Ignora e passa al contenuto principale
Icona del megafono

Crea app native nel cloud

Pronto per l'IA? Scopri come costruire e scalare app cloud-native con Azure.

LEARN, CONNECT, BUILD

Microsoft Reactor

Partecipa a Microsoft Reactor e interagisci con gli sviluppatori live

Sei pronto per iniziare a usare l''intelligenza artificiale e le tecnologie più recenti? Microsoft Reactor fornisce eventi, formazione e risorse della community per aiutare sviluppatori, imprenditori e startup a sviluppare la tecnologia di intelligenza artificiale e altro ancora. Unisciti a noi.

LEARN, CONNECT, BUILD

Microsoft Reactor

Partecipa a Microsoft Reactor e interagisci con gli sviluppatori live

Sei pronto per iniziare a usare l''intelligenza artificiale e le tecnologie più recenti? Microsoft Reactor fornisce eventi, formazione e risorse della community per aiutare sviluppatori, imprenditori e startup a sviluppare la tecnologia di intelligenza artificiale e altro ancora. Unisciti a noi.

Indietro

The Quote-to-Cash Blind Spot: Secret Scanning for Enterprise Revenue Systems

9 settembre, 2026 | 5:00 PM - 6:00 PM (UTC) Coordinated Universal Time

  • Formato:
  • alt##LivestreamLive Stream

Argomento: Sicurezza

Lingua: italiano

Every CPQ, CLM, and billing rollout I've run wires Salesforce or Vlocity to DocuSign, Stripe or Zuora-type billing, and ERP through API keys and OAuth tokens sitting in DataRaptors, Integration Procedures, and deployment scripts. AppSec teams usually classify that layer as "business configuration," so it never gets scanned the way application code does.

Where credentials actually live in a quote-to-cash stack: middleware scripts, integration procedures, CI/CD for CPQ deployments. Why "business systems" teams don't think of themselves as a scanning target, and what that costs. How GitHub Advanced Security's secret scanning, push protection, and custom patterns close the gap, even for teams that don't see themselves as developers.

A sample repo modeling a CPQ integration script with a hardcoded OAuth token and API key. Push protection blocking a commit in real time. A custom regex pattern built for an enterprise revenue-tool token format. The alert triage view a security lead would actually work from.

  • DevSecOps
  • Security
  • GitHub Copilot
  • GitHub Advanced Security

Relatori

Già registrato ed è necessario annullare? Annullare la registrazione

Registrazione

Accedere con l'account Microsoft

Eseguire l'accesso

In alternativa, immettere l''indirizzo di posta elettronica per la registrazione

*

Registrando per questo evento si accetta di rispettare il Codice di condotta del reattore Microsoft.

Parti di questa pagina possono essere tradotte da macchina o IA.