Ensure pipelines are automatically scanned for vulnerabilities
ID |
pipeline_scan_vuln |
Severity |
low |
Family |
SCM |
Tags |
non-reachable, sca, security, slsa-4, supply-chain |
Description
Scan for vulnerabilities in build pipelines. It is recommended to use automated tools for detecting known vulnerabilities.
Security
Automatic scanning for vulnerabilities detects known vulnerabilities in pipeline instructions and components, allowing faster patching in case one is found. These vulnerabilities can lead to a potentially massive breach if not handled as fast as possible, as attackers might also be aware of such vulnerabilities.