The Overlooked Attack Surface: Securing Code Repositories, Pipelines, and Developer Infrastructure
ID: e7619ba7-2d43-5149-bc42-f084f3c46170
STIX ID: report--e7619ba7-2d43-5149-bc42-f084f3c46170
Feed Name: Wiz Blog
This article argues that software supply chain breaches now top external attack vectors and promotes securing developer infrastructure as a core pillar of ASPM. It outlines how Wiz Code extends security across version control, CI/CD pipelines, and artifact registries by mapping identities, enforcing repository and pipeline controls, detecting and correlating active threats from logs and runtime signals, aligning with frameworks (CIS, OWASP Top 10 CI/CD, OpenSSF), and enabling image signing and verification to ensure only trusted artifacts are deployed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
