Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Harden a CI/CD pipeline by limiting what each job can access, treating workflow files and build scripts as executable code, isolating runners, controlling dependency inputs, and verifying the provenance of released artifacts. A pipeline deserves this care because it runs code from multiple sources, handles credentials, and may publish directly to production.

Why CI/CD pipelines are attractive targets

A pipeline connects software changes to privileged actions: fetching dependencies, building packages, accessing cloud resources, and deploying releases. An attacker who can change a workflow, compromise a runner, or execute code in a job may be able to steal credentials or alter what gets shipped.

Security therefore depends on more than protecting a repository or adding a scanner. The controls must cover the identities a job can use, the code and services it executes, the machine it runs on, the inputs it consumes, and the evidence available when an artifact is promoted.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reduce the value of stolen credentials

Design each job so that a compromised process has the least possible access for the shortest possible time. Prefer short-lived workload identity over stored, long-lived credentials when your CI host and cloud or deployment provider support it. NIST IR 8587, published in September 2026, provides implementation guidance for protecting identity tokens, access tokens, and assertions from forgery, theft, and misuse.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Scope identity to the job and task

  • Give separate jobs and environments separate identities where practical; do not let an ordinary test job inherit deployment authority.
  • Limit permissions to the actions actually required. A job that uploads a test report should not be able to change infrastructure or publish a production release.
  • When using federated workload identity, restrict which repository, branch, workflow, environment, or other supported claims can request a token. Set a narrow audience and validate the provider’s exact claim-matching behavior.
  • Keep credentials out of command-line arguments, logs, build output, and artifacts. Masking helps prevent accidental display but does not stop malicious code running in a job from using a credential it can access.

Keep secrets away from untrusted code

Do not expose secrets to pull-request builds or other jobs that execute code from contributors or sources you have not trusted. Build scripts, tests, package lifecycle hooks, and workflow steps can all execute code; a seemingly harmless change can attempt to read and transmit any secret available to the job. Separate validation of untrusted changes from privileged release work, and require an explicit, controlled transition before a job receives deployment credentials.

Secret availability, token lifetime, permissions, and identity-claim controls vary by CI host and identity provider. Confirm the current behavior and configuration in the official documentation for the services you use rather than assuming that a generic setting has the same meaning everywhere.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Protect workflow definitions and build scripts

Workflow files and scripts determine which code runs, what credentials it receives, and where outputs go. Treat changes to them as security-sensitive code changes, not routine configuration edits.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Require review from designated owners for workflow definitions, build scripts, deployment configuration, and other files that can change pipeline behavior.
  • Use branch protection and review policies to prevent an unreviewed change from reaching a privileged release path.
  • Apply policy checks to changes that add permissions, expose secrets, alter deployment targets, or introduce new external integrations.
  • Review how pull requests from forks, external contributors, and automation accounts are handled. A workflow should not grant elevated access merely because a change passed a build.
  • Keep the definition of release and deployment jobs understandable and auditable; avoid hidden privilege changes in shared scripts or indirect configuration.

Manage third-party actions, plugins, and integrations

Every action, plugin, task, or connected service adds code or a trust relationship to the pipeline. Inventory these dependencies, review their maintainers and requested permissions, and remove integrations that are no longer needed. Where the platform supports it, pin third-party code to an immutable revision instead of a movable tag; a tag can be changed by its publisher or an attacker who compromises the project.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Pinning makes the selected revision stable, but it does not establish that the code is safe. Review what the integration can read or modify, limit its job permissions, and establish a process to evaluate and update pinned revisions. Apply the same scrutiny to reusable workflows and internal shared pipeline components.

Isolate runners and limit what they can reach

A runner executes repository code and may hold temporary credentials or access to internal services. If an untrusted job can leave files, processes, or other state behind, a later job may inherit a foothold. Use clean, ephemeral workers for sensitive workloads where available, and avoid reusing a worker across trust boundaries unless its cleanup and isolation guarantees are clear.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Separate runners for untrusted pull requests from runners that build releases or deploy to sensitive environments.
  • Do not place persistent secrets or broad network access on general-purpose workers.
  • Restrict outbound network access to the destinations the build needs, such as approved source and package repositories. Egress controls can reduce the routes available for exfiltration, but should be tested against legitimate build requirements.
  • Limit access from runners to internal systems, metadata services, and production resources; use separate controls for runner identity and network reachability.
  • Review cleanup, image updates, access to runner administration, and how jobs are assigned to workers.

Control dependency inputs and artifact outputs

Build security covers both what enters the pipeline and what leaves it. Dependencies may arrive through package repositories, source archives, containers, or transitive components. Artifacts may then be consumed by another team or deployed directly. A successful build alone does not prove that either the inputs or output are trustworthy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make dependency acquisition deliberate

  • Use trustworthy, controlled repositories for dependencies; consider vetted internal sources where they fit your architecture.
  • Maintain an inventory of direct and transitive components, and assess or scan them as part of the development and release process.
  • Review dependency changes, including changes introduced indirectly by lockfiles, build tools, or automated update systems.
  • Define how components are selected and updated so that urgent fixes can be adopted without silently accepting arbitrary new inputs.

Preserve evidence about released artifacts

Use provenance and attestations to record relevant information about how an artifact was built, and use SBOM-related practices to describe its component inventory. Consumers can use this evidence when deciding whether to accept or promote an artifact. The value depends on the trustworthiness of the process that generated the evidence and whether the consumer actually verifies it; an attestation is not, by itself, proof that the source or build was benign.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose controls by comparing the trust boundaries

There is no universally preferred CI vendor or single control that addresses every pipeline risk. Compare implementation options against the boundaries they protect:

Decision area Weaker boundary Stronger target
Credentials Long-lived or broadly privileged credentials shared across jobs Short-lived identity where supported, with narrow permissions and job-specific scope
Runners Persistent workers shared by jobs with different trust levels Isolated, clean workers for sensitive jobs, with constrained egress
Workflow changes and integrations Unreviewed workflow changes or unpinned third-party code with broad access Owned and reviewed pipeline code, inventoried integrations, and immutable references where supported
Dependencies and artifacts Untracked inputs and artifacts trusted because a build completed Assessed component inputs and artifact decisions informed by provenance, attestations, and inventory evidence

Put the controls into an implementation sequence

  1. Map the release path. Identify which workflows run on each type of change, what code they execute, which identities and secrets they can access, which runners they use, and what they can publish or deploy.
  2. Separate untrusted validation from privileged work. Ensure contributor-controlled code cannot obtain release credentials or run on a worker with sensitive residual state. Add an explicit review or approval boundary before privileged jobs.
  3. Reduce identity privileges. Replace persistent credentials with short-lived workload identity where supported, scope permissions to the task, and constrain token audience, claims, and lifecycle using the providers’ current guidance.
  4. Lock down pipeline code and integrations. Require ownership and review for security-sensitive workflow changes, inventory external code and services, and pin revisions immutably where supported.
  5. Harden and segment runners. Use clean ephemeral workers for sensitive jobs where possible, separate trust levels, and limit network paths to what the build actually requires.
  6. Make inputs and outputs verifiable. Control dependency sources, inventory and assess components, and generate and retain provenance, attestations, and component inventory evidence appropriate to your release process.
  7. Test the boundaries and monitor exceptions. Verify that low-trust jobs cannot read secrets or deploy, that runner isolation works as intended, and that policy exceptions are visible, owned, and periodically reviewed.

Use NIST and SLSA at the right scope

NIST SP 800-204D, published February 12, 2024, focuses on integrating software supply-chain security measures into DevSecOps CI/CD pipelines. NIST SP 800-218 SSDF 1.1, published February 3, 2022, describes secure software development practices for a broader lifecycle. SLSA offers incremental supply-chain practices for producers and ways for consumers to evaluate artifacts. These resources complement one another; none should be treated as an interchangeable certification or a guarantee that a particular pipeline is secure.

Use the guidance to identify and improve practices at the appropriate level: pipeline controls, development lifecycle processes, and evidence that artifact consumers can evaluate. For settings and features tied to a particular CI host, cloud identity provider, or runner technology, use that provider’s current documentation because implementation details change over time.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prepare for suspected credential or pipeline compromise

A hardening plan should include a response path for a token leak, unexpected workflow change, compromised integration, or runner incident. Decide in advance who can disable a workflow or credential, revoke identity grants, quarantine an artifact, and pause deployment. Preserve relevant workflow, identity, runner, dependency, and artifact records so responders can establish what code ran and what it could access. After containment, rotate affected credentials, inspect downstream artifacts and deployments, and restore the pipeline from reviewed definitions and known-good inputs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.