Home / Companies / Cloudsmith / Blog / Post Details
Content Deep Dive

OWASP CI/CD Top 10: Inadequate Flow Control in CI/CD Pipelines

Blog post from Cloudsmith

Post Details
Company
Date Published
Author
Nigel Douglas
Word Count
1,001
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

With the recent shake-up around CVE funding and broader questions about long-term support for cybersecurity infrastructure, controlling what you can is more important than ever. Modern software development practices rely heavily on CI/CD systems, which serve as the primary conduit from a developer's local environment to production. The adoption of DevOps practices and microservices has diversified the CI/CD landscape, introducing a broader and more complex attack surface that threat actors are increasingly targeting. One key risk is Inadequate Flow Control, where an attacker exploits weak or missing safeguards within the CI/CD pipeline to push unauthorised or malicious code without triggering any manual checks or secondary validation. This can be achieved through various means such as committing code to a monitored branch that automatically triggers deployment, using manual triggers to deploy unauthorised code, or publishing malicious updates to shared libraries used in production. To mitigate this risk, businesses should establish controls that require multiple layers of validation, including enforcing strict branch protection rules, limiting and auditing auto-merge rules, requiring multi-person approval for deployments, and monitoring and detecting production drift. Integrating security-focused tools such as Sigstore, Scorecard, SLSA, and Allstar can also help strengthen the CI/CD security posture.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 1 2,570 304 102 +38%
Serverless 1 1,628 326 111 +97%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.