🌱 I’m currently learning AI and Blockchain-related topics
💬 Ask me about Incident Response, SecTools, DFIR, Best Practices
📫 Reach me at [email protected] to hire me!
🌱 I’m currently learning AI and Blockchain-related topics
💬 Ask me about Incident Response, SecTools, DFIR, Best Practices
📫 Reach me at [email protected] to hire me!
Forked from OWASP/API-Security
OWASP API Security Project
Dockerfile 2
# How to use this Template
- Install Terraform: Ensure you have Terraform installed locally.
- Configure providers: Authenticate with AWS, Azure and GCP using your credentials.
- Set variables: Define the necessary variables in a .tfvars file.
## My **best practices** to harden GitHub Actions workflows and protect sensitive assets used during automated builds and deployments.
---
## **1. Use minimal permissions for workflows**
### Scans Both Application Code and Infrastructure as Code Files
Recommended secrets scanning solution criteria:
• Scans for secrets in both IaC and application code
• Augments secrets scanning with the context of an IaC file around the secret
Une liste de liens permettant de se former aux outils utilisés dans le domaine du DevSecOps
Liste de liens permettant de se former aux outils utilisés dans le domaine du SecOps