Google Cloud and Mandiant outline safeguards for hardening CI/CD pipelines

Summary
Google Cloud and Mandiant provide a defense-in-depth blueprint for securing developer endpoints, code repositories, artifacts, CI/CD pipelines, and production deployments against software supply chain threats.
Key points
- The guidance cites campaigns targeting developer tools and workstations, as well as pipeline weaknesses such as cache poisoning, OIDC token theft, and mutable action references.
- Protect developer environments with local secret scanning, managed and vetted IDEs, endpoint monitoring, and isolated sandboxes.
- Strengthen repository security with phishing-resistant MFA, branch protections, short-lived credentials, and pinned dependencies.
- Route external packages through controlled proxies and quarantine; verify artifact signatures and provenance, and pin images and actions to immutable digests or commit hashes.
- Use ephemeral CI runners, restrict permissions and network access, isolate caches, and prevent untrusted pull requests from accessing secrets or deployment runners.
- Add security checks throughout development and deployment, including secret, code, dependency, container, and infrastructure scanning, plus signed SBOMs and runtime safeguards.
Article Details
- Defense Focus
- Prevent, detect, and contain compromises across developer environments, repositories, dependencies, CI/CD pipelines, artifacts, and production deployments.
- Detection Methods
- Monitor IDE process trees for anomalous file access, unexpected child processes, and unauthorized outbound connections.
- Scan local changes and repository pushes for exposed secrets; monitor repository API activity, force-pushes, and audit-history discrepancies.
- Screen new dependencies and container images at an internal proxy or registry, then continuously re-evaluate stored artifacts as vulnerabilities emerge.
- Use dependency reachability and known exploitation signals to prioritize vulnerability findings.
- Apply automated secret, application-code, dependency, container, dynamic-application, and cloud-posture scanning gates at the corresponding development and deployment stages.
- Verify artifact signatures, expected build identities, immutable digests, and signed software bills of materials before admission.
- Compare live cloud configuration with version-controlled infrastructure definitions and monitor runtime logs, metrics, and audit events.
- Data Sources
- Developer endpoint and IDE process, file-access, and network telemetry
- Device compliance signals
- Repository API activity, branch history, and audit logs
- Package lockfiles and dependency inventories
- Package-registry and container-image scan results
- Build provenance, artifact signatures, digests, and signed software bills of materials
- CI/CD runner execution, cache-access, and network logs
- Cloud configuration, runtime logs, system metrics, and audit events
- Rule Types
- Pre-commit and repository secret-scanning gates
- Static application security testing rules
- Software composition analysis and dependency-reachability checks
- Container and registry scanning policies
- Dynamic application security testing checks
- Infrastructure-as-Code and Policy-as-Code checks
- Artifact admission and signature-verification policies
- Platforms
- Developer endpoints and isolated development environments
- Source-code repositories
- Internal package proxies and artifact registries
- CI/CD build runners
- Container and cloud production environments
- Defensive Actions
- Restrict developer extensions to reviewed versions, scan for secrets before commits, and block repository access when device posture fails compliance checks.
- Require reviewed changes and automated checks before merging; restrict administrative bypasses and force-pushes.
- Replace persistent credentials with narrowly scoped, short-lived identities and protect developer authentication with hardware-backed credentials where possible.
- Pin dependencies, actions, and images to immutable versions, commits, or digests; enforce lockfile verification and a release-age cooldown for public packages.
- Route external components through an inspecting, quarantining internal proxy and separate internal repositories from public registries.
- Use single-use runners, restrict their outbound traffic, isolate build caches by branch privilege, and withhold secrets and deployment runners from unvetted pull-request code.
- Generate and sign build provenance and software bills of materials, and reject artifacts that fail identity, signature, or digest verification.
- Apply deployment admission checks, least-privilege runtime settings, network segmentation, and continuous configuration-integrity monitoring.
MITRE ATT&CK
T1195.001 · Compromise Software Dependencies and Development ToolsThe article describes attackers placing malicious code in open-source MCP packages and using poisoned dependencies to reach developer environments and build pipelines.T1528 · Steal Application Access TokenThe article identifies OIDC token extraction from pipelines and the theft of API tokens and active session credentials from local engineering environments.
People
Arafat IsmailAcknowledged for assistance with the guidance.Bhavesh DhakeAcknowledged for assistance with the guidance.Brentyn MuirAcknowledged for assistance with the guidance.Brian MeyerAcknowledged for assistance with the guidance.Emilio OropezaAcknowledged for assistance with the guidance.Eyad MahmoudAcknowledged for assistance with the guidance.Franklin RamosAcknowledged for assistance with the guidance.Gursev SinghAcknowledged for assistance with the guidance.Omar ElAhdanAcknowledged for assistance with the guidance.Sara TakhimAcknowledged for assistance with the guidance.Stuart CarreraAcknowledged for assistance with the guidance.Stuart MunroAcknowledged for assistance with the guidance.Will SilverstoneAcknowledged for assistance with the guidance.
Vendors
GitHubstatic credentials, attackers have escalated to advanced pipeline manipulation techniques, including GitHub Actions cache poisoning, OpenID Connect (OIDC) token extraction, and the subversion of mutable actionGoogleOrganizations can manage this secure boundary using Google Artifact Registry to host private repositories, configure virtual upstream repositories, and restrict direct build-runner access to public registries.
Products
GitHub Actionsstatic credentials, attackers have escalated to advanced pipeline manipulation techniques, including GitHub Actions cache poisoning, OpenID Connect (OIDC) token extraction, and the subversion of mutable action tags toGitHub AppsFor automated CI/CD pipelines and third-party integrations, organizations should mandate the use of GitHub Apps in place of service account PATs to leverage short-lived, highly scoped access tokens that automaticallyGoogle Artifact RegistryOrganizations can manage this secure boundary using Google Artifact Registry to host private repositories, configure virtual upstream repositories, and restrict direct build-runner access to public registries.Google Model ArmorProtect AI workloads from prompt injection and jailbreaks using runtime guardrails such as Google Model Armor.