Skip to content

Topic

CI/CD Pipeline Security

Securing build systems and their access to cloud accounts, including blast-radius containment for compromised or low-trust jobs.

Current stories

buildOne report1 publisher

A static denylist stopped one more prompt injection than no protection in a coding-agent study

Bouras, Dai and Mechtaev found a static denylist let 46 of 75 prompt injections execute in a coding agent, against 3 under preflight-scoped capabilities. A same-day Google report of malware stealing OIDC tokens from GitHub Actions runners puts the outer limit on an agent in the CI job's permissions.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50
productConfirmed3 publishers

GitLab's commits API returns server files to callers who never log in

GitLab's September 10 patch release closes CVE-2026-85706, a CVSS 10.0 path confinement failure in the repository commits API. GitLab.com was already patched, so the exposure sits with self-managed servers.

Publishers:dev.todevops.cominfoq.com

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 62%
Investor
Investor 5%

Reality

Evidence72
Adoption
Insufficient
Hype gap+5
Incentives30
Confidence70
buildOne report1 publisher

Go 1.27 executes a poisoned dependency at go test in a replay of npm's August 4 worm

Go 1.27 ran none of a poisoned module's code on go get, go build or go vet in a replay of npm's August 4 worm, but go test ran it with GITHUB_TOKEN in reach. Go teams still carry exposure through CI test runs, versions that stay cached for good, and bots that edit go.mod.

Publishers:dev.to

Reality

Evidence50
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence55
securityConfirmed2 publishers

Two actions-cool GitHub Actions resumed running the Mini Shai-Hulud stealer after coming back online

Two actions-cool GitHub Actions hijacked on May 18 came back online on September 16, still serving the Mini Shai-Hulud stealer to tag-pinned workflows. Only workflows pinned to a pre-May 18 commit SHA escaped; the rest have CI secrets to rotate.

Perspective Coverage

3 publishers
Builder
Builder 43%
Operator
Operator 47%
Investor
Investor 10%

Reality

Evidence60
Adoption40
Hype gap+15
Incentives30
Confidence65
buildOne report1 publisher

Tag-pinned workflows re-ran Mini Shai-Hulud after issues-helper was re-enabled

Socket says workflows using issues-helper@v2.2.1 re-ran Mini Shai-Hulud after the Action was re-enabled on September 16 with its malicious tags intact. The earlier takedown only made those jobs fail, so the fix that holds is dropping the Action or pinning a verified commit SHA.

Publishers:dev.to

Reality

Evidence55
Adoption35
Hype gap+10
Incentives
Insufficient
Confidence55
buildOne report1 publisher

Poisoned vite.config.js turns git pull and npm run build into malware

Malware that steals a developer's Git credentials force-pushes a poisoned vite.config.js to every reachable branch, a dozen rewritten in a minute in one case. A routine git pull and build then runs it, and dependency scanners never see the change.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50
buildConfirmed3 publishers

A file.path parameter in GitLab's commit API reads server files before authentication

The fix ships in 19.3.2, 19.2.6 and 19.1.8, and scanning for the flaw started the day after disclosure. Whether you can tell if a read succeeded on your instance depends on whether your proxy logs request bodies.

Publishers:dev.todocs.gitlab.comwatchtowr.com

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 73%
Investor
Investor 5%

Reality

Evidence80
Adoption
Insufficient
Hype gap+15
Incentives45
Confidence74
buildOne report1 publisher

Verifying one merged GitHub Actions env: fix took seven hops across four files

The canonical script-injection fix takes the untrusted expression out of run: and puts it in env:, and shape-matching scanners stop reading there. A new tool follows the value on into the composite action and the Node bundle that finally calls spawn().

Publishers:dev.to

Reality

Evidence58
Adoption
Insufficient
Hype gap−12
Incentives60
Confidence55

Earlier coverage

  1. Branch protection stopped the Terraform edits in Unit 42's ten-hour agent intrusion

    Build · September 16, 2026 · One report1 publisher

  2. Malicious packages appeared every six minutes while defenders patched in days

    Product · September 13, 2026 · One report1 publisher

  3. A CI leak drill measures the time between spotting a key in the log and revoking it

    Build · September 11, 2026 · One report1 publisher

  4. A committed .github/copilot-instructions.md prepends a repository's invariants to every Copilot request

    Build · September 11, 2026 · One report1 publisher

  5. JetBrains' final Cadence update moves the exposure from a 2024 backup into live storage

    Security · September 7, 2026 · One report1 publisher

  6. A backdoored LiteLLM package cleared 119,000 downloads before PyPI quarantined it

    Build · September 5, 2026 · One report1 publisher

  7. Unit 42 timed an agentic intrusion at fifty ATT&CK techniques in under ten hours

    Science · September 5, 2026 · Confirmed2 publishers

  8. Unpatched TeamCity server gave attackers AWS IAM credentials from JetBrains' Cadence backup

    Security · September 5, 2026 · One report1 publisher

  9. A missing attribute condition admits every identity its provider will vouch for

    Build · August 31, 2026 · One report1 publisher

  10. Jenkins static AWS keys work from anywhere; the OIDC replacement fails in four known ways

    Build · August 27, 2026 · One report1 publisher