Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

François Proulx - Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages

46 min22 oktober 2024

Om avsnittet

François Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain. To help address this, his team developed an open source scanner called Poutine that can identify vulnerable build pipelines at scale and provide remediation guidance. Francois has over 10 years of experience in building application security programs, he’s also the founder of the NorthSec conference in Montreal. François Proulx is a senior product security engineer at Boost Security, where he leads the supply chain research team. With over 10 years of experience building AppSec programs for companies like Intel and various startups, he's been instrumental in the DevSecOps movement, making numerous responsible disclosures to organizations such as AWS, Google, Red Hat, and ChainGuard, and speaking at conferences on the topic.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Our training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.
Learn more about Security Journey

Connect with François Proulx:
LinkedIn
Poutine

Mentioned in this episode:
Poutine
Living Off the Pipeline
NorthSec
Cooking for Geeks
Grand Theft Actions Abusing Self Hosted GitHub Runners
LinkedIn
François Proulx -- Actionable Software Supply Chain Security
TLDR newsletter
CycloneDX

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet François Proulx: Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages
01:51 We're joined by Francois Proulx, second-time visit slash visitor to the
04:39 It always, I mean, it raises your game to have to
06:46 Okay. Hey, Francois, I know you talked recently at a thing
12:44 Let me, let me read this back to you and make
15:53 So make sure, I wanna make sure I understand here. So
19:46 Game over, right
23:04 Okay. And then, yeah. So from there, the sky's the limit
25:17 Okay. So it seems like when I think about solutions, and
29:41 Yeah. I'm going to stick up for Microsoft for a minute
32:45 I think there's hope for the future that, that somebody will
35:13 Okay. So just to quickly touch on Poutine, if I am
40:59 All right. Yeah, we have 3 questions as well as we've
43:02 Great, very timely. Who is somebody that our listeners should know

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.