8 CI/CD security best practices: Protect your software pipeline
ID: ee4d9bfb-8b42-54d3-9911-522134f5dafc
STIX ID: report--ee4d9bfb-8b42-54d3-9911-522134f5dafc
Feed Name: ReversingLabs Blog
Date Published: 2023-11-14
Date Updated: 2026-04-29
Author: [email protected] (Ericka Chickowski)
This report provides eight best practices for securing CI/CD pipelines, stressing that CI/CD tooling is part of the software supply chain and citing the JetBrains TeamCity RCE—exploited by North Korean actors—as a cautionary example. It recommends enforcing least-privilege and MFA, strengthening secrets management, building continuous monitoring and observability, implementing security-as-code guardrails and gates, centralizing and hardening code signing per CA/B Forum requirements, managing security artifacts in registries, and continuously threat-modeling the pipeline to reduce risk across the development lifecycle.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
