Session

Treat Your Build Like Prod. Attackers Already Do.

Your CI system holds publishing credentials, signs releases, and runs code nobody on your team has reviewed. Its output is the software your customers run or use, which makes that pipeline production. Almost nobody treats it that way.

We'll map the trust boundary of your pipeline: where third-party code runs, which secrets are in reach, and who controls the definition. Then we'll repeat it on a developer laptop, where an AI agent drives builds and tooling with your credentials and less oversight than CI. Codecov and tj-actions both fell to trusted tooling nobody reviewed.

You'll leave able to draw both boundaries yourself. The hardening that pays off first: pinned versions, scoped tokens, ephemeral runners, and build records you keep long enough to answer questions later.

Brian Demers

Java Champion & Gradle Developer Advocate

Concord, New Hampshire, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top