CI/CD security
The CI/CD pipeline has access to the code, the deployment secrets, and production: compromising it is compromising everything it builds and deploys. SolarWinds showed that attacking the build is more profitable than attacking an endpoint. This card covers how to secure the software supply chain.
Why CI/CD is a target
Section titled “Why CI/CD is a target”- access to CODE + SECRETS + the ability to DEPLOY to production- compromising the build = injecting into ALL artifacts (SolarWinds)- surface: runners, plugins, pipeline dependencies, tokens, webhooksThreats (and mitigations)
Section titled “Threats (and mitigations)”Poisoned pipeline execution (PPE) inject into the build via a malicious PR/config -> isolate runners, review pipeline changes, don't run untrusted PRs with secretsCI secret theft overly-scoped tokens -> OIDC (no long-lived secrets), least privilege, ephemeral secrets (dso-secrets)Pipeline dependencies compromised third-party actions/plugins -> pin by HASH (not mutable tags), action allowlistRunner/agent compromise shared or persistent runner -> ephemeral, per-job isolated runnersRepository protection
Section titled “Repository protection”- branch protection: mandatory review, no direct push to main, status checks- commit signing (GPG/Sigstore) and verification- CODEOWNERS for sensitive paths (pipeline, infra)- mandatory 2FA/MFA and least privilege on the platform (GitHub/GitLab)Artifact integrity (supply chain)
Section titled “Artifact integrity (supply chain)”SLSA framework of supply-chain integrity levelsSigning Sigstore/cosign: sign artifacts and images -> verify at deployProvenance attestation of HOW and WHERE the artifact was builtAdmission the cluster only admits signed/verified images (dso-k8ssec)Security gates in the pipeline
Section titled “Security gates in the pipeline”- SAST (dso-sast), SCA+SBOM (dso-deps), secrets (dso-secrets), IaC scan (dso-iac)- fail the build on critical findings; results in the PR- container image scanning before publishing (dso-containers)Blue Team / AppSec
Section titled “Blue Team / AppSec”- Treat the pipeline as production: least privilege, ephemeral runners, OIDC/ephemeral secrets.
- Pin actions/plugins by hash and apply branch protection + commit signing.
- Sign and verify artifacts (Sigstore/SLSA) and admit only verified images.
- Integrate all gates (SAST/SCA/secrets/IaC/image) and protect platform access.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- SolarWinds (2020): injection into the build process → backdoor distributed to 18,000 customers.
- Codecov (2021): a compromised CI script leaked customer secrets.
- tj-actions/changed-files and other GitHub Actions incidents via mutable tags → pin by hash.
Testing checklist
Section titled “Testing checklist”- Branch protection, mandatory review, commit signing
- OIDC/ephemeral secrets, least privilege, no long-lived ones
- Actions/plugins pinned by hash + allowlist
- Ephemeral, isolated runners; untrusted PRs without secrets
- SAST/SCA/secrets/IaC/image gates in the pipeline
- Artifact signing and verification (Sigstore/SLSA)
- Admit only signed images (Kubernetes hardening)