{"id":371,"date":"2026-05-11T10:15:47","date_gmt":"2026-05-11T08:15:47","guid":{"rendered":"https:\/\/leblogtech.romain-s.fr\/?page_id=371"},"modified":"2026-05-11T10:15:47","modified_gmt":"2026-05-11T08:15:47","slug":"sae61-la-securite-de-la-supply-chain-logicielle","status":"publish","type":"page","link":"https:\/\/leblogtech.romain-s.fr\/index.php\/sae61-la-securite-de-la-supply-chain-logicielle\/","title":{"rendered":"SAE61 &#8211; La S\u00e9curit\u00e9 de la Supply Chain Logicielle\u00a0"},"content":{"rendered":"\n<div class=\"wp-block-uagb-container uagb-block-cb809602 alignfull uagb-is-root-container\"><div class=\"uagb-container-inner-blocks-wrap\">\n<div class=\"wp-block-uagb-advanced-heading uagb-block-6f641674\"><h2 class=\"uagb-heading-text\">Pr\u00e9sentation <\/h2><\/div>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Le document traite de la menace croissante que repr\u00e9sentent les attaques par empoisonnement de la cha\u00eene d&rsquo;approvisionnement (<em>Supply Chain Attacks<\/em>). Plut\u00f4t que de cibler une application finale, ces offensives visent les maillons amont, tels que les outils d&rsquo;automatisation (Jenkins, GitLab CI) et les d\u00e9pendances logicielles, pour y injecter du code malveillant.<\/p>\n\n\n\n<div class=\"wp-block-uagb-advanced-heading uagb-block-b056d7b8\"><h2 class=\"uagb-heading-text\">Objectifs du document<\/h2><\/div>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\" id=\"p-rc_5180887b85502b50-28\">Ce travail documente une s\u00e9rie d&rsquo;audits et d&rsquo;exercices de s\u00e9curit\u00e9 offensive men\u00e9s au sein du laboratoire <strong>CI\/CD Goat<\/strong>, un environnement d\u00e9lib\u00e9r\u00e9ment vuln\u00e9rable con\u00e7u pour illustrer les risques du <strong>Top 10 de l&rsquo;OWASP<\/strong> pour les cha\u00eenes CI\/CD<sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup>. Le rapport vise trois objectifs principaux :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-medium-font-size\"><strong>Identification et exploitation<\/strong> de vecteurs d&rsquo;attaque critiques tels que le mouvement lat\u00e9ral, l&#8217;empoisonnement de d\u00e9pendances et l&rsquo;exfiltration de secrets.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>Analyse des d\u00e9faillances de configuration<\/strong> observ\u00e9es dans des outils de r\u00e9f\u00e9rence comme Jenkins, GitLab et Gitea.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>Proposition de strat\u00e9gies de rem\u00e9diation<\/strong> concr\u00e8tes bas\u00e9es sur les standards de l&rsquo;industrie pour transformer une infrastructure vuln\u00e9rable en une architecture r\u00e9siliente.<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-uagb-advanced-heading uagb-block-babde9e8\"><h2 class=\"uagb-heading-text\">Structure du rapport<\/h2><\/div>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Le document s&rsquo;articule autour de onze challenges pratiques (allant de <em>White Rabbit<\/em> \u00e0 <em>Gryphon<\/em>), d\u00e9taillant pour chaque faille le but de l&rsquo;attaque, la r\u00e9alisation technique de l&rsquo;exploit, et les moyens de rem\u00e9diation sp\u00e9cifiques \u00e0 mettre en \u0153uvre. Il fournit \u00e9galement un glossaire complet des termes techniques li\u00e9s \u00e0 la s\u00e9curit\u00e9 des pipelines et \u00e0 l&rsquo;Infrastructure as Code (IaC).<\/p>\n\n\n<div class=\"_df_book df-lite\" id=\"df_367\"  _slug=\"cr-sae61-la-securite-de-la-supply-chain-logicielle\" data-title=\"prive-cr-sae61-la-securite-de-la-supply-chain-logicielle\" wpoptions=\"true\" thumbtype=\"\" ><\/div><script class=\"df-shortcode-script\" nowprocket type=\"application\/javascript\">window.option_df_367 = {\"webgl\":\"false\",\"outline\":[],\"autoEnableOutline\":\"false\",\"autoEnableThumbnail\":\"false\",\"overwritePDFOutline\":\"false\",\"enableDownload\":\"false\",\"direction\":\"1\",\"pageSize\":\"0\",\"soundEnable\":\"false\",\"source\":\"https:\\\/\\\/leblogtech.romain-s.fr\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/CRSAE61.pdf\",\"wpOptions\":\"true\"}; if(window.DFLIP && window.DFLIP.parseBooks){window.DFLIP.parseBooks();}<\/script>\n<\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Pr\u00e9sentation Le document traite de la menace croissante que repr\u00e9sentent les attaques par empoisonnement de la cha\u00eene d&rsquo;approvisionnement (Supply Chain [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"class_list":["post-371","page","type-page","status-publish","hentry"],"uagb_featured_image_src":{"full":false,"thumbnail":false,"medium":false,"medium_large":false,"large":false,"1536x1536":false,"2048x2048":false},"uagb_author_info":{"display_name":"adminRO","author_link":"https:\/\/leblogtech.romain-s.fr\/index.php\/author\/adminro\/"},"uagb_comment_info":0,"uagb_excerpt":"Pr\u00e9sentation Le document traite de la menace croissante que repr\u00e9sentent les attaques par empoisonnement de la cha\u00eene d&rsquo;approvisionnement (Supply Chain [&hellip;]","_links":{"self":[{"href":"https:\/\/leblogtech.romain-s.fr\/index.php\/wp-json\/wp\/v2\/pages\/371","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/leblogtech.romain-s.fr\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/leblogtech.romain-s.fr\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/leblogtech.romain-s.fr\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/leblogtech.romain-s.fr\/index.php\/wp-json\/wp\/v2\/comments?post=371"}],"version-history":[{"count":3,"href":"https:\/\/leblogtech.romain-s.fr\/index.php\/wp-json\/wp\/v2\/pages\/371\/revisions"}],"predecessor-version":[{"id":374,"href":"https:\/\/leblogtech.romain-s.fr\/index.php\/wp-json\/wp\/v2\/pages\/371\/revisions\/374"}],"wp:attachment":[{"href":"https:\/\/leblogtech.romain-s.fr\/index.php\/wp-json\/wp\/v2\/media?parent=371"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}