ATALAIA
  1. Home
  2. Services
  3. CI/CD Pipeline Audit
06Station 06 · Build

CI/CD Pipeline Audit

Your pipeline holds the keys to production. We audit runners, tokens, third-party actions and who can change the workflow itself.

One pipeline, five hotspots

A typical workflow from pull request to production. Every number is a place a malicious change can turn into a release.

  1. 1Pull requestfrom a fork
  2. 2ci.ymlworkflow file
  3. 3Runnershared, keeps cache
  4. 4Actionsuses: …@v3
  5. 5SecretsDEPLOY_TOKEN
  6. Productiondeploy
  1. 1
    Fork PRs run with the same rights as branch PRs

    Separate workflow for forks, no secrets.

  2. 2
    Anyone with write access can edit ci.yml

    CODEOWNERS and protected workflow files.

  3. 3
    The runner keeps its cache between jobs

    Ephemeral runners, one per job.

  4. 4
    Actions pinned to a tag the owner can move

    Pin every action to a commit SHA.

  5. 5
    One token reaches every environment, from every job

    One token per environment, scoped to the deploy job.

Following the keys

Pick a step, or let it play. Every line is what someone in the room actually says.

Step 1Map the line

Repos, workflows, runners, secrets and deploy targets.

ATALAIALet's list every workflow, runner and secret first.

PLATFORM23 workflows, two shared runners, and secrets in every repo.

Leaves the roomMap: 23 workflows, 4 runners, 31 secrets

Step 2Follow the keys

Which step can reach which secret and which environment.

ATALAIAThis deploy token is visible to every job, tests included.

PLATFORMIt's one token for all environments. Easier to rotate.

ATALAIAAnd easier to steal. A test step can deploy to production.

Leaves the room1 token reaches prod from every job

Step 3Break it on paper

How a malicious PR, action or runner would move.

ATALAIAA fork PR runs on the shared runner, and the runner keeps its cache.

DEV LEADSo a malicious PR could poison the next build?

ATALAIAYes. And this action is pinned to a tag. Whoever owns it can move the tag.

Leaves the roomAttack path: fork PR → runner → prod

Step 4Harden the templates

Pinned actions, scoped tokens, ephemeral runners, protected workflows.

PLATFORMNew template: actions pinned by SHA, one token per environment.

ATALAIAEphemeral runners for forks, and CODEOWNERS on workflow files.

DEV LEADWe roll it out to the 23 repos, one PR each.

Leaves the roomTemplate: pinned SHAs, scoped tokens, ephemeral runners

  • ATALAIA
  • PLATFORM
  • DEV LEAD
  • DEVELOPER

What goes wrong

A pipeline that can deploy anything can be made to deploy anything. Shared runners, broad tokens and unpinned actions turn one compromised step into a compromised release.

SIGNS YOU'RE HERE

  • Third-party actions are referenced by tag, not by commit
  • One deploy token works for every environment
  • Anyone with write access can edit the workflow files

What you get

  • A map of every pipeline, runner and secret
  • Findings ranked by blast radius
  • Pinned, least-privilege workflow templates
  • Branch and workflow protection settings to apply

Typical shape: Two to four weeks, depending on the number of pipelines.

Talk it through

A 30-minute call. No slides, no price list, and a next step either way.