Hoppa till huvudinnehåll
Megafonikon

Bygg molnbaserade inbyggda appar

Redo för AI? Upptäck hur du bygger och skalar molnbaserade appar med Azure.

LEARN, CONNECT, BUILD

Microsoft Reactor

Gå med i Microsoft Reactor och interagera med utvecklare live

Är du redo att komma igång med AI och de senaste teknikerna? Microsoft Reactor tillhandahåller evenemang, utbildning och communityresurser som hjälper utvecklare, entreprenörer och nystartade företag att bygga vidare på AI-teknik med mera. Följ med!

LEARN, CONNECT, BUILD

Microsoft Reactor

Gå med i Microsoft Reactor och interagera med utvecklare live

Är du redo att komma igång med AI och de senaste teknikerna? Microsoft Reactor tillhandahåller evenemang, utbildning och communityresurser som hjälper utvecklare, entreprenörer och nystartade företag att bygga vidare på AI-teknik med mera. Följ med!

Gå tillbaka

The Quote-to-Cash Blind Spot: Secret Scanning for Enterprise Revenue Systems

9 september, 2026 | 5:00 em - 6:00 em (UTC) Koordinerad universell tid

  • Format:
  • alt##LivestreamLivestream

Område: Säkerhet

Språk: Engelska

Every CPQ, CLM, and billing rollout I've run wires Salesforce or Vlocity to DocuSign, Stripe or Zuora-type billing, and ERP through API keys and OAuth tokens sitting in DataRaptors, Integration Procedures, and deployment scripts. AppSec teams usually classify that layer as "business configuration," so it never gets scanned the way application code does.

Where credentials actually live in a quote-to-cash stack: middleware scripts, integration procedures, CI/CD for CPQ deployments. Why "business systems" teams don't think of themselves as a scanning target, and what that costs. How GitHub Advanced Security's secret scanning, push protection, and custom patterns close the gap, even for teams that don't see themselves as developers.

A sample repo modeling a CPQ integration script with a hardcoded OAuth token and API key. Push protection blocking a commit in real time. A custom regex pattern built for an enterprise revenue-tool token format. The alert triage view a security lead would actually work from.

  • DevSecOps
  • Security
  • GitHub Copilot
  • GitHub Advanced Security

Talare

Har du redan registrerat dig och behöver avbryta? Avbryt registreringen

Registrering

Logga in med ditt Microsoft-konto

Logga in

Eller ange din e-postadress för att registrera dig

*

Genom att registrera dig för denna händelse samtycker du till att följa Microsoft Reactor Code of Conduct.

Delar av denna sida kan vara maskin- eller AI-översatta.