122 lines
8.4 KiB
Markdown
122 lines
8.4 KiB
Markdown
---
|
|
source_url: https://github.com/cicd-sensor/cicd-sensor
|
|
ingested: 2026-06-30
|
|
sha256: 08058a397765b7e6a7bf7d3d5018ee10cf4a016e082943576f6dee56c5d8a72a
|
|
discovered_from:
|
|
platform: discord
|
|
channel_id: '1477793137064935675'
|
|
channel_name: tw
|
|
message_id: '1521355038830624930'
|
|
author_id: '1477793167486226708'
|
|
posted_at: 2026-06-30T03:21:46.667000000Z
|
|
message_excerpt: 'CI/CD runtime security sensor mentioned with Betterleaks in development pipeline security context.'
|
|
score: 4
|
|
---
|
|
|
|
> 🚧 **Pre-release: Active development.**cicd-sensor is currently in pre-release and under active development. Feedback is very welcome.
|
|
|
|
[](https://github.com/cicd-sensor/cicd-sensor/blob/main/cicd-sensor.png)
|
|
|
|
## cicd-sensor
|
|
|
|
**Think EDR, but for CI/CD Pipelines.**
|
|
Open-source eBPF-powered runtime security sensor for GitHub Actions and GitLab CI/CD.
|
|
→ [Full documentation](https://cicd-sensor.github.io/)
|
|
|
|
[](https://github.com/cicd-sensor/cicd-sensor/blob/main/LICENSE) [](https://camo.githubusercontent.com/920759ad0fbe78e3c756bb908f771cfc9b9f332bfd6d757330dc1473c9aca9a9/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c616e67756167652d476f2d3030414444383f6c6f676f3d676f) [](https://camo.githubusercontent.com/fefe06c66905a8f773dffed48997bf85b135765e4d0c73eb768d70276abfebac/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f506c6174666f726d2d4c696e75782d4643433632343f6c6f676f3d6c696e7578) [](https://camo.githubusercontent.com/be0329c07c65d567c874f00316fc1716017dd065e6dd16b9c20be29760d58d93/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4f70656e253230536f757263652d5965732d627269676874677265656e)
|
|
|
|
---
|
|
|
|
## Demo
|
|
|
|
| [](https://github.com/cicd-sensor/cicd-sensor/blob/main/docs/assets/demo.gif) |
|
|
| --- |
|
|
|
|
<sub>Example: cicd-sensor added to a GitHub Actions workflow. The resulting reports are viewable in the GitHub job summary.</sub>
|
|
|
|
## What cicd-sensor does
|
|
|
|
When a compromised dependency in a CI/CD job steals your cloud credentials and leaks them, would you catch it? Would you have the logs to investigate afterward? cicd-sensor is an open-source sensor that lets every team answer both.
|
|
|
|
**Detection:** Detects supply-chain attacks at runtime using process ancestry (e.g. credential access from a process descended from `npm install`) and correlation across signals (e.g. multiple credential categories read in one job). Baseline rules target patterns seen in real CI/CD attacks, and are opt-out: turn them off if you only want the logs and evidence below.
|
|
|
|
**Logs and evidence:** Per run, cicd-sensor can emit logs for review, alerting, and forensics, routed through cicd-sensor Manager to cloud sinks like S3, GCS, and Pub/Sub. The cicd-sensor-action can also produce a graphical report and a build attestation per run. Your data stays under your control. cicd-sensor never sends anything to servers operated by the cicd-sensor project.
|
|
|
|
## Quick start
|
|
|
|
On GitHub-hosted runners, add the cicd-sensor action as the first step in your workflow.
|
|
|
|
```
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-24.04
|
|
steps:
|
|
- uses: cicd-sensor/cicd-sensor-action@777ddaafc9ec2e09c9779cdb860e75906adc19c2 # v0.0.34
|
|
```
|
|
|
|
For self-hosted GitHub Actions or GitLab CI/CD, see the [User Guide](https://cicd-sensor.github.io/user-guide/overview.html).
|
|
|
|
## Why CI/CD runtime needs this
|
|
|
|
CI/CD pipelines build, release, deploy, and manage cloud infrastructure, and they hold the cloud credentials, signing keys, and registry tokens to do it. Supply-chain attackers run inside those jobs and disappear with the evidence when the job ends.
|
|
|
|
Most other runtimes have their open-source defenders: Falco, Tetragon, Tracee, Wazuh, OSQuery. Open-source coverage for CI/CD runtime has lagged behind. Sigstore proved *where* and *how* artifacts were built; cicd-sensor preserves *what actually ran* so teams can detect, respond, and audit.
|
|
|
|
## Feature comparison
|
|
|
|
| Capability | cicd-sensor | Harden-Runner (Free) | Comment |
|
|
| --- | --- | --- | --- |
|
|
| **Licensing & deployment** | | | |
|
|
| Open source | ✅ Yes | ✅ Yes | |
|
|
| Data privacy | ✅ Self-hosted | SaaS backend | cicd-sensor runs entirely in your infrastructure, so logs and events stay in your environment. |
|
|
| **Platform coverage** | | | |
|
|
| Private repos | ✅ Yes | ❌ No | |
|
|
| Self-hosted runners | ✅ Yes | ❌ No | Enforcing self-hosted runners enables organization-wide log collection across every job. |
|
|
| GitHub Actions support | ✅ Yes | ✅ Yes | |
|
|
| GitLab CI/CD support | ✅ Yes | ❌ No | |
|
|
| **Capabilities** | | | |
|
|
| Detection rules | ✅ Yes | ✅ Yes | |
|
|
| Flexible custom rules | ✅ Yes | 🔶 Limited | cicd-sensor rules cover process ancestry, file access, and correlation across signals; Harden-Runner is mainly a network egress allowlist. |
|
|
| Network blocking | 🔶 Partial | ✅ Yes | cicd-sensor kills the process and stops the job on detection instead of filtering traffic like a firewall. |
|
|
| Log export | ✅ Yes | ❌ No | |
|
|
|
|
<sub>This table compares the free version of Harden-Runner. StepSecurity's paid platform adds more, such as private repository and self-hosted runner support, dashboards, and policy management.</sub>
|
|
|
|
<sub>Based on public information as of May 2026. Corrections welcome.</sub>
|
|
|
|
## Supported CI/CD pipelines
|
|
|
|
| Platform | Environment | Status |
|
|
| --- | --- | --- |
|
|
| GitHub Actions | GitHub-hosted runner | ✅ Supported |
|
|
| GitHub Actions | Self-hosted runner on a machine | ✅ Supported |
|
|
| GitHub Actions | Actions Runner Controller on Kubernetes | 🧪 Preview support |
|
|
| GitLab CI/CD | GitLab Runner Docker executor | ✅ Supported |
|
|
| GitLab CI/CD | GitLab Runner Kubernetes executor | 🧪 Preview support |
|
|
| GitLab CI/CD | GitLab-hosted runner | ❌ Not supported (technical constraints) |
|
|
|
|
Works on both public and private repositories, with no third-party SaaS dependency.
|
|
|
|
Linux kernel: 5.15 or later on `amd64`, 6.1 or later on `arm64`.
|
|
|
|
## Rules
|
|
|
|
cicd-sensor ships with a set of baseline rules. See the [Baseline Rules guide](https://cicd-sensor.github.io/user-guide/baseline-rules.html) for how they work; the rule definitions themselves live in [`rules/`](https://github.com/cicd-sensor/cicd-sensor/blob/main/rules). You can also write your own rules, or turn the baseline off entirely.
|
|
|
|
## Documentation
|
|
|
|
- [Getting Started](https://cicd-sensor.github.io/): what cicd-sensor is and how to start.
|
|
- [User Guide](https://cicd-sensor.github.io/user-guide/overview.html): deployment paths for GitHub Actions and GitLab CI/CD.
|
|
- [Rules](https://cicd-sensor.github.io/user-guide/rules.html): write detection, collection, and correlation rules.
|
|
- [Logging](https://cicd-sensor.github.io/user-guide/logging.html): log format delivered by the manager.
|
|
- [Attestation predicate](https://cicd-sensor.github.io/user-guide/attestation-predicate.html): runtime-trace predicate for CI/CD runtime evidence.
|
|
- [Developer Guide](https://cicd-sensor.github.io/developer-guide/overview.html): agent, eBPF runtime, manager, and rule engine internals.
|
|
|
|
## About the project
|
|
|
|
A read-only official mirror is published at [gitlab.com/cicd-sensor/cicd-sensor](https://gitlab.com/cicd-sensor/cicd-sensor). GitHub is the canonical source; the GitLab mirror is synced periodically.
|
|
|
|
## License
|
|
|
|
Apache License 2.0 ([LICENSE](https://github.com/cicd-sensor/cicd-sensor/blob/main/LICENSE)). BPF source under `internal/agent/bpf/` is dual-licensed `GPL-2.0-only OR BSD-2-Clause` ([details](https://github.com/cicd-sensor/cicd-sensor/blob/main/internal/agent/bpf/README.md#licensing)).
|