Secure code review
Manual review of source code, supported by static analysis, for vulnerabilities that cannot be seen from outside.
Application security
Assessment of the path from a commit to production: repositories, pipelines, runners, dependencies and build artefacts.
Infrastructure and cloud
The pipeline that builds and deploys your software holds more privileges than most administrators. It reads the source code, carries the signing keys and the cloud credentials and writes to production. It is also assembled from third-party actions, plugins and packages that change without notice.
We test this path the way an attacker would: what a contributor with minimal rights can do, what a malicious dependency or pull request can reach, and whether the artefact that is deployed is provably the one that was reviewed.
01Scope
02Approach
We trace the path from a commit to production and list the systems, identities and secrets along it.
Repositories, pipelines and registries are reviewed against the OWASP Top 10 CI/CD Security Risks and the SLSA requirements.
From the positions of an external contributor, an internal developer and a compromised dependency we attempt to reach secrets and to alter what is built. The work is done on forks and test projects wherever that proves the point.
Changes are ordered by the attack paths they close. Each comes with the configuration that implements it.
03
04
05Standards
The most critical risks of build and delivery pipelines.
OWASP Foundation
Requirements for the integrity and provenance of build artefacts.
Open Source Security Foundation
Practices of secure software development that findings are mapped to.
NIST
Severity score and vector of every finding.
FIRST
Class of weakness behind every finding.
The MITRE Corporation
06Questions
We run harmless proof code that shows what would be reachable, for example the name of a secret and not its value. Production pipelines are touched only where the rules of engagement allow it; most paths are proven in a test project with the same configuration.
The provider secures the platform. What you put on it is yours: permissions, triggers, secrets and third-party components. That is where attacks on pipelines succeed.
We verify that the bill of materials your build produces is complete and matches the artefact. Generating and maintaining it is part of your build; we recommend how.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.