Skip to content

Conversation

@bobbyonmagic
Copy link
Collaborator

Partial fix for #750 - adds Pipeline Hardening guide (skill 10 of 24)

Changes

  • 5 new guide files covering CI/CD pipeline security
  • Updated DevSecOps roadmap with link to guide

Guide Contents

  1. Pipeline Security Fundamentals - Threat model, attack vectors, security principles
  2. Runner and Environment Security - Isolation, hardening, ephemeral environments
  3. Secrets and Credentials - Vault integration, rotation, OIDC
  4. Artifact Security - Cosign signing, SLSA framework, SBOMs, provenance

All 4498 tests pass.

@cloudflare-workers-and-pages
Copy link

Deploying devops-daily with  Cloudflare Pages  Cloudflare Pages

Latest commit: ff6a3da
Status: ✅  Deploy successful!
Preview URL: https://d27824f5.devops-daily.pages.dev
Branch Preview URL: https://issue-750-pipeline-hardening.devops-daily.pages.dev

View logs

@bobbyonmagic bobbyonmagic merged commit f3f7f70 into main Feb 1, 2026
2 checks passed
@bobbyonmagic bobbyonmagic deleted the issue-750-pipeline-hardening-guide branch February 1, 2026 21:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants