Establishing Workload Identity for Zero Trust CI/CD: From Secrets to SPIFFE-Based Authentication
Fuente:
arXiv
Gespeichert in:
| 1. Verfasser: | Avirneni, Surya Teja |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2025
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
Intent-Aware Authorization for Zero Trust CI/CD
von: Avirneni, Surya Teja
Veröffentlicht: (2025)
von: Avirneni, Surya Teja
Veröffentlicht: (2025)
Decoupling Identity from Access: Credential Broker Patterns for Secure CI/CD
von: Avirneni, Surya Teja
Veröffentlicht: (2025)
von: Avirneni, Surya Teja
Veröffentlicht: (2025)
Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure
von: Avirneni, Surya Teja
Veröffentlicht: (2025)
von: Avirneni, Surya Teja
Veröffentlicht: (2025)
Lockbox -- A Zero Trust Architecture for Secure Processing of Sensitive Cloud Workloads
von: Thotempudi, Vamshi Krishna, et al.
Veröffentlicht: (2026)
von: Thotempudi, Vamshi Krishna, et al.
Veröffentlicht: (2026)
A Faceted Classification of Authenticator-Centric Authentication Techniques
von: Mattukat, Alex R., et al.
Veröffentlicht: (2026)
von: Mattukat, Alex R., et al.
Veröffentlicht: (2026)
A Requirement-Based Framework for Engineering Adaptive Authentication
von: Hassan, Alzubair, et al.
Veröffentlicht: (2026)
von: Hassan, Alzubair, et al.
Veröffentlicht: (2026)
The Secret Life of CVEs
von: Przymus, Piotr, et al.
Veröffentlicht: (2025)
von: Przymus, Piotr, et al.
Veröffentlicht: (2025)
Automated Generation of Accurate Privacy Captions From Android Source Code Using Large Language Models
von: Jain, Vijayanta, et al.
Veröffentlicht: (2026)
von: Jain, Vijayanta, et al.
Veröffentlicht: (2026)
Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
von: Ruan, Bonan, et al.
Veröffentlicht: (2026)
von: Ruan, Bonan, et al.
Veröffentlicht: (2026)
LLMs for Cyber Security: New Opportunities
von: Divakaran, Dinil Mon, et al.
Veröffentlicht: (2024)
von: Divakaran, Dinil Mon, et al.
Veröffentlicht: (2024)
A Longitudinal Study of Usability in Identity-Based Software Signing
von: Kalu, Kelechi G., et al.
Veröffentlicht: (2026)
von: Kalu, Kelechi G., et al.
Veröffentlicht: (2026)
Evaluating Large Language Models in detecting Secrets in Android Apps
von: Alecci, Marco, et al.
Veröffentlicht: (2025)
von: Alecci, Marco, et al.
Veröffentlicht: (2025)
Decoding Secret Memorization in Code LLMs Through Token-Level Characterization
von: Nie, Yuqing, et al.
Veröffentlicht: (2024)
von: Nie, Yuqing, et al.
Veröffentlicht: (2024)
Automatically Detecting Checked-In Secrets in Android Apps: How Far Are We?
von: Li, Kevin, et al.
Veröffentlicht: (2024)
von: Li, Kevin, et al.
Veröffentlicht: (2024)
DiVerify: Hardening Identity-Based Software Signing with Diverse-Context Scopes
von: Okafor, Chinenye, et al.
Veröffentlicht: (2024)
von: Okafor, Chinenye, et al.
Veröffentlicht: (2024)
Automated Testing of Broken Authentication Vulnerabilities in Web APIs with AuthREST
von: Corradini, Davide, et al.
Veröffentlicht: (2025)
von: Corradini, Davide, et al.
Veröffentlicht: (2025)
What You Trust Is Insecure: Demystifying How Developers (Mis)Use Trusted Execution Environments in Practice
von: Niu, Yuqing, et al.
Veröffentlicht: (2025)
von: Niu, Yuqing, et al.
Veröffentlicht: (2025)
A Systematic Literature Review on Continuous Integration and Deployment (CI/CD) for Secure Cloud Computing
von: Saleh, Sabbir M., et al.
Veröffentlicht: (2025)
von: Saleh, Sabbir M., et al.
Veröffentlicht: (2025)
ZTaint-Havoc: From Havoc Mode to Zero-Execution Fuzzing-Driven Taint Inference
von: Xie, Yuchong, et al.
Veröffentlicht: (2025)
von: Xie, Yuchong, et al.
Veröffentlicht: (2025)
How Far are App Secrets from Being Stolen? A Case Study on Android
von: Wei, Lili, et al.
Veröffentlicht: (2025)
von: Wei, Lili, et al.
Veröffentlicht: (2025)
Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
von: Schorlemmer, Taylor R., et al.
Veröffentlicht: (2024)
von: Schorlemmer, Taylor R., et al.
Veröffentlicht: (2024)
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
von: Kalu, Kelechi G., et al.
Veröffentlicht: (2025)
von: Kalu, Kelechi G., et al.
Veröffentlicht: (2025)
The Data Enclave Advantage: A New Paradigm for Least-Privileged Data Access in a Zero-Trust World
von: Bistolfi, Nico, et al.
Veröffentlicht: (2025)
von: Bistolfi, Nico, et al.
Veröffentlicht: (2025)
RiskHarvester: A Risk-based Tool to Prioritize Secret Removal Efforts in Software Artifacts
von: Basak, Setu Kumar, et al.
Veröffentlicht: (2025)
von: Basak, Setu Kumar, et al.
Veröffentlicht: (2025)
IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
von: Rahman, Md Nafiu, et al.
Veröffentlicht: (2026)
von: Rahman, Md Nafiu, et al.
Veröffentlicht: (2026)
AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts
von: Basak, Setu Kumar, et al.
Veröffentlicht: (2024)
von: Basak, Setu Kumar, et al.
Veröffentlicht: (2024)
A Privacy-Preserving DAO Model Using NFT Authentication for the Punishment not Reward Blockchain Architecture
von: Bayan, Talgar, et al.
Veröffentlicht: (2024)
von: Bayan, Talgar, et al.
Veröffentlicht: (2024)
Towards Trust Proof for Secure Confidential Virtual Machines
von: Mao, Jingkai, et al.
Veröffentlicht: (2024)
von: Mao, Jingkai, et al.
Veröffentlicht: (2024)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
von: Okafor, Chinenye, et al.
Veröffentlicht: (2024)
von: Okafor, Chinenye, et al.
Veröffentlicht: (2024)
Toward Secure Web to ERP Payment Flows: A Case Study of HTTP Header Trust Failures in SAP Based Systems
von: Dini, Vick
Veröffentlicht: (2026)
von: Dini, Vick
Veröffentlicht: (2026)
Characterizing Trust Boundary Vulnerabilities in TEE Containers: An Empirical Study
von: Liu, Weijie, et al.
Veröffentlicht: (2025)
von: Liu, Weijie, et al.
Veröffentlicht: (2025)
FirmReBugger: A Benchmark Framework for Monolithic Firmware Fuzzers
von: Duong, Mathew, et al.
Veröffentlicht: (2026)
von: Duong, Mathew, et al.
Veröffentlicht: (2026)
Trusting code in the wild: Exploring contributor reputation measures to review dependencies in the Rust ecosystem
von: Hamer, Sivana, et al.
Veröffentlicht: (2024)
von: Hamer, Sivana, et al.
Veröffentlicht: (2024)
Zero-Permission Manipulation: Can We Trust Large Multimodal Model Powered GUI Agents?
von: Qian, Yi, et al.
Veröffentlicht: (2026)
von: Qian, Yi, et al.
Veröffentlicht: (2026)
When "Correct" Is Not Safe: Can We Trust Functionally Correct Patches Generated by Code Agents?
von: Peng, Yibo, et al.
Veröffentlicht: (2025)
von: Peng, Yibo, et al.
Veröffentlicht: (2025)
In Specs we Trust? Conformance-Analysis of Implementation to Specifications in Node-RED and Associated Security Risks
von: Schneider, Simon, et al.
Veröffentlicht: (2025)
von: Schneider, Simon, et al.
Veröffentlicht: (2025)
Enterprise Identity Integration for AI-Assisted Developer Services: Architecture, Implementation, and Case Study
von: Chinthareddy, Manideep Reddy
Veröffentlicht: (2026)
von: Chinthareddy, Manideep Reddy
Veröffentlicht: (2026)
Verifiable Provenance of Software Artifacts with Zero-Knowledge Compilation
von: Ron, Javier, et al.
Veröffentlicht: (2026)
von: Ron, Javier, et al.
Veröffentlicht: (2026)
Automating SBOM Generation with Zero-Shot Semantic Similarity
von: Pereira, Devin, et al.
Veröffentlicht: (2024)
von: Pereira, Devin, et al.
Veröffentlicht: (2024)
Engineering Trustworthy Machine-Learning Operations with Zero-Knowledge Proofs
von: Scaramuzza, Filippo, et al.
Veröffentlicht: (2025)
von: Scaramuzza, Filippo, et al.
Veröffentlicht: (2025)
Ähnliche Einträge
-
Intent-Aware Authorization for Zero Trust CI/CD
von: Avirneni, Surya Teja
Veröffentlicht: (2025) -
Decoupling Identity from Access: Credential Broker Patterns for Secure CI/CD
von: Avirneni, Surya Teja
Veröffentlicht: (2025) -
Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure
von: Avirneni, Surya Teja
Veröffentlicht: (2025) -
Lockbox -- A Zero Trust Architecture for Secure Processing of Sensitive Cloud Workloads
von: Thotempudi, Vamshi Krishna, et al.
Veröffentlicht: (2026) -
A Faceted Classification of Authenticator-Centric Authentication Techniques
von: Mattukat, Alex R., et al.
Veröffentlicht: (2026)