cos · @cos
284 followers · 2135 posts · Server fosstodon.org

If a random person gives you source code and asks to debian package it, is there any proper way to install it's Build-Depends with apt beforehand?

I've only found some shady scripts that extract the field. What would be the proper debian way to do it?

#debian #packaging #continousintegration

Last updated 2 years ago

quote from pentest report (asked if this is ok):

:ablobcatpopcorn:โ€‹ (great work, sadly NDA'ed)

"We bypassed the internal SSH Zero Trust Gateway because its service account was setup to fully trust the [...] Continuous Integration. Due to the chosen Zero Trust gateway this compromise was undetectable, because there are no logon events on the target Linux systems being recorded [... This had been disabled by the admins because there was no log investigation procedure for this.]"

seems to have basic requirements. No basics, and Zero Trust becomes Blind Trust.

I am interested in what others do with automation / and Zero Trust. Obviously the login secrets have to be stored in CI. And no one will ever check these CI logon logs, because these are too many.

Architecturally this is a challenge.

#zerotrust #continousintegration

Last updated 3 years ago

ErikP · @erikp
24 followers · 128 posts · Server social.anoxinon.de

I wrote a Gitlab CI pipeline to build, test and deploy my app - here are
3 things I learnt about CI

- reusing jobs with "extends"
- integration
- speeding up the cache

on-sw-integration.epischel.de/

#gitlab #junit #cicd #continousintegration #continousdelivery

Last updated 3 years ago

Marc · @marceden
1 followers · 2 posts · Server ruhr.social
openSUSE Linux · @opensuse
3457 followers · 1325 posts · Server fosstodon.org