跳到主要內容
擴音器圖示

打造雲端原生應用程式

準備好迎接 AI 了嗎? 探索如何利用 Azure 建構並擴展雲端原生應用程式。

學習、聯繫、建置

Microsoft Reactor

加入 Microsoft Reactor 並與開發人員即時互動

準備好開始使用 AI 和最新技術嗎? Microsoft Reactor 提供活動、訓練和社群資源,協助開發人員、企業家和初創公司建置 AI 技術等等。 加入我們!

學習、聯繫、建置

Microsoft Reactor

加入 Microsoft Reactor 並與開發人員即時互動

準備好開始使用 AI 和最新技術嗎? Microsoft Reactor 提供活動、訓練和社群資源,協助開發人員、企業家和初創公司建置 AI 技術等等。 加入我們!

返回

The Quote-to-Cash Blind Spot: Secret Scanning for Enterprise Revenue Systems

9 9月, 2026 | 5:00 下午 - 6:00 下午 (UTC) 國際標準時間

  • 格式:
  • alt##Livestream線上直播

主題: 安全性

語言: 英文

Every CPQ, CLM, and billing rollout I've run wires Salesforce or Vlocity to DocuSign, Stripe or Zuora-type billing, and ERP through API keys and OAuth tokens sitting in DataRaptors, Integration Procedures, and deployment scripts. AppSec teams usually classify that layer as "business configuration," so it never gets scanned the way application code does.

Where credentials actually live in a quote-to-cash stack: middleware scripts, integration procedures, CI/CD for CPQ deployments. Why "business systems" teams don't think of themselves as a scanning target, and what that costs. How GitHub Advanced Security's secret scanning, push protection, and custom patterns close the gap, even for teams that don't see themselves as developers.

A sample repo modeling a CPQ integration script with a hardcoded OAuth token and API key. Push protection blocking a commit in real time. A custom regex pattern built for an enterprise revenue-tool token format. The alert triage view a security lead would actually work from.

  • DevSecOps
  • Security
  • GitHub Copilot
  • GitHub Advanced Security

演講者

已經註冊,需要取消嗎? 取消註冊

註冊

使用您的 Microsoft 帳戶登入。

登入

或輸入您的電子郵件地址以註冊

*

註冊這個活動,即表示您同意遵守 Microsoft Reactor 管理辦法.

本頁面的一部分可能是機器翻譯或人工智能翻譯的.