CIO Brief: Pipeline Supply-Chain Risk Explained
Retrospective: this article looks back at events from March 2025, written in 2026 with the benefit of hindsight.
The short version: In March 2025, a popular add-on used in tens of thousands of software build pipelines was hijacked. It quietly printed companies' secret keys into logs — some publicly visible. Nobody at those companies changed anything; their pipelines simply trusted a tool that changed underneath them.
What a build pipeline supply-chain attack is
Modern software is built by automated pipelines that use many third-party components. If one of those components is compromised, the attacker's code runs inside your build — with access to the keys used to deploy to production.
The business impact
- Leaked cloud and production credentials.
- Potential tampering with software you ship.
- Emergency rotation work across teams.
Questions to ask your team
- Which third-party components run in our build pipelines?
- Are they locked to specific, reviewed versions, or do they update automatically?
- Do our pipelines store long-lived cloud keys?
- Did the tj-actions incident affect us, and how did we confirm?
What good looks like
Pipeline components locked to reviewed versions, an approved list of allowed components, no long-lived secrets in pipelines, and monitoring for unusual pipeline behavior.
The decision
Ask engineering to lock all third-party pipeline components to fixed versions and remove stored cloud keys from pipelines. Both are well-understood fixes with outsized risk reduction.
- tj-actions/changed-files Compromise (Mar 2025): A GitHub Action Leaks CI Secrets Incident Teardowns
- How to Pin and Allowlist GitHub Actions in Cloud Deployment Pipelines How-To & Hardening
- Detecting GitHub Actions Supply Chain Attack: Sentinel and GuardDuty Detections Detection & Response