Pular para o conteúdo principal
Ícone do megafone

Construa Aplicativos Nativos na Nuvem

Pronto para a IA? Descubra como construir e escalar aplicativos nativos em nuvem com Azure.

APRENDER, CONECTAR, CRIAR

Microsoft Reactor

Junte-se ao Microsoft Reactor e interaja com os desenvolvedores ao vivo

Pronto para começar a usar a IA e as tecnologias mais recentes? O Microsoft Reactor fornece eventos, treinamento e recursos da comunidade para ajudar desenvolvedores, empreendedores e startups a desenvolver a tecnologia de IA e muito mais. Junte-se a nós!

APRENDER, CONECTAR, CRIAR

Microsoft Reactor

Junte-se ao Microsoft Reactor e interaja com os desenvolvedores ao vivo

Pronto para começar a usar a IA e as tecnologias mais recentes? O Microsoft Reactor fornece eventos, treinamento e recursos da comunidade para ajudar desenvolvedores, empreendedores e startups a desenvolver a tecnologia de IA e muito mais. Junte-se a nós!

Voltar

The Quote-to-Cash Blind Spot: Secret Scanning for Enterprise Revenue Systems

9 setembro, 2026 | 5:00 PM - 6:00 PM (UTC) Tempo Universal Coordenado UTC

  • Formato:
  • alt##LivestreamTransmissão ao vivo

Tópico: Segurança

Linguagem: Inglês

Every CPQ, CLM, and billing rollout I've run wires Salesforce or Vlocity to DocuSign, Stripe or Zuora-type billing, and ERP through API keys and OAuth tokens sitting in DataRaptors, Integration Procedures, and deployment scripts. AppSec teams usually classify that layer as "business configuration," so it never gets scanned the way application code does.

Where credentials actually live in a quote-to-cash stack: middleware scripts, integration procedures, CI/CD for CPQ deployments. Why "business systems" teams don't think of themselves as a scanning target, and what that costs. How GitHub Advanced Security's secret scanning, push protection, and custom patterns close the gap, even for teams that don't see themselves as developers.

A sample repo modeling a CPQ integration script with a hardcoded OAuth token and API key. Push protection blocking a commit in real time. A custom regex pattern built for an enterprise revenue-tool token format. The alert triage view a security lead would actually work from.

  • DevSecOps
  • Security
  • GitHub Copilot
  • GitHub Advanced Security

Palestrantes

Já tem registro e precisa cancelar? Cancelar registro

Registro

Entre com sua conta Microsoft

Entrar

Ou insira seu endereço de email para se registrar

*

Ao se registrar para este evento, você concorda em cumprir o Código de conduta do Microsoft Reactor.

Partes desta página podem ser traduzidas por máquina ou IA.