top of page
The CI/CD Pipeline Is the Attack Surface
Adding a SAST scanner to your CI/CD pipeline is not the same as securing it. Three documented incidents from the past 13 months — tj-actions, Trivy, and Axios — show how the pipeline execution layer, dependency installation, and runner credentials are all being targeted at scale. Episode 9 builds the threat model your shift-left programme is missing.
Christopher Clarkson
Apr 712 min read
bottom of page
