ci-cd-security
Safeguard articles tagged "ci-cd-security" — guides, analysis, and best practices for software supply chain and application security.
100 articles
Where to Put the Security Gate So It Does Not Stop the Line
Most badly behaved security gates are correctly configured checks in the wrong position. The four places a check can run, what each can afford, and the rollout sequence that keeps a gate alive.
How a GitHub Actions Flaw Turned a 61-Million-Download Python Package Into a Cryptominer Delivery Vector
The Ultralytics YOLO compromise in December 2024 didn't touch a single line of reviewed code. It exploited the CI/CD pipeline that builds and publishes the package instead.
Two Supply Chain Compromises, Two Different Failure Modes: TanStack npm and ASUS Live Update
A live npm registry attack against TanStack's trusted GitHub Actions publishing pipeline and a years-old ASUS Live Update client backdoor show two distinct ways software trust gets weaponized.
A CVSS 10.0 That Only Reads Files: GitLab CVE-2026-85706
An unauthenticated attacker reads arbitrary files from a GitLab server. There is no code execution, and it still scores 10.0 — because on a source host a read primitive is a credential incident.
CVE-2026-63077: Your Build Server Is a Credential Store With an Open Port
An unauthenticated attacker sends a crafted object to TeamCity's agent polling endpoint and gets OS command execution as the server process. Every credential the build server holds sits downstream.
npm Classic Tokens Are Gone. The keyv Worm Shows Why That Mattered.
Every npm classic token has been permanently revoked — unrecoverable, unrecreatable. Teams treated it as a chore. Then a worm propagated across 444 packages on exactly that kind of credential.
Bring Your Own Runtime: Why the keyv Payload Downloaded Bun
The August 2026 npm worm did not run its second stage in Node. It downloaded a standalone Bun binary first — a choice that defeats a surprising amount of build-pipeline monitoring.
npm 12 Turned Install Scripts Off. The keyv Worm Used a preinstall Hook Anyway.
Install scripts have been off by default since npm 12 shipped in July 2026. Four weeks later a worm propagated through preinstall hooks. A default is not a control until you prove it is enforced.
npm CLI Login in CI: Tokens, npm-cli-login, and Safer Patterns
The npm-cli-login package automated interactive npm login for CI pipelines — a pattern that npm's 2025 authentication overhaul has made both broken and unnecessary. Here is what to use instead.
CI/CD pipeline supply chain attacks explained
A breakdown of how CI/CD supply chain attacks work, from SolarWinds to the 2025 tj-actions/changed-files breach, and how to detect and stop them.
Argument injection vulnerabilities explained
How argument injection (CWE-88) vulnerabilities work, real CVEs like PHPMailer and Git ssh URLs, and how teams detect and prevent CWE-88 flaws.
The tj-actions/changed-files GitHub Action Supply Chain C...
CVE-2025-30066 exposed how a compromised tj-actions/changed-files GitHub Action leaked CI/CD secrets into build logs across 23,000+ repos. Timeline, impact, and fixes.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.