Eshaan Jain
T-Mobile (via Mphasis)
LEARN, CONNECT, BUILD
AI 및 최신 기술을 시작할 준비가 되셨나요? Microsoft Reactor는 개발자, 기업가 및 신생 기업이 AI 기술 등을 기반으로 구축하는 데 도움이 되는 이벤트, 교육 및 커뮤니티 리소스를 제공합니다. 참여하세요.
LEARN, CONNECT, BUILD
AI 및 최신 기술을 시작할 준비가 되셨나요? Microsoft Reactor는 개발자, 기업가 및 신생 기업이 AI 기술 등을 기반으로 구축하는 데 도움이 되는 이벤트, 교육 및 커뮤니티 리소스를 제공합니다. 참여하세요.
9 9월, 2026 | 5:00 오후 - 6:00 오후 (UTC) 협정 세계시
항목: 보안
언어: 영어
Every CPQ, CLM, and billing rollout I've run wires Salesforce or Vlocity to DocuSign, Stripe or Zuora-type billing, and ERP through API keys and OAuth tokens sitting in DataRaptors, Integration Procedures, and deployment scripts. AppSec teams usually classify that layer as "business configuration," so it never gets scanned the way application code does.
Where credentials actually live in a quote-to-cash stack: middleware scripts, integration procedures, CI/CD for CPQ deployments. Why "business systems" teams don't think of themselves as a scanning target, and what that costs. How GitHub Advanced Security's secret scanning, push protection, and custom patterns close the gap, even for teams that don't see themselves as developers.
A sample repo modeling a CPQ integration script with a hardcoded OAuth token and API key. Push protection blocking a commit in real time. A custom regex pattern built for an enterprise revenue-tool token format. The alert triage view a security lead would actually work from.
스피커
이미 등록되어 있으며 취소해야 합니까? 등록 취소
이 이벤트는 다음의 일부입니다. Spotlight on GitHub Advanced Security Series.
여기를 클릭하여 시리즈 페이지 방문 예정된 모든 주문형 이벤트를 볼 수 있는 위치입니다.