5 ms·
I'm kind of shocked all y'all commentators have such well secured CI systems. ;) I've been developing software for 17 years, and at every employer, from 2 to 20
by passive 10y ago
I'm kind of shocked all y'all commentators have such well secured CI systems. ;)
I've been developing software for 17 years, and at every employer, from 2 to 20,000 employees, CI systems were treated as an afterthought in terms of infrastructure and security resources.
It was dramatically obvious how bad this was from a security perspective, so perhaps this article isn't necessary, but certainly it's right on the money.
- xahrepap 10y agoWe have a CI tool that I've been trying to secure for a long time. Usually when I add something (SSL so people can't sniff passwords / hijack sessions) the response I get from some others is "why bother? If something bad happens the person who does it will be fired!" It baffles me really. Most of the time I do it anyway. But we still have a few major holes I've been slowly patching. There's one last glaring problem: permissions are controlled by teams in an external tool. Anyone has auth to change teams in said tool.