Files
llm-wiki/raw/articles/cicd-sensor-2026.md
T
2026-06-30 22:22:00 +09:00

122 lines
8.4 KiB
Markdown

---
source_url: https://github.com/cicd-sensor/cicd-sensor
ingested: 2026-06-30
sha256: 08058a397765b7e6a7bf7d3d5018ee10cf4a016e082943576f6dee56c5d8a72a
discovered_from:
platform: discord
channel_id: '1477793137064935675'
channel_name: tw
message_id: '1521355038830624930'
author_id: '1477793167486226708'
posted_at: 2026-06-30T03:21:46.667000000Z
message_excerpt: 'CI/CD runtime security sensor mentioned with Betterleaks in development pipeline security context.'
score: 4
---
> 🚧 **Pre-release: Active development.**cicd-sensor is currently in pre-release and under active development. Feedback is very welcome.
[![cicd-sensor logo](https://github.com/cicd-sensor/cicd-sensor/raw/main/cicd-sensor.png)](https://github.com/cicd-sensor/cicd-sensor/blob/main/cicd-sensor.png)
## cicd-sensor
**Think EDR, but for CI/CD Pipelines.**
Open-source eBPF-powered runtime security sensor for GitHub Actions and GitLab CI/CD.
→ [Full documentation](https://cicd-sensor.github.io/)
[![License](https://camo.githubusercontent.com/a549a7a30bacba7bfceebdc207a8e86c3f2c02995a2527640dca30048fd2b64e/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c6963656e73652d417061636865253230322e302d626c75652e737667)](https://github.com/cicd-sensor/cicd-sensor/blob/main/LICENSE) [![Language](https://camo.githubusercontent.com/920759ad0fbe78e3c756bb908f771cfc9b9f332bfd6d757330dc1473c9aca9a9/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c616e67756167652d476f2d3030414444383f6c6f676f3d676f)](https://camo.githubusercontent.com/920759ad0fbe78e3c756bb908f771cfc9b9f332bfd6d757330dc1473c9aca9a9/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c616e67756167652d476f2d3030414444383f6c6f676f3d676f) [![Platform](https://camo.githubusercontent.com/fefe06c66905a8f773dffed48997bf85b135765e4d0c73eb768d70276abfebac/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f506c6174666f726d2d4c696e75782d4643433632343f6c6f676f3d6c696e7578)](https://camo.githubusercontent.com/fefe06c66905a8f773dffed48997bf85b135765e4d0c73eb768d70276abfebac/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f506c6174666f726d2d4c696e75782d4643433632343f6c6f676f3d6c696e7578) [![Open Source](https://camo.githubusercontent.com/be0329c07c65d567c874f00316fc1716017dd065e6dd16b9c20be29760d58d93/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4f70656e253230536f757263652d5965732d627269676874677265656e)](https://camo.githubusercontent.com/be0329c07c65d567c874f00316fc1716017dd065e6dd16b9c20be29760d58d93/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4f70656e253230536f757263652d5965732d627269676874677265656e)
---
## Demo
| [![cicd-sensor GitHub Actions demo](https://github.com/cicd-sensor/cicd-sensor/raw/main/docs/assets/demo.gif)](https://github.com/cicd-sensor/cicd-sensor/blob/main/docs/assets/demo.gif) |
| --- |
<sub>Example: cicd-sensor added to a GitHub Actions workflow. The resulting reports are viewable in the GitHub job summary.</sub>
## What cicd-sensor does
When a compromised dependency in a CI/CD job steals your cloud credentials and leaks them, would you catch it? Would you have the logs to investigate afterward? cicd-sensor is an open-source sensor that lets every team answer both.
**Detection:** Detects supply-chain attacks at runtime using process ancestry (e.g. credential access from a process descended from `npm install`) and correlation across signals (e.g. multiple credential categories read in one job). Baseline rules target patterns seen in real CI/CD attacks, and are opt-out: turn them off if you only want the logs and evidence below.
**Logs and evidence:** Per run, cicd-sensor can emit logs for review, alerting, and forensics, routed through cicd-sensor Manager to cloud sinks like S3, GCS, and Pub/Sub. The cicd-sensor-action can also produce a graphical report and a build attestation per run. Your data stays under your control. cicd-sensor never sends anything to servers operated by the cicd-sensor project.
## Quick start
On GitHub-hosted runners, add the cicd-sensor action as the first step in your workflow.
```
jobs:
build:
runs-on: ubuntu-24.04
steps:
- uses: cicd-sensor/cicd-sensor-action@777ddaafc9ec2e09c9779cdb860e75906adc19c2 # v0.0.34
```
For self-hosted GitHub Actions or GitLab CI/CD, see the [User Guide](https://cicd-sensor.github.io/user-guide/overview.html).
## Why CI/CD runtime needs this
CI/CD pipelines build, release, deploy, and manage cloud infrastructure, and they hold the cloud credentials, signing keys, and registry tokens to do it. Supply-chain attackers run inside those jobs and disappear with the evidence when the job ends.
Most other runtimes have their open-source defenders: Falco, Tetragon, Tracee, Wazuh, OSQuery. Open-source coverage for CI/CD runtime has lagged behind. Sigstore proved *where* and *how* artifacts were built; cicd-sensor preserves *what actually ran* so teams can detect, respond, and audit.
## Feature comparison
| Capability | cicd-sensor | Harden-Runner (Free) | Comment |
| --- | --- | --- | --- |
| **Licensing & deployment** | | | |
| Open source | ✅ Yes | ✅ Yes | |
| Data privacy | ✅ Self-hosted | SaaS backend | cicd-sensor runs entirely in your infrastructure, so logs and events stay in your environment. |
| **Platform coverage** | | | |
| Private repos | ✅ Yes | ❌ No | |
| Self-hosted runners | ✅ Yes | ❌ No | Enforcing self-hosted runners enables organization-wide log collection across every job. |
| GitHub Actions support | ✅ Yes | ✅ Yes | |
| GitLab CI/CD support | ✅ Yes | ❌ No | |
| **Capabilities** | | | |
| Detection rules | ✅ Yes | ✅ Yes | |
| Flexible custom rules | ✅ Yes | 🔶 Limited | cicd-sensor rules cover process ancestry, file access, and correlation across signals; Harden-Runner is mainly a network egress allowlist. |
| Network blocking | 🔶 Partial | ✅ Yes | cicd-sensor kills the process and stops the job on detection instead of filtering traffic like a firewall. |
| Log export | ✅ Yes | ❌ No | |
<sub>This table compares the free version of Harden-Runner. StepSecurity's paid platform adds more, such as private repository and self-hosted runner support, dashboards, and policy management.</sub>
<sub>Based on public information as of May 2026. Corrections welcome.</sub>
## Supported CI/CD pipelines
| Platform | Environment | Status |
| --- | --- | --- |
| GitHub Actions | GitHub-hosted runner | ✅ Supported |
| GitHub Actions | Self-hosted runner on a machine | ✅ Supported |
| GitHub Actions | Actions Runner Controller on Kubernetes | 🧪 Preview support |
| GitLab CI/CD | GitLab Runner Docker executor | ✅ Supported |
| GitLab CI/CD | GitLab Runner Kubernetes executor | 🧪 Preview support |
| GitLab CI/CD | GitLab-hosted runner | ❌ Not supported (technical constraints) |
Works on both public and private repositories, with no third-party SaaS dependency.
Linux kernel: 5.15 or later on `amd64`, 6.1 or later on `arm64`.
## Rules
cicd-sensor ships with a set of baseline rules. See the [Baseline Rules guide](https://cicd-sensor.github.io/user-guide/baseline-rules.html) for how they work; the rule definitions themselves live in [`rules/`](https://github.com/cicd-sensor/cicd-sensor/blob/main/rules). You can also write your own rules, or turn the baseline off entirely.
## Documentation
- [Getting Started](https://cicd-sensor.github.io/): what cicd-sensor is and how to start.
- [User Guide](https://cicd-sensor.github.io/user-guide/overview.html): deployment paths for GitHub Actions and GitLab CI/CD.
- [Rules](https://cicd-sensor.github.io/user-guide/rules.html): write detection, collection, and correlation rules.
- [Logging](https://cicd-sensor.github.io/user-guide/logging.html): log format delivered by the manager.
- [Attestation predicate](https://cicd-sensor.github.io/user-guide/attestation-predicate.html): runtime-trace predicate for CI/CD runtime evidence.
- [Developer Guide](https://cicd-sensor.github.io/developer-guide/overview.html): agent, eBPF runtime, manager, and rule engine internals.
## About the project
A read-only official mirror is published at [gitlab.com/cicd-sensor/cicd-sensor](https://gitlab.com/cicd-sensor/cicd-sensor). GitHub is the canonical source; the GitLab mirror is synced periodically.
## License
Apache License 2.0 ([LICENSE](https://github.com/cicd-sensor/cicd-sensor/blob/main/LICENSE)). BPF source under `internal/agent/bpf/` is dual-licensed `GPL-2.0-only OR BSD-2-Clause` ([details](https://github.com/cicd-sensor/cicd-sensor/blob/main/internal/agent/bpf/README.md#licensing)).