メイン コンテンツにスキップ
メガホンアイコン

クラウドネイティブアプリを構築する

AIの準備はできていますか? Azureでクラウドネイティブアプリを構築し拡張する方法を発見しましょう。

学ぶ、つながる、構築する

Microsoft Reactor

Microsoft Reactor に参加し、開発者とライブで交流する

AI と最新のテクノロジを使い始める準備はできましたか? Microsoft Reactor は、開発者、起業家、スタートアップ企業が AI テクノロジなどを構築するのに役立つイベント、トレーニング、コミュニティ リソースを提供します。 ご参加ください。

学ぶ、つながる、構築する

Microsoft Reactor

Microsoft Reactor に参加し、開発者とライブで交流する

AI と最新のテクノロジを使い始める準備はできましたか? Microsoft Reactor は、開発者、起業家、スタートアップ企業が AI テクノロジなどを構築するのに役立つイベント、トレーニング、コミュニティ リソースを提供します。 ご参加ください。

戻る

The Quote-to-Cash Blind Spot: Secret Scanning for Enterprise Revenue Systems

9 9月, 2026 | 5:00 午後 - 6:00 午後 (UTC) 協定世界時

  • 形式:
  • alt##Livestreamライブストリーム

トピック: セキュリティ

言語: 英語

Every CPQ, CLM, and billing rollout I've run wires Salesforce or Vlocity to DocuSign, Stripe or Zuora-type billing, and ERP through API keys and OAuth tokens sitting in DataRaptors, Integration Procedures, and deployment scripts. AppSec teams usually classify that layer as "business configuration," so it never gets scanned the way application code does.

Where credentials actually live in a quote-to-cash stack: middleware scripts, integration procedures, CI/CD for CPQ deployments. Why "business systems" teams don't think of themselves as a scanning target, and what that costs. How GitHub Advanced Security's secret scanning, push protection, and custom patterns close the gap, even for teams that don't see themselves as developers.

A sample repo modeling a CPQ integration script with a hardcoded OAuth token and API key. Push protection blocking a commit in real time. A custom regex pattern built for an enterprise revenue-tool token format. The alert triage view a security lead would actually work from.

  • DevSecOps
  • Security
  • GitHub Copilot
  • GitHub Advanced Security

講演者

登録をキャンセルする必要がありますか? 登録のキャンセル

登録

Microsoft アカウントでサインインします

サインイン

または自分のメール アドレスを入力して登録してください

*

このイベントに登録することで Microsoft Reactor 倫理規定に同意したことになります.

このページの一部は機械またはAIによって翻訳される場合があります。