2024
DOI: 10.4236/jsea.2024.175018
|View full text |Cite
|
Sign up to set email alerts
|

Sher: A Secure Broker for DevSecOps and CI/CD Workflows

Pranau Kumar,
Vijay K. Madisetti

Abstract: GitHub Actions, a popular CI/CD platform, introduces significant security challenges due to its integration with GitHub's open ecosystem and its use of flexible workflow configurations. This paper presents Sher, a Python-based tool that enhances the security of GitHub Actions by automating the detection and remediation of security issues in workflows. Self-Hosted Ephemeral Runner, or Sher, acts as a broker between GitHub's APIs and a customizable, isolated environment, analyzing workflows through a static rule… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...

Citation Types

0
0
0

Publication Types

Select...

Relationship

0
0

Authors

Journals

citations
Cited by 0 publications
references
References 4 publications
0
0
0
Order By: Relevance

No citations

Set email alert for when this publication receives citations?