Skip to content
GitHub Advanced Security

๊ฐœ๋ฐœ ์†๋„์— ๋ฐœ๋งž์ถฐ ์ง„ํ™”๋œ ๋ณด์•ˆ

๊ธฐ๋ฐ€ ์œ ์ถœ ๋ฏธ๋ฆฌ ์˜ˆ๋ฐฉ

Secret Protection ์‚ดํŽด ๋ณด๊ธฐ

์ฝ”๋“œ์˜ ์ทจ์•ฝ์„ฑ ํ•ด๊ฒฐ

Code Security ์‚ดํŽด๋ณด๊ธฐ

/security/advanced-security ๋กœ๊ณ 

3MCarlseberg GroupDatadogHashicorpKPMGLinkedInMercado LibreOtto GroupTelus

์œ„ํ—˜ ๊ด€๋ฆฌ์˜ ์„ ๊ตฌ์ž๊ฐ€ ๋˜๋‹ค

์ž์ฒด ๋ณด์•ˆ, ๊ธฐ๋ฐ€ ๋ณดํ˜ธ, ์˜์กด์„ฑ ๋ชจ๋‹ˆํ„ฐ๋ง์œผ๋กœ ์œ„ํ˜‘์„ ์˜ˆ๋ฐฉํ•˜์„ธ์š”.

Screenshot displaying a code snippet with an Express.js application setup and a CodeQL scan result indicating a high-severity reflected cross-site scripting vulnerability due to user-provided value. The GitHub Copilot Autofix feature is generating a fix suggestion.

GitHub Copilot Autofix์˜ AI ๊ธฐ๋ฐ˜ ์ธ์‚ฌ์ดํŠธ์™€ ์ž๋™ํ™”๋œ ์ˆ˜์ • ์ž‘์—…์œผ๋กœ ๋ณด์•ˆ ์ฝ”๋“œ๋ฅผ ๋Œ€๊ทœ๋ชจ๋กœ ์ž‘์„ฑํ•ฉ๋‹ˆ๋‹ค.

AI๋ฅผ ํ†ตํ•œ ๊ฐœ๋ฐœ ๊ฐ•ํ™”

Screenshot displaying a code snippet with a highlighted Copilot Autofix suggestion. The original code sends a response with user-provided query name directly, and the suggested fix escapes the user-provided query name to prevent cross-site scripting vulnerability.

์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ์„ GitHub์— ํ†ตํ•ฉํ•˜์—ฌ ์‹ค์‹œ๊ฐ„์œผ๋กœ ์ทจ์•ฝ์ ์„ ํ™•์ธํ•˜๊ณ  ํ•ด๊ฒฐํ•ฉ๋‹ˆ๋‹ค.

๊ธฐ๋ณธ AppSec์„ ํ™œ์šฉํ•˜์—ฌ ํŒ€ ์—ญ๋Ÿ‰ ์ฆ์ง„

Screenshot of a terminal output showing a git push command failure due to GitHub Push Protection detecting secrets. The error message 'error GH009: Secrets detected! This push failed.' is displayed, instructing the user to resolve the secrets before pushing again.
GitHub Advanced Security๋Š” ๊ธฐ๋ฐ€ ์œ ์ถœ์˜ ์œ„ํ—˜์„ ํ•ด๊ฒฐํ•ด์™”์Šต๋‹ˆ๋‹ค. ์ด์ œ ๊ฐœ๋ฐœ์ž๋“ค์€ ์ฝ”๋“œ๋ฅผ ์‹ค์ œ๋กœ ๋ฐฐํฌํ•˜๊ธฐ ์ „์— ๋ฌธ์ œ๋ฅผ ์ธ์ง€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ฆ‰๊ฐ์ ์ธ ํ”ผ๋“œ๋ฐฑ ๋ฃจํ”„๊ฐ€ ์žˆ๊ธฐ ๋•Œ๋ฌธ์ด์ฃ .
Florian Koch๋…์ผ ์ž์‚ฐ ๊ด€๋ฆฌ ์ปจ์„คํŒ…์‚ฌ(Deutsche Vermรถgensberatung)์˜ ์ˆ˜์„ ๊ฐœ๋ฐœ์ž

์ด์ค‘์œผ๋กœ ์•ˆ์ „ํ•œ ์™„๋ฒฝ ๋ณด์•ˆ

Secret Protection๊ณผ Code Security๋ฅผ ๊ฒฐํ•ฉํ•˜์—ฌ ์ฝ”๋“œ๋ฅผ ๋‹ค๊ฐ๋„๋กœ ์™„๋ฒฝํžˆ ๋ณดํ˜ธํ•ฉ๋‹ˆ๋‹ค.

์š”๊ธˆ์ œ ๋ฐ ์š”๊ธˆ ๋ณด๊ธฐ
์• ๋“œ์˜จ

GitHub Secret Protection

๊ธฐ๋ฐ€ ์œ ์ถœ์„ ๋ง‰๊ธฐ ์œ„ํ•ด ์ „๋…ํ•˜๋Š” ํŒ€๊ณผ ์กฐ์ง์„ ์œ„ํ•œ ์†”๋ฃจ์…˜์ž…๋‹ˆ๋‹ค.
$19USD
์›”๋ณ„ ํ™œ์„ฑ ์ปค๋ฏธํ„ฐ๋‹น
๋ฆฌํฌ์ง€ํ† ๋ฆฌ์—์„œ ์‚ฌ์šฉํ•  ์ค€๋น„๊ฐ€ ๋˜์…จ๋‚˜์š”?
์ง€๊ธˆ ์‹œ์ž‘ํ•˜๊ธฐ
์• ๋“œ์˜จ

GitHub Code Security

ํ”„๋กœ๋•์…˜ ์ „ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ์žก์•„๋‚ด๋Š” ์กฐ์ง๊ณผ ํŒ€์„ ์œ„ํ•œ ์†”๋ฃจ์…˜์ž…๋‹ˆ๋‹ค.
$30USD
์›”๋ณ„ ํ™œ์„ฑ ์ปค๋ฏธํ„ฐ๋‹น
๋ฆฌํฌ์ง€ํ† ๋ฆฌ์—์„œ ์‚ฌ์šฉํ•  ์ค€๋น„๊ฐ€ ๋˜์…จ๋‚˜์š”?
์ง€๊ธˆ ์‹œ์ž‘ํ•˜๊ธฐ

GitHub Advanced Security๋ฅผ ์ตœ๋Œ€ํ•œ ํ™œ์šฉํ•˜์„ธ์š”

๋ณด์•ˆ ์†”๋ฃจ์…˜์œผ๋กœ ์กฐ์ง์—์„œ ๋ฐ›์„ ์ˆ˜ ์žˆ๋Š” ์ด์ ์— ๋Œ€ํ•ด ์•Œ์•„ ๋ณด์„ธ์š”.

๋ฐ๋ชจ ์š”์ฒญ

์กฐ์ง์—์„œ ์†Œํ”„ํŠธ์›จ์–ด ๋ณด์•ˆ ๊ธฐ์ค€์„ ๊ฐœ์„ ํ•จ์œผ๋กœ์จ ์–ป๋Š” ์ด์ ์— ๋Œ€ํ•ด ์‚ดํŽด ๋ณด์„ธ์š”.

Forrester ๋ณด๊ณ ์„œ ์ฝ๊ธฐ

์—…๊ณ„ ์ „๋ฌธ๊ฐ€๋“ค์ด ์ƒ์‚ฐ์„ฑ์„ ์ €ํ•˜์‹œํ‚ค์ง€ ์•Š์œผ๋ฉด์„œ ์ฝ”๋“œ๋ฅผ ๋ณดํ˜ธํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ณด์„ธ์š”.

๋น„๋””์˜ค ์‚ดํŽด๋ณด๊ธฐ

์ž์ฃผ ๋ฌป๋Š” ์งˆ๋ฌธ

GitHub Advanced Security๋ž€ ๋ฌด์—‡์ธ๊ฐ€์š”?

GitHub Advanced Security(GHAS)์—๋Š” GitHub Secret Protection ๋ฐ GitHub Code Security ๋“ฑ์˜ GitHub ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ ์ œํ’ˆ์ด ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. GHAS๋Š” ๊ฐœ๋ฐœ์ž๊ฐ€ ์ด๋ฏธ ์•Œ๊ณ  ์žˆ๊ณ  ์ข‹์•„ํ•˜๋Š” GitHub ํ”Œ๋žซํผ์— ์ •์  ๋ถ„์„, ์†Œํ”„ํŠธ์›จ์–ด ๊ตฌ์„ฑ ๋ถ„์„(SCA) ๋ฐ secret ์Šค์บ”์„ ์œ„ํ•œ ์ตœ์ฒจ๋‹จ ๋„๊ตฌ๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. ๋„์ž…์„ ์ €ํ•ดํ•˜๋Š” ๋ณต์žกํ•œ ์›Œํฌํ”Œ๋กœ๋กœ ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœ ํˆด์ฒด์ธ์— ๋ถ€๋‹ด์„ ์ฃผ๋Š” ๊ธฐ์กด์˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ ํŒจํ‚ค์ง€์™€ ๋‹ฌ๋ฆฌ, GHAS๋Š” ๊ฐœ๋ฐœ์ž๊ฐ€ ๋ณด๋‹ค ์‰ฝ๊ณ  ๋น ๋ฅด๊ฒŒ ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœ ์ˆ˜๋ช… ์ฃผ๊ธฐ์—์„œ ์ทจ์•ฝ์„ฑ์„ ์ฐพ์•„ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ฉ๋‹ˆ๋‹ค.

์„œ๋“œ ํŒŒํ‹ฐ AppSec ์ œํ’ˆ ๋Œ€์‹  GitHub Advanced Security๋ฅผ ์„ ํƒํ•ด์•ผ ํ•˜๋Š” ์ด์œ ๋Š” ๋ฌด์—‡์ธ๊ฐ€์š”?

์„œ๋“œ ํŒŒํ‹ฐ์˜ ๋ณด์•ˆ ์ถ”๊ฐ€ ๊ธฐ๋Šฅ๊ณผ ๋‹ฌ๋ฆฌ, GitHub Advanced Security๋Š” ๊ฐœ๋ฐœ์ž๋“ค์ด ์ด๋ฏธ ์•Œ๊ณ  ์žˆ๊ณ  ์ข‹์•„ํ•˜๋Š” ๊ธฐ๋ณธ GitHub ์›Œํฌํ”Œ๋กœ ์ „์ฒด์—์„œ ์šด์˜๋ฉ๋‹ˆ๋‹ค. GitHub Advanced Security๋Š” ๊ฐœ๋ฐœ์ž๊ฐ€ ๋ณด๋‹ค ์‰ฝ๊ฒŒ ์ทจ์•ฝ์„ฑ์„ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜์—ฌ ๋ณด์•ˆ ํŒ€์ด ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ธฐ๋ฐ˜ ์ทจ์•ฝ์„ฑ์œผ๋กœ๋ถ€ํ„ฐ ๋น„์ฆˆ๋‹ˆ์Šค, ๊ณ ๊ฐ, ์ปค๋ฎค๋‹ˆํ‹ฐ๋ฅผ ๋ณดํ˜ธํ•  ์ˆ˜ ์žˆ๋Š” ์ค‘์š”ํ•œ ์ „๋žต์— ์ง‘์ค‘ํ•  ์‹œ๊ฐ„์„ ํ™•๋ณดํ•ด ์ค๋‹ˆ๋‹ค.

DevSecOps๋ž€ ๋ฌด์—‡์ธ๊ฐ€์š”?

DevSecOps๋Š” ์†Œํ”„ํŠธ์›จ์–ด ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ฐœ๋ฐœ์— ํ•„์š”ํ•œ ๊ฐœ๋ฐœ, ๋ณด์•ˆ, ์šด์˜ ๋„๊ตฌ์˜ ์กฐํ•ฉ์ž…๋‹ˆ๋‹ค.

AppSec์ด๋ž€ ๋ฌด์—‡์ธ๊ฐ€์š”?

์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ(AppSec)์€ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๋ณด์•ˆ ์ทจ์•ฝ์„ฑ์„ ๊ฒ€์ƒ‰, ์ˆ˜์ •, ์˜ˆ๋ฐฉํ•˜๋Š” ํ”„๋กœ์„ธ์Šค์ž…๋‹ˆ๋‹ค. GitHub Advanced Security์€ ์ฝ”๋“œ ์ž์ฒด์˜ ์ทจ์•ฝ์„ฑ์„ ํŒŒ์•…ํ•˜๋Š” ์ •์  ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ ํ…Œ์ŠคํŠธ(SAST)๋ฅผ ์œ„ํ•œ AppSec ํˆด์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

Microsoft Azure DevOps์™€ GitHub Advanced Security๋ฅผ ํ•จ๊ป˜ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‚˜์š”?

์˜ˆ. GitHub Advanced Security๋Š” Azure DevOps์˜ ์ถ”๊ฐ€ ๊ธฐ๋Šฅ์œผ๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์‚ฌ๋ก€ ์—ฐ๊ตฌ ๋ฐ ๊ณ ๊ฐ ์ž๋ฃŒ๋ฅผ ์–ด๋””์—์„œ ์ œ๊ณตํ•˜๋‚˜์š”?

๊ณ ๊ฐ ์‚ฌ๋ก€๋ฅผ ์ฝ๊ณ  Telus, Mercado Libre, KPMG ๋“ฑ์˜ ๊ณ ๊ฐ์ด GitHub Advanced Security๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๋ณดํ˜ธํ•˜๊ณ  ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœ ์ˆ˜๋ช… ์ฃผ๊ธฐ๋ฅผ ๊ฐ€์†ํ™”ํ•œ ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ณด์„ธ์š”.

๊ตฌ์ž… ์ „์— ์„ค๋ช…์„œ๋ฅผ ๊ฒ€ํ† ํ•ด ๋ณผ ์ˆ˜ ์žˆ์„๊นŒ์š”?

์˜ˆ. ๋ชจ๋“  GitHub ์ œํ’ˆ๊ณผ ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ GitHub Advanced Security์˜ ์„ค๋ช…์„œ๋„ ๊ณต๊ฐœํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

GitHub๋Š” ์ปจ์„คํŒ…, ๊ต์œก, ๊ธฐํƒ€ ๋ฐฐํฌ ์„œ๋น„์Šค๋ฅผ ์ œ๊ณตํ•˜๋‚˜์š”?

์˜ˆ! Expert Service ์†Œ๊ฐœ ํŽ˜์ด์ง€์—์„œ ๋” ์ž์„ธํžˆ ์•Œ์•„๋ณด์„ธ์š”.