Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
個人開発でセキュリティを意識して見ようの会
Search
saitojo1106
July 05, 2026
450
3
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
個人開発でセキュリティを意識して見ようの会
saitojo1106
July 05, 2026
Featured
See All Featured
Embracing the Ebb and Flow
colly
88
5.2k
[RailsConf 2023] Rails as a piece of cake
palkan
59
7k
AI: The stuff that nobody shows you
jnunemaker
PRO
10
1.1k
技術選定の審美眼(2025年版) / Understanding the Spiral of Technologies 2025 edition
twada
PRO
120
120k
The Organizational Zoo: Understanding Human Behavior Agility Through Metaphoric Constructive Conversations (based on the works of Arthur Shelley, Ph.D)
kimpetersen
PRO
0
470
Have SEOs Ruined the Internet? - User Awareness of SEO in 2025
akashhashmi
0
500
Performance Is Good for Brains [We Love Speed 2024]
tammyeverts
12
1.9k
Designing Experiences People Love
moore
143
24k
The Spectacular Lies of Maps
axbom
PRO
1
1k
Abbi's Birthday
coloredviolet
4
10k
sira's awesome portfolio website redesign presentation
elsirapls
0
420
Raft: Consensus for Rubyists
vanstee
142
7.7k
Transcript
個人開発でセキュリティを意識してみ ようの会 (※今回は選定のみ )
自己紹介 齋藤 丈(@mukimuki_js) • とある企業で内定者インターン中 • 27卒・B4 • TS,Go,(Flutter) •
読書,筋トレ,勉強会 • デザインやセキュリティに興味あり ※セキュリティ専門家じゃ無いですw
今日持ち帰って欲しいこと • セキュリティツールの選定方法 • 開発におけるセキュリティ脅威 • 個人利用無料のセキュリティツール
背景 • 最近はかなり物騒になってきてい る ◦ ソフトウェアサプライチェーン攻撃 ◦ Actions侵害
個人的気になったきっかけ • GMO Flatt Security ◦ ツイート(米内CTO) ◦ ブログ ◦
Youtube 対応早すぎて神↓
ソフトウェアサプライチェーン攻撃とは pkg汚染 • OSSメンテナアカウント乗っ取りで悪性バージョンの公 開されnpm installしてしまうと認証情報なり色々盗ま れちゃう(axiosの例) GithubActions( ビルドやテスト、デプロイなどを行う基盤 )
• Actionsで使っているビルドパッケージなどの汚染によ り、それの利用者のコードをビルドなど実行中に secretsや様々なキーを窃取されてしまう
ソフトウェアサプライチェーンとは (※素人の理解です ) ユーザが開発で使っている外部サービス汚染 ↓ 汚染サービス実行/install ↓ 端末が遠隔操作、認証情報窃取 ↓ 会社情報抜き取られ、次のリポジトリ、ユーザに攻撃
って感じでチェーンのようにつながっていく攻撃
課題 • 開発においてOSSなど依存しまくりなはず ◦ 自分だとフロントエンド開発でaxios,tanstack query,React hook form,zod,Orval…… バックエンドだとogen,sqlc,マジでキリない… ◦
拡張機能もあるけどここだと割愛 • AI駆動開発(ソースはないです個人の意見多めかも) ◦ 勝手に色々pkgをinstallして依存を増やしていくが確認ができない/遅れる ◦ 今回は少し関係ないけど脆弱性のあるコードを書いたり、キー露出もある ◦ 開発速度が上がったが、レビューは誰が?ツールに頼りたくない?
目的:対策スコープ サプライチェーン攻撃に絞り、個人開発無料で使えるツール、サービスを調 べて選定していく、他にも自分でできる対策も調査する👀 ※選定基準は今回は自分のプロジェクトに絞っているので全部カバーはできないかもです 🙏 ※React,TypeScript,Go,GCP,あたりを使うことを想定してます 😭
サクッとできそうなものを調査してみる 参考資 料:https://speakerdeck.com/flatt_security/quick-actions-you-can-ta ke-today-against-software-supply-chain-attacks?slide=8
SaaS • Takumi Guard ◦ 悪性パッケージをインストール前にブロック (TS/JS,Go,Python,Ruby………) • Socket ◦
PRで依存追加変更のたびに分析してくれて、分析結果を 出してくれる ◦ 他にもvscode拡張、Firewall(Takumiと同じ)まであるそう (無料版はGo未対応)
(自分でできる設定 ) • レジストリ(pkgの倉庫)にクールダウン設定 ◦ 7日間が推奨らしい ◦ .npmrcに追記→ignore-scripts=trueとmin-release-age=7でマルウェア実行と公開直後のパッケージ回避 • pkgバージョン固定(.lockファイル)
• Githubのdependabotでのクールダウン設定もできる (CICDの保護)
実践する際 • 外部SaaS:Takumi Guardを使用 • 自分でできる設定 ◦ Githubのdependabot ◦ バージョン固定
◦ パッケージのクールダウン指定
参考資料 • https://speakerdeck.com/flatt_security/quick-actions-you-can-take-today-against-software-suppl y-chain-attacks • https://flatt.tech/takumi/features/guard • https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns • https://qiita.com/masato_makino/items/516ca6f8a8b497131602
•