Przejdź do głównej zawartości
Ikona megafonu

Buduj aplikacje natywne w chmurze

Gotowy na AI? Dowiedz się, jak budować i skalować aplikacje natywne w chmurze za pomocą Azure.

LEARN, CONNECT, BUILD

Microsoft Reactor

Dołącz do usługi Microsoft Reactor i skontaktuj się z deweloperami na żywo

Chcesz rozpocząć pracę ze sztuczną inteligencją i najnowszymi technologiami? Usługa Microsoft Reactor udostępnia zdarzenia, szkolenia i zasoby społeczności, które ułatwiają deweloperom, przedsiębiorcom i startupom tworzenie technologii sztucznej inteligencji i nie tylko. Dołącz do nas!

LEARN, CONNECT, BUILD

Microsoft Reactor

Dołącz do usługi Microsoft Reactor i skontaktuj się z deweloperami na żywo

Chcesz rozpocząć pracę ze sztuczną inteligencją i najnowszymi technologiami? Usługa Microsoft Reactor udostępnia zdarzenia, szkolenia i zasoby społeczności, które ułatwiają deweloperom, przedsiębiorcom i startupom tworzenie technologii sztucznej inteligencji i nie tylko. Dołącz do nas!

Wróć

The Quote-to-Cash Blind Spot: Secret Scanning for Enterprise Revenue Systems

9 września, 2026 | 5:00 PM - 6:00 PM (UTC) Skoordynowany czas uniwersalny

  • Formatuj:
  • alt##LivestreamTransmisja na żywo

Temat: Zabezpieczenia

Język: angielski

Every CPQ, CLM, and billing rollout I've run wires Salesforce or Vlocity to DocuSign, Stripe or Zuora-type billing, and ERP through API keys and OAuth tokens sitting in DataRaptors, Integration Procedures, and deployment scripts. AppSec teams usually classify that layer as "business configuration," so it never gets scanned the way application code does.

Where credentials actually live in a quote-to-cash stack: middleware scripts, integration procedures, CI/CD for CPQ deployments. Why "business systems" teams don't think of themselves as a scanning target, and what that costs. How GitHub Advanced Security's secret scanning, push protection, and custom patterns close the gap, even for teams that don't see themselves as developers.

A sample repo modeling a CPQ integration script with a hardcoded OAuth token and API key. Push protection blocking a commit in real time. A custom regex pattern built for an enterprise revenue-tool token format. The alert triage view a security lead would actually work from.

  • DevSecOps
  • Security
  • GitHub Copilot
  • GitHub Advanced Security

Prelegenci

Masz już zarejestrowane i chcesz anulować? Anulowanie rejestracji

Rejestracja

Zaloguj się przy użyciu konta Microsoft

Zaloguj

Możesz też wprowadzić swój adres e-mail, aby się zarejestrować

*

Rejestrując się na potrzeby tego wydarzenia, zgadzasz się przestrzegać Kodeks postępowania w usłudze Microsoft Reactor.

Części tej strony mogą być tłumaczone maszynowo lub przez AI.