logo

CI/CD pipelines and the cloud: Are your development secrets at risk?

ID: c0883530-ed50-5b3b-ae12-ac76190f7d00

STIX ID: report--c0883530-ed50-5b3b-ae12-ac76190f7d00

Feed Name: ReversingLabs Blog

Threat Score
60/100

Date Published: 2024-05-08

Date Updated: 2026-04-29

Author: [email protected] (John P. Mello Jr.)

...
...

Executive Summary: This report warns that CI/CD pipelines combined with cloud command-line interfaces (AWS, GCP, Azure) can leak secrets when environment variables or CLI outputs are logged or mishandled, exposing credentials, tokens, and keys. It outlines common causes (hard-coded secrets, misconfigured jobs, .gitignore omissions, insecure environment variable handling), emphasizes the potential for attackers to access cloud resources or inject malicious code, and recommends mitigations including using secrets managers, temporary credentials, secure CLI defaults, automated scanning and rotation, and developer training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.