Cloud Security Members Only

CI/CD Pipeline Attacks

CI/CD pipelines run with elevated permissions to deploy code, access secrets, and push artifacts — high-value attack targets. Covers GitHub Actions script injection and pull_request_target abuse, Jenkins Script Console RCE, secrets leaking in pipeline logs, third-party action supply chain risks, and the SLSA framework for build integrity.

Related Articles