new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

ci-cd/plugin-management

4 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Plugin Management: apply least privilege to installations

Least privileges must be enforced to ensure only a small subset of users have the permissions required to extend CI/CD platforms with plugins or integrations.

Plugin Management: vet before installation

Plugins or integrations must be vetted before installation. Questions to consider include: Is the vendor a recognized and respected developer? Does the vendor have a strong history in application security? How popular is the plugin? Is it actively maintained? Will it require configuration changes that reduce security? Does the organization have resources to properly configure it?

Plugin Management: incorporate into configuration management

After a plugin or integration has been approved, it must be incorporated into the organization's configuration management processes. The software must be kept up-to-date with security patches.

Plugin Management: continually review for value

Extensions must be continually reviewed for value; if no longer needed, the extension should be removed.

Give your agent this brain