically fixing identified issues. By providing a secure, ephemeral runner environment and a dynamic analysis tool, Sher addresses common misconfigurations and vulnerabilities, contributing to the resilience and integrity of DevSecOps practices within software development pipelines. 展开更多
关键词 CI/CD Pipelines GitHub gitops DevSecOps ISOLATION Security SAST
下载PDF
上一页 1 下一页 到第
使用帮助 返回顶部