logo

YouShallNotPass! Hardening CI/CD pipelines on mission critical environments

ID: b1b4a78d-dc32-5369-825b-9e2a5c199861

STIX ID: report--b1b4a78d-dc32-5369-825b-9e2a5c199861

Feed Name: Kudelski Security

Date Published: 2023-11-01

Date Updated: 2026-07-22

...
...

This blog post introduces YouShallNotPass (YSNP), an open-source custom CI/CD runner and validation service that integrates with GitLab/GitHub and HashiCorp Vault to enforce security controls (repo, image, script, and user checks) prior to job execution. It covers architecture, custom executor scripts for GitLab and GitHub, Vault-based configuration and ACLs, integration testing, and practical use cases demonstrating how YSNP prevents runner hijacking, malicious pipeline modifications, and user impersonation attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.