Code review does not protect a compromised runner
Reviewing code carefully is worth nothing if the machine that builds it has been tampered with.
The runner sees the source, holds the secrets, produces the artefact and can modify any of them. Every review in the world happens upstream of that. This is why build infrastructure deserves the same scrutiny as the code, and why it usually receives far less.
More on CI/CD security
- A deployment pipeline is a privileged production pathIt goes straight over the gate
- Forked code should not automatically receive secretsThe belt does not ask who sent it
- Branch protection does not protect every release pathThe gate only guards its own road
- Deployment credentials should match deployment scopeOne bolt across all three
- Build logs can become secret leaksThe log is a page, and people read pages
- Self-hosted runners inherit local trustYou gave the job a desk indoors
