This commit is contained in:
2026-07-18 10:09:57 +09:00
parent 86cad348b4
commit 8f0e53766a
45 changed files with 6221 additions and 781 deletions
+6 -2
View File
@@ -1,10 +1,10 @@
---
title: CI/CD Runtime Security
created: 2026-06-30
updated: 2026-07-02
updated: 2026-07-16
type: concept
tags: [security, supply-chain, quality, reliability, automation]
sources: [raw/articles/cicd-sensor-2026.md, raw/articles/scrutineer-oss-security-workflow-2026.md, raw/articles/tangled-spindle-microvm-ci-runners-2026.md, raw/articles/thehackernews-argo-cd-repo-server-unpatched-rce-2026.md, raw/articles/synacktiv-argo-cd-codeql-rce-2026.md, raw/articles/zenn-ai-generated-github-actions-yaml-security-2026.md, raw/articles/flatt-github-actions-credential-leakage-2026.md, raw/articles/github-secret-scanning-public-monitoring-2026.md, raw/articles/microsoft-ghqr-github-quick-review-2026.md, raw/articles/strix-ai-pentesting-agent-2026.md]
sources: [raw/articles/cicd-sensor-2026.md, raw/articles/scrutineer-oss-security-workflow-2026.md, raw/articles/tangled-spindle-microvm-ci-runners-2026.md, raw/articles/thehackernews-argo-cd-repo-server-unpatched-rce-2026.md, raw/articles/synacktiv-argo-cd-codeql-rce-2026.md, raw/articles/zenn-ai-generated-github-actions-yaml-security-2026.md, raw/articles/flatt-github-actions-credential-leakage-2026.md, raw/articles/github-secret-scanning-public-monitoring-2026.md, raw/articles/microsoft-ghqr-github-quick-review-2026.md, raw/articles/strix-ai-pentesting-agent-2026.md, raw/articles/github-actions-workflow-execution-protections-2026.md, raw/articles/1password-credential-broker-2026.md]
confidence: medium
---
@@ -28,10 +28,14 @@ AI が生成した GitHub Actions YAML は、動作確認だけでなく trigger
GMO Flatt Security の GitHub Actions 解説は、OIDC / Trusted Publishing を入れても「認証後に runner 上へ置かれる派生クレデンシャル」は残る、という runtime 視点を強調する。`GITHUB_TOKEN` は `actions/checkout` の credential persistence や `Runner.Worker` のメモリから読まれうるし、AWS/GCP/Azure/Docker などの認証 Action は一時クレデンシャルや設定ファイルを後続 step から到達可能な場所へ置く。Environment 保護、ruleset、claim の数値 ID 検証、job 分離、短い session duration は有効だが、依存関係・Action・正規レビュアー経由で信頼済み経路に悪意ある code が入ると、漏洩を完全には防げない。したがって runner 側の process/network/file trace と cloud 側の異常検知を合わせ、漏洩後の検知・調査・失効手順まで設計する必要がある。^[raw/articles/flatt-github-actions-credential-leakage-2026.md]
1Password Credential Broker は、この OIDC / Workload Identity Federation を credential 配布側へ寄せる実装例である。GitHub Actions job が platform-issued signed token で repo・branch・workflow・environment・commit を証明し、1Password が trust policy と照合して item-level の credential だけを job-scoped window で渡す。これは runner 上の派生 credential 問題を完全には消さないが、vault への常時 access と広い service account token を減らし、誰のどの workflow がどの credential を取ったかを監査可能にする。将来の AI agent 対応では、agent も同じく task-scoped short-lived token を受け取るため、[[ai-agent-identity-security]] の実装パターンとしても重要である。^[raw/articles/1password-credential-broker-2026.md]
GitHub の Secret Protection による public monitoring は、secret leak detection の境界を「自社 repo」から GitHub の公開面全体へ広げる例である。企業メンバーや verified domain の metadata から、個人 fork、OSS repo、issue、pull request、discussion などに漏れた secret を enterprise に帰属させる。これは CI/CD runtime そのものの隔離策ではないが、agent・bot・開発者が組織外の公開面へ token を誤って出す前提で、公開漏洩の発見を incident response loop に入れる実務的な補助線になる。^[raw/articles/github-secret-scanning-public-monitoring-2026.md]
Microsoft の GitHub Quick Review (`ghqr`) は、GitHub Enterprise / org / repo / GHES を横断して security posture を棚卸しする CLI である。Dependabot、secret scanning、code scanning、2FA/SAML、branch protection、CODEOWNERS、Actions workflow permissions、self-hosted runners、audit log、Copilot policy、MCP settings までを Markdown / Excel / JSON に出せるため、CI/CD runtime security を「個別 YAML のレビュー」から「GitHub tenant 全体の定期診断」へ広げる道具として位置づけられる。^[raw/articles/microsoft-ghqr-github-quick-review-2026.md]
GitHub Actions の workflow execution protections は、runtime boundary を YAML 内の自己防衛から enterprise / org / repository policy へ引き上げる機能である。Actor rule で workflow を起動できる user / role / GitHub App / Copilot / Dependabot を制限し、event rule で `pull_request_target` や `workflow_dispatch` などを制御できる。これは malicious workflow file が commit に入った後で runner が動く前に、中央 ruleset が「その actor/event は workflow を走らせてよいか」を判定するため、AI が生成した YAML のレビューや [[open-source-package-supply-chain-attacks]] の依存実行対策と補完関係にある。^[raw/articles/github-actions-workflow-execution-protections-2026.md]
[[strix]] は、CI/CD に入る security testing が SAST や設定監査だけでなく、実行中の application へ AI pentest agent を当て、reconnaissance、exploitation、PoC validation、修正案、report まで返す方向へ広がる例である。これは「runner が何をしたかを監視する」cicd-sensor 型の runtime evidence と対になる。Strix のような tool を PR gate に置くなら、検査対象の sandbox、network egress、test credential、false-positive review、auto-fix の human gate まで含めて CI/CD runtime security として設計する必要がある。^[raw/articles/strix-ai-pentesting-agent-2026.md]
## Design implications