IJWMT Vol. 16, No. 4, 8 Aug. 2026
Cover page and Table of Contents: PDF (size: 491KB)
PDF (491KB), PP.291-299
Views: 0 Downloads: 0
CI/CD security, DevSecOps, GitHub Actions, Docker, credential leaks, misconfigurations, pipeline hardening
Continuous Integration and Continuous Deployment (CI/CD) pipelines have become fundamental to modern software engineering, enabling rapid and reliable delivery of applications. However, their automation introduces critical vulnerabilities, particularly credential leaks and misconfigurations, which undermine the security of development and deployment environments. This study investigates security risks in Dock-er-based GitHub Actions workflows and proposes a tailored, DevSecOps-aligned security checklist to mitigate these threats. A systematic literature review was combined with hands-on experiments, in which controlled credential exposures and workflow misconfigurations were deliberately introduced and analyzed. Security controls such as secret scanning with GitGuardian and TruffleHog, configuration validation with GHAST, and access control enforcement were tested in a CI/CD testbed. The findings demonstrate that these integrated methods significantly reduce the risk of credential leakage and pipeline hijacking, while maintaining minimal performance overhead. The novelty of this work lies in consolidating fragmented best practices into a work-flow-specific model that is immediately applicable to real-world projects. This contrib-utes actionable guidance for secure-by-design CI/CD pipelines, offering practical protection against supply-chain threats while preserving delivery speed and scalability.
Akzhibek Amirova, "Securing CI/CD Pipelines: A DevSecOps Framework for Preventing Credential Leaks and Misconfigurations", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.16, No.4, pp. 291-299, 2026. DOI:10.5815/ijwmt.2026.04.16
[1]Meli, M.; Gasser, L.; Ernst, M.D. “How Bad Can It Git? Characterizing Secret Leakage in Public GitHub Repositories,” in Proceedings of the Network and Distributed System Security Symposium (NDSS), 2019
[2]GitGuardian. State of Secrets Sprawl Report 2024. Available online: https://www.gitguardian.com (accessed on 2 October 2025).
[3]SolarWinds. The SolarWinds Cyberattack Explained. SolarWinds, 2021.
[4]Saleh, S. M.; Al Ifat, M. N.; Madhavji, N. H.; Steinbacher, J. “A Threat-Oriented Study of API Security Challenges in CI/CD Pipelines,” in 2025 IEEE International Conference on Cloud Computing Technology and Science (CloudCom), Shenzhen, China, 2025, pp. 1–8. DOI: 10.1109/CloudCom67567.2025.11331540.
[5]OWASP Foundation. OWASP Top 10 CI/CD Security Risks. 2023. Available online: https://owasp.org (accessed on 2 October 2025).
[6]Batista, L.; et al. “Securing DevOps by Identifying the Most Common Vulnerabilities in CI/CD Pipelines,” in 2025 IEEE Symposium on Computers and Communications (ISCC), IEEE, 2025, pp. 1–6. DOI: 10.1109/ISCC65549.2025.11326304
[7]Alshammari, B.; Singh, M. M. “A Systematic Literature Review on Tackling Cyber Threats for Cyber Logistic Chain and Conceptual Frameworks for Robust Detection Mechanisms,” IEEE Access, vol. 13, pp. 67661–67692, 2025. DOI: 10.1109/ACCESS.2025.3552689.
[8]Bernardino, N. A.; Sequeira, B.; Piza, E.; Henriques, F.; Neves, F.; Reis, C. I. “Enhancing DevSecOps: Three Custom Tools for Continuous Security,” in 2024 IEEE 11th International Conference on Cyber Security and Cloud Computing (CSCloud), 2024, pp. 53–58. DOI: 10.1109/CSCloud62866.2024.00017.
[9]Zhao, X.; et al. Identifying the Primary Dimensions of DevSecOps: A Multi-Aspects Study. Science of Computer Programming 2024, 230, 102912.
[10]OWASP Foundation. CI/CD Security Risks. OWASP, 2021.
[11]Pan, Z.; et al. “Ambush from All Sides: Understanding Security Threats in Open-Source Software CI/CD Pipelines,” IEEE Transactions on Dependable and Secure Computing, vol. 21, no. 1, pp. 403–418, 2023. DOI: 10.1109/TDSC.2023.3253572.
[12]Saha, A.; et al. “Secrets in Source Code: Reducing False Positives Using Machine Learning,” in 2020 International Conference on COMmunication Systems & NETworkS (COMSNETS), IEEE, 2020, pp. 168–175. DOI: 10.1109/COMSNETS48256.2020.9027350..
[13]Trend Micro. Security Analysis of GitHub Action Runners. Technical Report, 2023.
[14]GitHub. GitHub Actions Documentation. GitHub, 2023.
[15]Muralee, S.; Koishybayev, I.; Nahapetyan, A.; Tystahl, G.; Reaves, B.; Bianchi, A.; et al. “ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and Actions,” in 32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 6983–7000.
[16]Riggio, E.; Pautasso, C. “Pipelines Under Pressure: An Empirical Study of Security Misconfigurations of GitHub Workflows,” in International Conference on Product-Focused Software Process Improvement, Cham, Switzerland: Springer Nature Switzerland, 2025, pp. 220–236. DOI: 10.1007/978-3-032-12089-2_14.
[17]GitGuardian. State of Secrets Sprawl Report. GitGuardian, 2023.
[18]OWASP. Static Application Security Testing (SAST) Tools Guide. OWASP, 2022.
[19]SonarQube. Documentation and Security Rules. SonarSource, 2023.
[20]Snyk. Container and Dependency Scanning Documentation. Snyk, 2023.
[21]Docker. Docker Security Best Practices. Docker Inc., 2023.
[22]GitHub Security Lab. Security Advisories on Actions. GitHub, 2023.
[23]Semgrep. Open-Source Static Analysis Engine. r2c, 2022.
[24]Veracode. State of Software Security Report. Veracode, 2023.
[25]Checkmarx. Application Security Testing Solutions. Checkmarx Ltd., 2022.
[26]Clair. Container Vulnerability Scanner. CoreOS/Red Hat, 2021.
[27]Google Cloud. Supply Chain Security in CI/CD. Google, 2023.
[28]Thompson, K. “Reflections on Trusting Trust,” Communications of the ACM, vol. 27, no. 8, pp. 761–763, 1984. DOI: 10.1145/358198.358210.