Work place: Astana IT University, Astana 010000, Kazakhstan
E-mail: akzhibek.amirova@astanait.edu.kz
Website: https://orcid.org/0000-0002-5715-4954
Research Interests:
Biography
Akzhibek Amirova was born in Kazakhstan. She received a Ph.D. degree in information in 2024. Her major field of study is information systems, with a focus on cybersecurity, and intelligent network systems. She is currently an Assistant Professor at Astana IT University, Astana, Kazakhstan. She has been actively involved in research projects related to cybersecurity, industrial Internet of Things (IoT), and next-generation communication systems, including 5G and 6G networks. Dr. Amirova is a member of IEEE and actively participates in academic and professional activities in the field of cybersecurity. She has contributed to multiple scientific publications in international journals and conferences and is involved in educational and research initiatives in information security and network systems.
DOI: https://doi.org/10.5815/ijwmt.2026.04.16, Pub. Date: 8 Aug. 2026
Continuous Integration and Continuous Deployment (CI/CD) pipelines have become fundamental to modern software engineering, enabling rapid and reliable delivery of applications. However, their automation introduces critical vulnerabilities, particularly credential leaks and misconfigurations, which undermine the security of development and deployment environments. This study investigates security risks in Dock-er-based GitHub Actions workflows and proposes a tailored, DevSecOps-aligned security checklist to mitigate these threats. A systematic literature review was combined with hands-on experiments, in which controlled credential exposures and workflow misconfigurations were deliberately introduced and analyzed. Security controls such as secret scanning with GitGuardian and TruffleHog, configuration validation with GHAST, and access control enforcement were tested in a CI/CD testbed. The findings demonstrate that these integrated methods significantly reduce the risk of credential leakage and pipeline hijacking, while maintaining minimal performance overhead. The novelty of this work lies in consolidating fragmented best practices into a work-flow-specific model that is immediately applicable to real-world projects. This contrib-utes actionable guidance for secure-by-design CI/CD pipelines, offering practical protection against supply-chain threats while preserving delivery speed and scalability.
[...] Read more.Subscribe to receive issue release notifications and newsletters from MECS Press journals