<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>VelocityConf on webratz.de</title><link>https://www.webratz.de/tags/velocityconf/</link><description>Recent content in VelocityConf on webratz.de</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 24 Nov 2019 10:52:52 +0200</lastBuildDate><atom:link href="https://www.webratz.de/tags/velocityconf/index.xml" rel="self" type="application/rss+xml"/><item><title>Privilege Escalation in Build Pipelines</title><link>https://www.webratz.de/article/privilege-escalation-build-pipelines/</link><pubDate>Sun, 24 Nov 2019 10:52:52 +0200</pubDate><guid>https://www.webratz.de/article/privilege-escalation-build-pipelines/</guid><description>&lt;p&gt;I recently gave a talk at &lt;a href="https://conferences.oreilly.com/velocity/vl-eu"&gt;O&amp;rsquo;Reilly Velocity Conference&lt;/a&gt; in Berlin.
My initial plan was to create a blog version of it also, but I didn&amp;rsquo;t have enough time.
Luckily there is a recording and the slides are available! Here&amp;rsquo;s the abstract:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;CI/CD systems are usually tightly coupled, and inherit for the CD part a lot of administrative privileges combined with network access to production systems. We tend to believe that we only execute trusted software within those systems, but it quickly becomes clear that code from a huge variety of sources is loaded and executed in that system that isn’t under your control.&lt;/p&gt;</description></item></channel></rss>