ci-cd
Safeguard articles tagged "ci-cd" — guides, analysis, and best practices for software supply chain and application security.
100 articles
One Shared Deploy Credential Is Forty Pipelines' Worth of Blast Radius
Set up once, when there was one service. Forty pipelines later, every one of them still uses it, and it can deploy to production, which means it can read the secrets and infrastructure of everything it touches.
CI Secret Masking Matches the Exact String, and Almost Nothing Else
Encode it, uppercase it, split it across two log lines, and masking has nothing to match against. This is not a bug in any platform. It is the only mechanism possible without semantic analysis of every command a pipeline runs.
Your Staging Environment Is on the Internet and Nobody Chose That
Less hardening, unfinished code, no monitoring, real credentials, and often production's network reachability. An attacker choosing between your two environments will frequently prefer this one.
Auto-Merging Updates Fast and Reviewing What You Take Are in Conflict
Patch quickly, because exploitation begins within days. Review what you take from third parties, because a malicious version of a package you trust is the most effective supply chain attack. Auto-merge picks one and abandons the other.
A Self-Hosted Runner Is a Machine on Your Network That Runs Strangers' Code
A hosted runner is destroyed after the job. A self-hosted one persists, on your network, executing code from your repository, and if that repository accepts contributions the code is not always yours.
The Service Template Is the Highest-Leverage Control You Will Build
One security engineer cannot review every service a hundred developers write. What works is deciding things once, in a scaffold, so every service created afterwards starts with those decisions already made.
A Lockfile Is Not a Control, the Install Command Is
You pinned every dependency with an integrity hash and committed the file. None of that means the artifact you shipped contains those versions, because several install commands are allowed to resolve differently and rewrite the lockfile.
Your Pull Request Process Is Already Your Change Management
An auditor asks for change management evidence and the instinct is to build a change request form nobody will use. You already have the control, and it produces better evidence because it is generated by the work rather than alongside it.
A Clean Scan Usually Means the Scanner Did Not Look
Analysed your code and found nothing, or failed to analyse your code and therefore found nothing. Most tools report both as success. Seven reasons coverage collapses, and the canary dependency that proves a scan still works.
Your CI Job Is Not Hung, It Is Slower Than Your Timeout
A timeout kills a process and loses its buffered output, so a suite that needed eleven minutes looks exactly like a deadlock. How to tell them apart, the defaults that catch people, and why a killed scan must never count as a pass.
The Dockerfile in Your Repository Is Probably Not What Builds
An urgent fix gets made on the build host, the backport never happens, and the repository copy becomes a historical document. Absent files prompt questions; stale ones answer them wrongly.
A Container Stuck on health: starting Is Probably a Crash Loop
Each restart resets the health check, so a crash loop and a slow boot look identical in the status column. The one command that tells them apart, and the merge conflict class that produces the most convincing version.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.