Multi-CloudCIO BriefingsRetrospectives

CIO Brief: Your Build Pipeline Has the Keys to Production

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from April 2022, written in 2026 with the benefit of hindsight.

The short version: In 2022, attackers stole the digital access passes that Heroku and Travis CI used to connect to customers' GitHub code repositories, and downloaded private code from dozens of organizations. Your build and deployment tools hold the keys to your products and your cloud.

Why the build pipeline is critical

Modern software is built and deployed automatically by pipelines that connect code repositories, cloud accounts and production systems. Those tools need powerful access, and they often store credentials. Compromise the pipeline, and an attacker can steal code, insert malicious changes or reach production.

The business impact

  • Source code theft, including any secrets inside it.
  • Supply-chain risk if attackers alter software you ship to customers.
  • Cloud compromise through stored deployment credentials.

Questions to ask your team

  • Which third-party tools have access to our code repositories?
  • Do our pipelines store long-lived cloud credentials, or use short-lived ones?
  • Are secrets ever committed to our repositories?
  • Who can change pipeline configurations?

What good looks like

Minimal third-party integrations with least-privilege access, short-lived credentials for deployments, secret scanning on every repository, and protected pipeline configuration.

The decision

Ask your engineering leads to eliminate stored cloud keys from CI/CD pipelines this year. The technology to do it is mature and free.

heroku github oauth token breach impactHeroku/Travis CI OAuth2022

More on this story