CI/CD Security · Learn

Learn: CI/CD and Supply Chain Security

How build pipelines, source control, and package registries get turned into an attack path. Pipelines run untrusted code with powerful credentials, so one poisoned build can reach production.

CI/CD Security · LearnAll services Download PDF
TL;DR

How build pipelines, source control, and package registries get turned into an attack path. Pipelines run untrusted code with powerful credentials, so one poisoned build can reach production.

By John Dill, Red Team Lead, SecureLayer7Updated

Topics

How build pipelines, source control, and package registries get turned into an attack path. Pipelines run untrusted code with powerful credentials, so one poisoned build can reach production.

References

  1. [1]OWASP Top 10 CI/CD Security Risks(OWASP)
Related terms

Find the CI/CD and supply-chain risks before an attacker does.

Scope an engagement

Find the CI/CD and supply-chain risks before an attacker does.

We test for these techniques and many others, and ship findings with a reproducible attack, the trust boundary that failed, and a fix a defender can implement.