Why AI Coding Agents Leak Secrets in CI/CD (And How to Stop It)
カートのアイテムが多すぎます
カートに追加できませんでした。
ウィッシュリストに追加できませんでした。
ほしい物リストの削除に失敗しました。
ポッドキャストのフォローに失敗しました
ポッドキャストのフォロー解除に失敗しました
-
ナレーター:
-
著者:
Your developer didn't leak an API secret to GitHub. Their autonomous AI coding agent generated a mock key, filled in a real one, and opened a Pull Request.
This episode breaks down the growing security risk of AI coding agents in CI/CD pipelines: why agents hardcode real credentials into test configs, why PR code reviews happen too late to prevent git history contamination, and how to enforce pre-receive hooks and ephemeral identity controls.
If your pipeline relies on prompts to prevent secret leaks, your security boundary is imaginary.
Keywords: AI coding agents, secret scanning, CI/CD security, DevSecOps, git push protection, credential leaks, GitHub Copilot agents, application security, software supply chain, OIDC tokens
This is Maya. New episodes three times a week.
youtube.com/@mayabuildsai