Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Awesome
  3. CI/CD Attacks

CI/CD Attacks

CC0-1.0

A curated collection of offensive security research, techniques, and tools for attacking CI/CD pipelines and software supply chains.

GitHubGitHub
613 stars58 forks0 contributors

What is CI/CD Attacks?

Awesome CI/CD Attacks is a curated, open-source repository of offensive security research focused on continuous integration and continuous deployment (CI/CD) pipelines and software supply chains. It aggregates techniques, tools, case studies, and resources for identifying and exploiting vulnerabilities in the systems used to develop, build, test, and deploy software. The project serves as a centralized knowledge base for understanding how attackers can compromise modern development workflows.

Target Audience

Security researchers, red teamers, penetration testers, and DevSecOps professionals who need to understand offensive CI/CD tactics to assess the security of their own pipelines or conduct authorized security testing.

Value Proposition

It provides a uniquely comprehensive and curated collection of real-world attack methods and resources specifically for CI/CD environments, saving researchers time from scouring disparate sources. The focus on practical, offensive techniques makes it an essential reference for building realistic threat models and effective defenses.

Overview

Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.

Use Cases

Best For

  • Security professionals researching attack vectors in GitHub Actions or Azure DevOps
  • Red teams planning exercises targeting an organization's software development lifecycle
  • Penetration testers assessing the security of CI/CD pipeline configurations
  • DevSecOps engineers looking to understand offensive techniques to improve defensive controls
  • Students and researchers studying software supply chain security vulnerabilities
  • Developers writing secure CI/CD workflows who want to understand common pitfalls and exploits

Not Ideal For

  • Teams seeking plug-and-play security scanners without manual research
  • Organizations focused only on compliance audits without offensive testing
  • Beginners in cybersecurity who need step-by-step tutorials on CI/CD basics

Pros & Cons

Pros

Comprehensive Attack Catalog

Organizes techniques from initial access to defense evasion, as detailed in sections like 'Publicly Exposed Sensitive Data' and 'Post Exploitation', providing a structured overview of CI/CD vulnerabilities.

Real-World Case Studies

Includes analyses of high-profile attacks, such as the PyTorch supply chain compromise case study, offering practical insights into how exploits unfold in production environments.

Curated Tool References

Links to specialized frameworks like ADOKit for Azure DevOps and Gato for GitHub, saving researchers time in discovering and evaluating offensive tools for various platforms.

Vetted Resource Aggregation

Carefully selects articles and papers from 2021 onward, ensuring the repository maintains high-quality, recent research without outdated or low-value content.

Cons

Static Link Collection

Primarily a list of external resources without interactive content or built-in tools, requiring users to navigate and validate links independently, which can lead to broken links or outdated information.

High Knowledge Barrier

Assumes familiarity with CI/CD systems and offensive security concepts, as seen in technical terms like 'dependency confusion' and 'OIDC misconfigurations', making it less accessible for newcomers.

Limited Defensive Guidance

While it mentions defensive insights implicitly, the focus is on attacks, so detailed mitigation strategies or step-by-step hardening guides are not extensively covered, leaving defenders to infer best practices.

Frequently Asked Questions

Quick Stats

Stars613
Forks58
Contributors0
Open Issues0
Last commit1 month ago
CreatedSince 2024

Tags

#cicd#red-teaming#security-tooling#software-supply-chain#awesome-list#tools#vulnerability-research#devsecops#bugbounty#offensive-security#appsec#hacking#awesome#research#dependency-confusion#ci-cd-security#github-actions

Included in

Awesome452.0k
Auto-fetched 6 hours ago

Related Projects

HackingHacking

A curated list of awesome Hacking tutorials, tools and resources

Stars16,758
Forks1,703
Last commit2 years ago
SecuritySecurity

A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.

Stars14,657
Forks2,334
Last commit6 months ago
Malware AnalysisMalware Analysis

Defund the Police.

Stars13,995
Forks2,676
Last commit2 years ago
Web SecurityWeb Security

🐶 A curated list of Web Security materials and resources.

Stars13,617
Forks1,805
Last commit5 days ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub