CI/CD Security · Learn

Learn: CI/CD and Supply Chain Security

How build pipelines, source control, and package registries get turned into an attack path. Pipelines run untrusted code with powerful credentials, so one poisoned build can reach production.

CI/CD Security · LearnAll services Download PDF
TL;DR

How build pipelines, source control, and package registries get turned into an attack path. Pipelines run untrusted code with powerful credentials, so one poisoned build can reach production.

By John Dill, Red Team Lead, SecureLayer7Updated

Topics

How build pipelines, source control, and package registries get turned into an attack path. Pipelines run untrusted code with powerful credentials, so one poisoned build can reach production.

References

  1. [1]OWASP Top 10 CI/CD Security Risks(OWASP)
Related terms

Find the CI/CD and supply-chain risks before an attacker does.

Related service
Red Team Assessment
Goal-based adversary emulation across your people, apps, and network, the full path an attacker would take.
Red team assessment

Scope an engagement

Find the CI/CD and supply-chain risks before an attacker does.

We test for these techniques and many others, and ship findings with a reproducible attack, the trust boundary that failed, and a fix a defender can implement.