Skip to content

CI/CD security

The CI/CD pipeline has access to the code, the deployment secrets, and production: compromising it is compromising everything it builds and deploys. SolarWinds showed that attacking the build is more profitable than attacking an endpoint. This card covers how to secure the software supply chain.

- access to CODE + SECRETS + the ability to DEPLOY to production
- compromising the build = injecting into ALL artifacts (SolarWinds)
- surface: runners, plugins, pipeline dependencies, tokens, webhooks
Poisoned pipeline execution (PPE) inject into the build via a malicious PR/config
-> isolate runners, review pipeline changes, don't run untrusted PRs with secrets
CI secret theft overly-scoped tokens
-> OIDC (no long-lived secrets), least privilege, ephemeral secrets (dso-secrets)
Pipeline dependencies compromised third-party actions/plugins
-> pin by HASH (not mutable tags), action allowlist
Runner/agent compromise shared or persistent runner
-> ephemeral, per-job isolated runners
- branch protection: mandatory review, no direct push to main, status checks
- commit signing (GPG/Sigstore) and verification
- CODEOWNERS for sensitive paths (pipeline, infra)
- mandatory 2FA/MFA and least privilege on the platform (GitHub/GitLab)
SLSA framework of supply-chain integrity levels
Signing Sigstore/cosign: sign artifacts and images -> verify at deploy
Provenance attestation of HOW and WHERE the artifact was built
Admission the cluster only admits signed/verified images (dso-k8ssec)
- SAST (dso-sast), SCA+SBOM (dso-deps), secrets (dso-secrets), IaC scan (dso-iac)
- fail the build on critical findings; results in the PR
- container image scanning before publishing (dso-containers)
  • Treat the pipeline as production: least privilege, ephemeral runners, OIDC/ephemeral secrets.
  • Pin actions/plugins by hash and apply branch protection + commit signing.
  • Sign and verify artifacts (Sigstore/SLSA) and admit only verified images.
  • Integrate all gates (SAST/SCA/secrets/IaC/image) and protect platform access.
  • SolarWinds (2020): injection into the build process → backdoor distributed to 18,000 customers.
  • Codecov (2021): a compromised CI script leaked customer secrets.
  • tj-actions/changed-files and other GitHub Actions incidents via mutable tags → pin by hash.
  • Branch protection, mandatory review, commit signing
  • OIDC/ephemeral secrets, least privilege, no long-lived ones
  • Actions/plugins pinned by hash + allowlist
  • Ephemeral, isolated runners; untrusted PRs without secrets
  • SAST/SCA/secrets/IaC/image gates in the pipeline
  • Artifact signing and verification (Sigstore/SLSA)
  • Admit only signed images (Kubernetes hardening)