
François Proulx - Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages
Om avsnittet
François Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain. To help address this, his team developed an open source scanner called Poutine that can identify vulnerable build pipelines at scale and provide remediation guidance. Francois has over 10 years of experience in building application security programs, he’s also the founder of the NorthSec conference in Montreal. François Proulx is a senior product security engineer at Boost Security, where he leads the supply chain research team. With over 10 years of experience building AppSec programs for companies like Intel and various startups, he's been instrumental in the DevSecOps movement, making numerous responsible disclosures to organizations such as AWS, Google, Red Hat, and ChainGuard, and speaking at conferences on the topic.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Our training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.
→ Learn more about Security Journey
Connect with François Proulx:
→ LinkedIn
→ Poutine
Mentioned in this episode:
→ Poutine
→ Living Off the Pipeline
→ NorthSec
→ Cooking for Geeks
→ Grand Theft Actions Abusing Self Hosted GitHub Runners
→ LinkedIn
→ François Proulx -- Actionable Software Supply Chain Security
→ TLDR newsletter
→ CycloneDX
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet François Proulx: Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages
01:51 We're joined by Francois Proulx, second-time visit slash visitor to the
04:39 It always, I mean, it raises your game to have to
06:46 Okay. Hey, Francois, I know you talked recently at a thing
12:44 Let me, let me read this back to you and make
15:53 So make sure, I wanna make sure I understand here. So
19:46 Game over, right
23:04 Okay. And then, yeah. So from there, the sky's the limit
25:17 Okay. So it seems like when I think about solutions, and
29:41 Yeah. I'm going to stick up for Microsoft for a minute
32:45 I think there's hope for the future that, that somebody will
35:13 Okay. So just to quickly touch on Poutine, if I am
40:59 All right. Yeah, we have 3 questions as well as we've
43:02 Great, very timely. Who is somebody that our listeners should know
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.