Category: CI/CD Security

Privilege Escalation Vulnerability

Privilege Escalation Vulnerability in CI/CD pipelines

A privilege escalation vulnerability in CI/CD pipelines needs no exploit. How attackers abuse tokens, triggers, and containers, and how to close each path.
10 min read
inject environment variables to the build process

Inject Environment Variables to the Build Process Securely

Inject environment variables to the build process securely. Learn how to prevent leaks and protect secrets in CI/CD pipelines.
7 min read
ReDoS

ReDoS Explained: What Regular Expression DoS Is and How to Prevent It

ReDoS attacks can crash your apps. Discover how vulnerable regex patterns work and how to detect and prevent them with modern AppSec practices.
9 min read
slsa attestation - slsa framework - SLSA v1.2

SLSA v1.2 : Updates to the SLSA Framework Explained

A clear developer guide to SLSA v1.2 that explains the new requirements, the framework and how to use slsa attestation in your builds.
5 min read
MCP Security

MCP Security: Protecting the Model Context Protocol

Learn model context protocol and MCP security basics plus server security best practices for safer AI–DevOps.
6 min read
yagni - secure coding principles - clean code

YAGNI and Secure Code: Why “Not Yet” Can Save You From Bugs

Apply YAGNI and secure coding principles to keep clean code, reduce risk, and automate code hygiene in DevSecOps pipelines. Learn how!
access control list - access control lists - access control policy

Access Control List in CI/CD: The Hidden Risk Behind Simple Permissions

Discover the hidden risks of access control lists in CI/CD and how to enforce a secure access control policy in our post!
npm i -s - npm install --save - npm malicious packages

NPM i -s and the Hidden Risks in Your Dependencies

Learn how npm i -s and npm install --save can expose you to npm malicious packages and secure your dependencies.
git remote set-url - git set url for remote - git add remote

When Git remote set-url Becomes a Supply Chain Risk

Learn how Git remote set-url and git add remote can be abused in CI/CD pipelines & how to prevent supply chain attacks
infector virus - file infector virus - malware code

File Infector Virus in Code Repositories: What Devs Need to Watch For

Discover how an infector virus spreads through code repositories and how to detect and block hidden malware code in CI/CD pipelines.
jenkins security - security jenkins - jenkins security best practices

Jenkins Security FAQs: Everything You Need to Know

Learn how to apply jenkins security best practices, protect pipelines, and strengthen security jenkins workflows for reliable automation.
5 min read
attribute based access control - abac - abac vs rbac

Attribute-Based Access Control in CI/CD: Enforcing Policies Beyond Roles

Learn how attribute based access control secures CI/CD pipelines. Discover ABAC vs RBAC differences & why context-driven access wins.