Loading…
In-person + Virtual
18-21 April
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon Europe 2023 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Central European Summer Time (UTC +2). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change and session seating is available on a first-come, first-served basis. 
Wednesday, April 19 • 16:30 - 17:05
Verifiable GitHub Actions with eBPF - Jose Donizetti, Aqua

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.


GitHub actions have been one of the most popular ways to build and release software, with recent developments in supply chain security it became a major target for malicious attacks. A couple of years ago a widespread hack to codecov, a popular service prevalent in build pipelines, caught the industry’s attention. In response, a new solution to protect the build pipeline was created on top of Tracee, OSS Runtime Security solution, and introduced the concept of profiling with eBPF and verifying software builds. In this talk, we will present that solution and explore the lessons learned in the past two years since the initial release.

Speakers
JD

Jose Donizetti

Open Source Developer, Aqua
Jose Donizetti is an OpenSource Engineer at Aqua working on projects like Tracee and Trivy. In the past he was running thousands of redis at Shopify platform caching team.



Wednesday April 19, 2023 16:30 - 17:05 CEST
D201-202 | Second Floor | Congress Centre (Elicium Building)
  CI/CD