Files
llm-wiki/raw/articles/cicd-sensor-2026.md
2026-06-30 22:22:00 +09:00

8.4 KiB

source_url, ingested, sha256, discovered_from, score
source_url ingested sha256 discovered_from score
https://github.com/cicd-sensor/cicd-sensor 2026-06-30 08058a397765b7e6a7bf7d3d5018ee10cf4a016e082943576f6dee56c5d8a72a
platform channel_id channel_name message_id author_id posted_at message_excerpt
discord 1477793137064935675 tw 1521355038830624930 1477793167486226708 2026-06-30T03:21:46.667000000Z CI/CD runtime security sensor mentioned with Betterleaks in development pipeline security context.
4

🚧 **Pre-release: Active development.**cicd-sensor is currently in pre-release and under active development. Feedback is very welcome.

cicd-sensor logo

cicd-sensor

Think EDR, but for CI/CD Pipelines.
Open-source eBPF-powered runtime security sensor for GitHub Actions and GitLab CI/CD.
→ Full documentation

License Language Platform Open Source


Demo

cicd-sensor GitHub Actions demo

Example: cicd-sensor added to a GitHub Actions workflow. The resulting reports are viewable in the GitHub job summary.

What cicd-sensor does

When a compromised dependency in a CI/CD job steals your cloud credentials and leaks them, would you catch it? Would you have the logs to investigate afterward? cicd-sensor is an open-source sensor that lets every team answer both.

Detection: Detects supply-chain attacks at runtime using process ancestry (e.g. credential access from a process descended from npm install) and correlation across signals (e.g. multiple credential categories read in one job). Baseline rules target patterns seen in real CI/CD attacks, and are opt-out: turn them off if you only want the logs and evidence below.

Logs and evidence: Per run, cicd-sensor can emit logs for review, alerting, and forensics, routed through cicd-sensor Manager to cloud sinks like S3, GCS, and Pub/Sub. The cicd-sensor-action can also produce a graphical report and a build attestation per run. Your data stays under your control. cicd-sensor never sends anything to servers operated by the cicd-sensor project.

Quick start

On GitHub-hosted runners, add the cicd-sensor action as the first step in your workflow.

jobs:
  build:
    runs-on: ubuntu-24.04
    steps:
      - uses: cicd-sensor/cicd-sensor-action@777ddaafc9ec2e09c9779cdb860e75906adc19c2 # v0.0.34

For self-hosted GitHub Actions or GitLab CI/CD, see the User Guide.

Why CI/CD runtime needs this

CI/CD pipelines build, release, deploy, and manage cloud infrastructure, and they hold the cloud credentials, signing keys, and registry tokens to do it. Supply-chain attackers run inside those jobs and disappear with the evidence when the job ends.

Most other runtimes have their open-source defenders: Falco, Tetragon, Tracee, Wazuh, OSQuery. Open-source coverage for CI/CD runtime has lagged behind. Sigstore proved where and how artifacts were built; cicd-sensor preserves what actually ran so teams can detect, respond, and audit.

Feature comparison

Capability cicd-sensor Harden-Runner (Free) Comment
Licensing & deployment
Open source ✅ Yes ✅ Yes
Data privacy ✅ Self-hosted SaaS backend cicd-sensor runs entirely in your infrastructure, so logs and events stay in your environment.
Platform coverage
Private repos ✅ Yes ❌ No
Self-hosted runners ✅ Yes ❌ No Enforcing self-hosted runners enables organization-wide log collection across every job.
GitHub Actions support ✅ Yes ✅ Yes
GitLab CI/CD support ✅ Yes ❌ No
Capabilities
Detection rules ✅ Yes ✅ Yes
Flexible custom rules ✅ Yes 🔶 Limited cicd-sensor rules cover process ancestry, file access, and correlation across signals; Harden-Runner is mainly a network egress allowlist.
Network blocking 🔶 Partial ✅ Yes cicd-sensor kills the process and stops the job on detection instead of filtering traffic like a firewall.
Log export ✅ Yes ❌ No

This table compares the free version of Harden-Runner. StepSecurity's paid platform adds more, such as private repository and self-hosted runner support, dashboards, and policy management.

Based on public information as of May 2026. Corrections welcome.

Supported CI/CD pipelines

Platform Environment Status
GitHub Actions GitHub-hosted runner ✅ Supported
GitHub Actions Self-hosted runner on a machine ✅ Supported
GitHub Actions Actions Runner Controller on Kubernetes 🧪 Preview support
GitLab CI/CD GitLab Runner Docker executor ✅ Supported
GitLab CI/CD GitLab Runner Kubernetes executor 🧪 Preview support
GitLab CI/CD GitLab-hosted runner ❌ Not supported (technical constraints)

Works on both public and private repositories, with no third-party SaaS dependency.

Linux kernel: 5.15 or later on amd64, 6.1 or later on arm64.

Rules

cicd-sensor ships with a set of baseline rules. See the Baseline Rules guide for how they work; the rule definitions themselves live in rules/. You can also write your own rules, or turn the baseline off entirely.

Documentation

  • Getting Started: what cicd-sensor is and how to start.
  • User Guide: deployment paths for GitHub Actions and GitLab CI/CD.
  • Rules: write detection, collection, and correlation rules.
  • Logging: log format delivered by the manager.
  • Attestation predicate: runtime-trace predicate for CI/CD runtime evidence.
  • Developer Guide: agent, eBPF runtime, manager, and rule engine internals.

About the project

A read-only official mirror is published at gitlab.com/cicd-sensor/cicd-sensor. GitHub is the canonical source; the GitLab mirror is synced periodically.

License

Apache License 2.0 (LICENSE). BPF source under internal/agent/bpf/ is dual-licensed GPL-2.0-only OR BSD-2-Clause (details).