Skip to content
All services
DevSecOps & secure CI/CDAssess

Pipeline security check

A one-week review of one CI/CD platform, from organisation settings to runners and secrets, with findings mapped to the OWASP Top 10 CI/CD Security Risks and SLSA.

When you need it

Your pipelines can change production, and more people and tools can change your pipelines than anyone planned. One malicious pull request, a hijacked third-party action or a leaked CI variable could open a path into your cloud, and nobody has checked how easily.

What sets the quote

  • One CI platform per check: GitHub Actions, GitLab CI/CD, Azure Pipelines, Jenkins, Bitbucket Pipelines, Google Cloud Build or AWS CodePipeline and CodeBuild.
  • Organisation settings and repository rules for up to 25 repositories.
  • Up to 10 pipelines reviewed in depth, chosen with you from those that can reach production.
  • Hosted runners, plus up to 2 self-hosted runner or agent pools.
  • Deployments to up to 3 environments.
  • Larger estates, or a second CI platform, are quoted after the call.

What changes

  • You know every path from a pull request to production, and which ones an attacker could use.
  • You know whether each release deploys exactly what was tested, built once and promoted by digest.
  • Every finding comes with evidence and a fix, so your team can act without investigating again.
  • You have a 90-day plan ordered by risk and effort, ready for your backlog.

What you get

  • Findings report with severity, affected repositories and pipelines, evidence and the fix
  • Each finding mapped to the OWASP Top 10 CI/CD Security Risks (CICD-SEC-1 to CICD-SEC-10)
  • The SLSA Build level of your main builds today, and the steps to the next level
  • List of cloud keys stored in CI, each with its OIDC replacement
  • One-page summary of the ten biggest risks for management
  • 90-day roadmap ordered by risk and effort
  • All findings as a CSV file for your ticket system
  • A 90-minute readout with your team

What we cover on each platform

AreaGitHub ActionsGitLab CI/CDAzure Pipelines
Access and repository rulesSSO and enforced 2FA, rulesets and branch protection, required reviews, CODEOWNERSSSO and enforced 2FA, protected branches, merge request approval rules, Code OwnersEntra ID sign-in with MFA, branch policies, required reviewers by path
Untrusted inputpull_request_target and workflow_run triggers, event data used in run stepsMerge request pipelines from forks, variables expanded in scriptsPull request builds from forks, variables settable at queue time
Third-party codeActions pinned by commit SHA, allowed-actions policyinclude files and CI/CD components pinned to a SHA or versionMarketplace tasks and extensions, templates from other repositories
RunnersGitHub-hosted and self-hosted runners, runner groups, ephemeral runnersGitLab-hosted and self-managed runners, protected runnersMicrosoft-hosted agents, self-hosted agent pools and their pipeline permissions
Secrets and cloud accessOrganisation, repository and environment secrets, GITHUB_TOKEN permissions, OIDCProtected and masked variables, ID tokens for OIDC, job token scopeVariable groups, Key Vault links, service connections with workload identity federation
Gates, approvals and auditRequired status checks, environments with required reviewers, audit log streamingMerge request approval policies, protected environments with deployment approvals, audit eventsBuild validation, environment approvals and checks, auditing and audit streaming

Jenkins, Bitbucket Pipelines, Google Cloud Build and AWS CodePipeline/CodeBuild are checked in the same six areas, using each platform’s own settings.

Not included

  • Fixing the findings (quoted separately, often as keyless pipelines and secrets cleanup or a secure CI/CD pipeline)
  • Penetration testing or live attacks on your pipelines (we can refer you to a certified partner)
  • Application code review
  • Compliance certification or audit opinions

What we need from you

  • Read access to the repositories and pipeline definitions in scope, for example the Read role on GitHub, Reporter on GitLab or the Readers group in Azure DevOps.
  • A 60-minute screen-share with a CI platform admin for the organisation, runner and secret settings that read-only roles cannot see.
  • Read-only access to the cloud roles your pipelines use: SecurityAudit on AWS, Reader plus Entra Global Reader on Azure, or Viewer and Security Reviewer on Google Cloud.
  • Two 60-minute interviews: your platform or DevOps owner and your security owner.

How it works

  1. Free 30-minute call, then a written fixed quote based on your repository, pipeline and runner counts.

  2. Automated and manual checks of organisation settings and pipeline files in up to 25 repositories.

  3. In-depth review of up to 10 pipelines, their runners and secrets, and the cloud roles they use.

  4. Report, roadmap and a 90-minute readout.

At a glance

Duration
1 week
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Assess

DevSecOps gap check

In 1–2 weeks, a check of how your teams build and ship software, scored against OWASP SAMM and NIST SSDF, ending in a gap list and a 90-day plan.

Duration:1–2 weeks
Build

Keyless pipelines and secrets cleanup

Your pipelines move from long-lived cloud keys to short-lived federated tokens, with secret scanning and dependency gates that stop new leaks and risky dependencies before merge.

Duration:1–3 weeks
Build Popular

Secure CI/CD pipeline

A pipeline that scans every change, builds each image once, promotes it by digest and asks for approval before production, for one app in 2–3 weeks or up to 10 repositories in 4–5 weeks.

Duration:2–5 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.