The Application Security Podcast

The Application Security Podcast


François Proulx - Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages

October 22, 2024

Franois Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain. To help address this, his team developed an open source scanner cal