Software supply chain & DevSecOps
Security in the pipeline, and in everything the pipeline pulls in.
33 sketches
CI/CDReviewed here, altered in transit
Branch protectionThe fence does not go all the way round
Code signingA signature nobody checks
Dependency pinningHeld still, or left open
Developer credentialsThe machine with the longest reach
Developer experienceThe path people actually take
Ephemeral runnersStart clean, or inherit everything
Package registriesThe name on the tin
ProvenanceWho signed it, and what made it
Release approvalsThe gate that stopped being a decision
Secret scanningFound is not fixed
Security championsThe handle that was never fitted
Security gatesGates earn the right to stop you
Shift leftEarlier is cheaper, not someone else's job
Source controlThe ledger is also the lever
A trusted build can faithfully ship malicious sourceThe oven never reads the recipe
Dependency confusion exploits naming and resolutionSame name, wrong shelf
Typosquatting attacks developer attentionThe eye test you take at 2am
Lockfiles improve repeatability, not eternal safetyAlways the same tin
Transitive dependencies enlarge unseen trustOne handshake, a hundred guests
Maintainer compromise can use the normal release channelIt came by the usual van
Build secrets should not become build artefactsDeleted on top, still underneath
Reproducible builds make unexpected differences visibleLevel, or it is telling you something
A deployment pipeline is a privileged production pathIt goes straight over the gate
Code review does not protect a compromised runnerNobody looked inside the machine
Forked code should not automatically receive secretsThe belt does not ask who sent it
Branch protection does not protect every release pathThe gate only guards its own road
Deployment credentials should match deployment scopeOne bolt across all three
Build logs can become secret leaksThe log is a page, and people read pages
Self-hosted runners inherit local trustYou gave the job a desk indoors
Release signing depends on protecting signing keysThe seal is only as good as the stamp
Pipeline dependencies are code-execution dependenciesEvery step gets a hand on the lever
Rollback needs the same security as rolloutTwo levers, one machine
