logo

The Overlooked Attack Surface: Securing Code Repositories, Pipelines, and Developer Infrastructure

ID: e7619ba7-2d43-5149-bc42-f084f3c46170

STIX ID: report--e7619ba7-2d43-5149-bc42-f084f3c46170

Feed Name: Wiz Blog

Date Published: 2025-02-14

Date Updated: 2026-05-01

...
...

This article argues that software supply chain breaches now top external attack vectors and promotes securing developer infrastructure as a core pillar of ASPM. It outlines how Wiz Code extends security across version control, CI/CD pipelines, and artifact registries by mapping identities, enforcing repository and pipeline controls, detecting and correlating active threats from logs and runtime signals, aligning with frameworks (CIS, OWASP Top 10 CI/CD, OpenSSF), and enabling image signing and verification to ensure only trusted artifacts are deployed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.