{"title":"软件管理平台自动化工作流中权限生命周期的初步研究","authors":"Giacomo Benedetti, Luca Verderame, A. Merlo","doi":"10.1109/EuroSPW59978.2023.00007","DOIUrl":null,"url":null,"abstract":"This paper focuses on the role of privileges in automation workflows within modern software development practices, which heavily rely on DevOps principles. Automation workflows, which are sets of automated software management processes, have become essential to software development and are integrated into software management platforms such as GitHub, GitLab, and BitBucket. However, privileges are crucial in ensuring the security and integrity of the software development process. This paper aims to identify the phases in which privileges are involved in automation workflows and analyze how these platforms handle the privilege life cycle in automation workflows to provide a better understanding of their security implications. The security discussion highlighted in this analysis aims to stimulate solutions and further research.","PeriodicalId":220415,"journal":{"name":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","volume":"44 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"A Preliminary Study of Privilege Life Cycle in Software Management Platform Automation Workflows\",\"authors\":\"Giacomo Benedetti, Luca Verderame, A. Merlo\",\"doi\":\"10.1109/EuroSPW59978.2023.00007\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper focuses on the role of privileges in automation workflows within modern software development practices, which heavily rely on DevOps principles. Automation workflows, which are sets of automated software management processes, have become essential to software development and are integrated into software management platforms such as GitHub, GitLab, and BitBucket. However, privileges are crucial in ensuring the security and integrity of the software development process. This paper aims to identify the phases in which privileges are involved in automation workflows and analyze how these platforms handle the privilege life cycle in automation workflows to provide a better understanding of their security implications. The security discussion highlighted in this analysis aims to stimulate solutions and further research.\",\"PeriodicalId\":220415,\"journal\":{\"name\":\"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)\",\"volume\":\"44 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-07-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/EuroSPW59978.2023.00007\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EuroSPW59978.2023.00007","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
A Preliminary Study of Privilege Life Cycle in Software Management Platform Automation Workflows
This paper focuses on the role of privileges in automation workflows within modern software development practices, which heavily rely on DevOps principles. Automation workflows, which are sets of automated software management processes, have become essential to software development and are integrated into software management platforms such as GitHub, GitLab, and BitBucket. However, privileges are crucial in ensuring the security and integrity of the software development process. This paper aims to identify the phases in which privileges are involved in automation workflows and analyze how these platforms handle the privilege life cycle in automation workflows to provide a better understanding of their security implications. The security discussion highlighted in this analysis aims to stimulate solutions and further research.