CIO Brief: Your Build Pipeline Has the Keys to Production
Retrospective: this article looks back at events from April 2022, written in 2026 with the benefit of hindsight.
The short version: In 2022, attackers stole the digital access passes that Heroku and Travis CI used to connect to customers' GitHub code repositories, and downloaded private code from dozens of organizations. Your build and deployment tools hold the keys to your products and your cloud.
Why the build pipeline is critical
Modern software is built and deployed automatically by pipelines that connect code repositories, cloud accounts and production systems. Those tools need powerful access, and they often store credentials. Compromise the pipeline, and an attacker can steal code, insert malicious changes or reach production.
The business impact
- Source code theft, including any secrets inside it.
- Supply-chain risk if attackers alter software you ship to customers.
- Cloud compromise through stored deployment credentials.
Questions to ask your team
- Which third-party tools have access to our code repositories?
- Do our pipelines store long-lived cloud credentials, or use short-lived ones?
- Are secrets ever committed to our repositories?
- Who can change pipeline configurations?
What good looks like
Minimal third-party integrations with least-privilege access, short-lived credentials for deployments, secret scanning on every repository, and protected pipeline configuration.
The decision
Ask your engineering leads to eliminate stored cloud keys from CI/CD pipelines this year. The technology to do it is mature and free.
- Heroku and Travis CI OAuth Tokens Stolen (Apr 2022): Hijacking GitHub Access Incident Teardowns
- How to Secure CI/CD Pipelines With OIDC Federation Instead of Stored Secrets How-To & Hardening
- Detecting Stolen OAuth Tokens: Sentinel and GuardDuty Detections Detection & Response