Aug 2026· International Journal of Wireless and Microwave Technologies· 0 citations
TL;DR
This study investigates security risks in Dock-er-based GitHub Actions workflows and proposes a tailored, DevSecOps-aligned security checklist to mitigate these threats, offering practical protection against supply-chain threats while preserving delivery speed and scalability.
Abstract
Continuous Integration and Continuous Deployment (CI/CD) pipelines have become fundamental to modern software engineering, enabling rapid and reliable delivery of applications. However, their automation introduces critical vulnerabilities, particularly credential leaks and misconfigurations, which undermine the security of development and deployment environments. This study investigates security risks in Dock-er-based GitHub Actions workflows and proposes a tailored, DevSecOps-aligned security checklist to mitigate these threats. A systematic literature review was combined with hands-on experiments, in which controlled credential exposures and workflow misconfigurations were deliberately introduced and analyzed. Security controls such as secret scanning with GitGuardian and TruffleHog, configuration validation with GHAST, and access control enforcement were tested in a CI/CD testbed. The findings demonstrate that these integrated methods significantly reduce the risk of credential leakage and pipeline hijacking, while maintaining minimal performance overhead. The novelty of this work lies in consolidating fragmented best practices into a work-flow-specific model that is immediately applicable to real-world projects. This contrib-utes actionable guidance for secure-by-design CI/CD pipelines, offering practical protection against supply-chain threats while preserving delivery speed and scalability.
The idea of secure environments of continuous integration and continuous delivery has emerged as an object of study due to the fact that current delivery pipelines concentrate privileged automation, dependency resolution, artifact handling, and release control within a small number of highly interconnected systems. Thi...
Ratan Raj Anandeshi· International Journal of Sci...· 0 citations
A secure CI/CD update workflow that combines keyless Cosign signing (OIDC/Fulcio), immutable SHA-256 digest–based image addressing, mandatory pre-deployment signature verification, and freshness controls against rollback attacks is presented, while permitting controlled rollback only to previously verified versions.
The article represents a Proof of Concept (PoC) for policy-as-code methodology designed to detect “Privilege Sprawl” in GitLab CI/CD environments and showed how teams can reduce their organisational exposure by 73% and get back into compliance with Least Privilege.
Ensuring the integrity of automotive software, from source code to deployed binaries, has become critical as vehicles increasingly rely on over-the-air (OTA) updates and complex supply chains. The Uptane framework secures OTA update delivery for automotive systems but does not enforce integrity within the upstream soft...
Iwinosa Aideyan, M. Pesé, Richard. R. Brooks· Distributed Ledger Technolog...· 0 citations
The Adaptive Risk-Driven DevSecOps Framework (ARDDSF) is proposed, a layered framework for securing multi-cloud enterprise systems in the era of agentic artificial intelligence that bridges DevSecOps automation, AI-assisted security analysis, Zero Trust policy enforcement, and multi-cloud governance.
Nitin Bodade· International Journal of Inn...· 0 citations
This paper presents an architecture for verifiable container image distribution that addresses key-management challenges and enables policy-enforced admission-time verification, and implements a proof-of-concept integrated with GitHub Actions and GitLab Runners that mitigates common supply-chain attacks under a realist...
N. Fotiou, Lefteris Georgiadis, Ignacio Lacalle et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.