What's new

Welcome to Free download educational resource and Apps from TUTBB

Join us now to get access to all our features. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, and so, so much more. It's also quick and totally free, so what are you waiting for?

GitHub Actions Security Masterclass Secure CI/CD Pipelines

TUTBB

Active member
Joined
Apr 9, 2022
Messages
192,578
Reaction score
20
Points
38
b19ee3d52eb09f1451ba7f21667bb409.webp

GitHub Actions Security Masterclass Secure CI/CD Pipelines
Published 9/2026
Created by Dogukan Saner
MP4 | Video: h264, 1920x1080 | Audio: AAC, 44.1 KHz, 2 Ch
Level: Intermediate | Genre: eLearning | Language: English | Duration: 48 Lectures ( 6h 5m ) | Size: 2.8 GB​

Defend workflows, tokens, secrets, OIDC, runners, artifacts, and software supply chains through hands-on labs
What you'll learn
⚡ Audit GitHub Actions workflows and identify risky trust paths from untrusted input to production authority
⚡ Harden triggers, permissions, secrets, OIDC identities, third-party actions, and reusable workflows
⚡ Secure runners, caches, artifacts, SBOMs, provenance, attestations, and deployment pipelines
⚡ Detect, investigate, and recover from CI/CD supply-chain incidents using practical defensive methods
Requirements
❗ Basic familiarity with Git, GitHub, and YAML is helpful but not required
❗ A basic understanding of CI/CD concepts is recommended
❗ A Windows, macOS, or Linux computer with Python 3 and a terminal
❗ No paid GitHub account, cloud account, production credentials, or prior cybersecurity experience is required. All labs use safe, offline synthetic files
Description
This course contains the use of artificial intelligence.
All course content, instructional methods, technical explanations, examples, and practical labs were created by me based on my professional work and experience. All educational content is my original work. AI tools were used for audiovisual production, including the course videos and voice narration. I personally reviewed every lesson for technical accuracy, pronunciation, clarity, safety, and overall learner experience.
GitHub Actions can test code, access secrets, publish packages, generate releases, assume cloud identities, and deploy applications to production. This makes CI/CD automation an important production security boundary and a critical part of software supply-chain security.
GitHub Actions Security Masterclass: Secure CI/CD Pipelines is a practical, defense-focused course designed to teach you how to review, harden, monitor, and protect GitHub Actions workflows. The course follows a structured methodology, beginning with workflow execution and trust modeling before progressing through secure triggers, untrusted input, token permissions, secrets, OIDC, third-party actions, reusable workflows, runners, artifacts, provenance, deployment controls, incident response, and organization-wide governance.
What You Will Learn
✨ Understand how GitHub Actions workflows, jobs, steps, contexts, actions, and runners interact.
✨ Trace trust and authority from an incoming event to a production artifact or deployment.
✨ Select secure workflow triggers and prevent untrusted input from reaching executable contexts.
✨ Minimize GITHUB_TOKEN permissions and reduce the exposure of repository secrets.
✨ Replace long-lived cloud credentials with narrowly constrained OIDC identities.
✨ Review and pin third-party actions, reusable workflows, and custom actions securely.
✨ Protect build inputs, lockfiles, caches, artifacts, and cross-workflow data.
✨ Generate and verify SBOM, provenance, artifact attestations, and SLSA-related evidence.
✨ Isolate GitHub-hosted and self-hosted runners from untrusted workloads and persistent state.
✨ Enforce deployment protection using environments, approvals, CODEOWNERS, rulesets, and organization policies.
✨ Detect unexpected workflow changes, investigate supply-chain incidents, and restore trust safely.
✨ Audit and harden an intentionally weak CI/CD pipeline through an end-to-end capstone project.
Each lesson combines focused explanations, visual trust-path diagrams, terminal demonstrations, weak-versus-hardened comparisons, evidence interpretation, defensive guidance, and verification checks. You will learn not only which security settings to use, but also how to understand the trust relationships they protect, verify whether each control is effective, and avoid unsupported security conclusions.
All practical demonstrations use deterministic synthetic profiles and local course files. The labs do not contact GitHub, access cloud accounts, read real credentials, execute workflows, or modify production systems.
This course is suitable for DevOps engineers, DevSecOps professionals, platform engineers, cloud security engineers, application security specialists, software developers, SREs, security analysts, auditors, incident responders, and cybersecurity students. Previous GitHub Actions security experience is not required, although basic familiarity with Git, YAML, command-line tools, and CI/CD concepts will be helpful.
Security methods must be applied only to repositories and environments you own or are explicitly authorized to review.
Who this course is for
⭐ DevOps, DevSecOps, platform, cloud, and SRE professionals who manage GitHub Actions pipelines
⭐ Developers and technical leads who want to build safer CI/CD workflows
⭐ Application security and cloud security engineers responsible for software supply-chain protection
⭐ Security analysts, auditors, and incident responders who need practical GitHub Actions review and investigation skills
⭐ Beginners seeking hands-on CI/CD security experience through safe, defensive labs
Homepage
Code:
https://www.udemy.com/course/github-actions-security-masterclass-secure-cicd-pipelines

Recommend Download Link Hight Speed | Please Say Thanks Keep Topic Live

Rapidgator
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part1.rar.html
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part2.rar.html
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part3.rar.html
AlfaFile
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part1.rar
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part2.rar
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part3.rar
DDownload
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part1.rar
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part2.rar
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part3.rar
KatFile
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part1.rar.html
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part2.rar.html
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part3.rar.html
FreeDL
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part1.rar.html
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part2.rar.html
jilpf.GitHub.Actions.Security.Masterclass.Secure.CICD.Pipelines.part3.rar.html
No Password - Links are Interchangeable
 
Top Bottom