Skip to main content

4 posts tagged with "ci-cd"

View All Tags

Prevention Has a Ceiling: Designing CI Pipelines That Survive Being Breached

· 41 min read
Ivan Baha
Software Team Lead & Architect

A follow-up to The Silent Exfiltration.

That article described a pipeline in which a single malicious dependency could read every secret in the runner environment and post it to an arbitrary host, before any scan, on any branch, without a merge. It ended with a remediation ladder.

This one starts with an uncomfortable observation: organisations that climbed that ladder are still being hit. The largest software companies in the world, with dedicated supply chain security teams and eight-figure security budgets, had credentials compromised in this attack class in 2026. The conclusion is not that they were careless. The conclusion is that prevention has a ceiling, and above that ceiling a different approach is required – one that assumes the attacker is already executing within the build, and asks how much they obtain, how far they reach, and how long before anyone notices.

One Vulnerability, a Hundred Pipelines, One Board

· 11 min read
Ivan Baha
Software Team Lead & Architect

Twice a month, give or take, the same task lands on my team with a fresh CVE number attached: a high-severity vulnerability in a dependency; patch it everywhere, now. "Everywhere" is close to a hundred microservices, each one a separate GitLab repository with its own pipeline. And "now" does not pause anything else – feature work carries on, because the roadmap doesn't know what a CVE is.

The fixing itself stopped being the hard part a while ago. The hard part is what comes after: watching a hundred pipelines deliver the fix through unstable infrastructure and manual gates, and knowing – not hoping, knowing – that it landed everywhere. Until recently, that knowledge cost a wall of browser tabs and most of a working day.

This post is about the two weekend days that removed the tabs.

The Silent Exfiltration: Why Your CI Pipeline Is an Open Vault

· 17 min read
Ivan Baha
Software Team Lead & Architect

Modern CI/CD pipelines for Node.js applications show three worsening structural issues — secrets injected into the runner environment at the start of the pipeline, unrestricted npm lifecycle script execution during dependency installation, and open outbound network access on CI runners — which together enable silent, zero-alert credential exfiltration by any malicious package in the dependency tree. These findings are platform-independent: GitLab CI, GitHub Actions, and similar systems all have identical default insecure settings. The March 2026 compromise of the Axios npm package, a North Korean state-sponsored supply chain attack targeting a library with about 100 million weekly downloads, is discussed as a real case study confirming the large-scale exploitation of this attack surface.

The "GitOps-Lite" Pattern for Small Projects

· 3 min read
Ivan Baha
Software Team Lead & Architect

When setting up CI/CD for test or staging environments, we immediately want to reach for managed Kubernetes clusters like EKS or GKE. However, for small teams of 1-5 developers and tight budgets, it may not be the best way. A dedicated DevOps specialist and a $70-$100 monthly overhead just for the control plane, on top of main resource costs, sounds a bit extra.