Pipeline dependencies are code-execution dependencies
Every action, plugin or step you pull into a pipeline runs code with the pipeline's access.
They are usually chosen casually, referenced by a moving tag, and updated silently by their author. That is a third party executing inside your build with your credentials. Pinning them to a specific commit rather than a tag is a small change that closes a large gap.
More on CI/CD security
- A deployment pipeline is a privileged production pathIt goes straight over the gate
- Code review does not protect a compromised runnerNobody looked inside the machine
- Forked code should not automatically receive secretsThe belt does not ask who sent it
- Branch protection does not protect every release pathThe gate only guards its own road
- Deployment credentials should match deployment scopeOne bolt across all three
- Build logs can become secret leaksThe log is a page, and people read pages
