logo

Auditing GitLab: The CI/CD Kill Chain

ID: b19155bb-ce8e-5ef3-9831-39c6012f1144

STIX ID: report--b19155bb-ce8e-5ef3-9831-39c6012f1144

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: BHIS

...
...

This blog-style research report details a three-phase large-scale audit of public GitLab projects using GoGatoZ to find CI/CD misconfigurations and supply-chain risks: Phase 1 (broad DevOps keyword sweep), Phase 2 (Fortune 500–targeted), and Phase 3 (industry verticals). Across 3,757 projects the authors reported 7,331 findings (1,580 HIGH), with prevalent issues including unprotected fork merge pipelines, privileged/self-hosted runners, remote script execution (curl | bash), variable injection, and plaintext secrets; the report also describes a systematic false-positive filtering workflow and provides specific remediation, mitigation, and prevention guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.