YouShallNotPass! Hardening CI/CD pipelines on mission critical environments
ID: b1b4a78d-dc32-5369-825b-9e2a5c199861
STIX ID: report--b1b4a78d-dc32-5369-825b-9e2a5c199861
Feed Name: Kudelski Security
This blog post introduces YouShallNotPass (YSNP), an open-source custom CI/CD runner and validation service that integrates with GitLab/GitHub and HashiCorp Vault to enforce security controls (repo, image, script, and user checks) prior to job execution. It covers architecture, custom executor scripts for GitLab and GitHub, Vault-based configuration and ACLs, integration testing, and practical use cases demonstrating how YSNP prevents runner hijacking, malicious pipeline modifications, and user impersonation attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
