CI/CD pipeline su kritični za sigurnost — imaju pristup izvornom kodu, kredencijalima i produkcijskom primjeni. Kompromitiran pipeline može biti katastrofalan (napadi na lanac opskrbe). Osiguranje pipeline-a uključuje zaštitu tajni, samog pipeline-a, ovisnosti i proizvedenih artefakata.
Zašto je sigurnost pipeline-a kritična
Pipelines are a HIGH-VALUE TARGET — they have powerful access:
→ SOURCE CODE, deployment CREDENTIALS, production ACCESS, secrets
→ a compromised pipeline can inject malicious code into your software (SUPPLY CHAIN
ATTACK — affecting all your users) or steal credentials/deploy malicious versions
→ Real, serious attacks (SolarWinds, etc.) targeted build/CI systems.
