CI/CD Pipeline Security

The riskiest code in your repo is often the build file

Pipelines run with broad permissions, pull in third-party actions, and handle your secrets, yet they rarely get reviewed the way application code does. Pragma Core scans your pipeline definitions every day across five platforms, classifies what it finds by severity, and tracks each issue from the day it appears to the day it is fixed.

Scan your pipelines View all features

From a build file to a tracked finding

Enable scanning on a repository and the platform takes it from there. No SCM token to wire up, no pipeline to instrument, no agent to install.

1
Refresh the checkout
The scan job pulls the latest commit on the protected branch itself, so an enable-and-forget repository still gets scanned against today's pipeline files, not a stale copy.
2
Run the engine
The checkov engine inspects every pipeline definition across the five supported platforms in a single pass and reports each failed check with its file, resource, and a remediation guideline.
3
Classify and diff
Each check is assigned a severity from a curated map, then diffed by fingerprint against the existing findings. New issues open, missing ones close, and reappearing ones reopen on the same row.
4
Triage and push
Acknowledge accepted risks, watch fixed issues drop out of the default view, and push anything that needs an owner straight to Jira with the link kept across rescans.

A snapshot of one workspace

A real org runs pipelines on more than one platform and carries a tail of misconfigurations at any moment. Here is what the dashboard collapses that into.

Failed checks by platform

Sample workspace

Open findings grouped by CI platform and broken down by severity. Hover any bar to see the mix. The platform owns the severity classification, since the open-source engine ships every check without one.

Top open findings

Latest 5

Ranked by severity, with the check ID and the file each one lives in. The fingerprint deliberately ignores line numbers, so editing code above a finding does not churn the row.

CheckSeverityIssueFile
CKV_GHA_7CriticalShell injection via untrusted input.github/workflows/ci.yml
CKV_GHA_2HighWrite-all token permissions.github/workflows/release.yml
CKV_GHA_5HighSecret piped to curl.gitlab-ci.yml
CKV_GHA_4MediumAction pinned to a mutable tag.github/workflows/ci.yml
CKV_DOCKER_7MediumBase image uses the latest tagazure-pipelines.yml

Built for the way pipelines actually drift

Five platforms, one pass
GitHub Actions, GitLab CI, Azure Pipelines, Bitbucket Pipelines, and CircleCI are all inspected in a single scan of your working tree. No per-platform setup and no SCM token required.
Severity you can trust
The open-source engine reports every check without a severity, so the platform owns the classification. Shell injection and reverse shells map to critical, write-all permissions and secret exfiltration to high, mutable image tags to medium.
Findings track over time
Each finding is diffed by a fingerprint that ignores line numbers. New issues open, fixed ones drop out of the default view but stay filterable, and a reappearing issue reopens the same row instead of spamming you with a new one.
Scanned every day
Every repository with pipeline scanning enabled is rescanned daily on a dedicated queue, so a freshly merged misconfiguration shows up the next morning. You can also trigger a scan by hand whenever you want.
Push to Jira
Send any finding to Jira with one click. The issue key and URL are stored on the finding and survive the fixed and reopen cycle, so the ticket stays linked even if the misconfiguration comes back.
Never falsely clean
If the engine binary is missing or the output cannot be parsed, the scan is marked failed and surfaced, never reported as a clean pass. A green result means the pipelines were actually inspected.

Wherever your builds run

GitHub Actions GitLab CI Azure Pipelines Bitbucket Pipelines CircleCI

Supply-chain attacks love a permissive pipeline

Close the gap attackers aim for
A workflow with write-all permissions, an action pinned to a mutable tag, a secret echoed into a log. These are the footholds behind real supply-chain incidents, and they hide in files most reviews never open.
Pin your third-party actions
Every unpinned action is a trust decision you renew on every build. The scanner flags actions referenced by a mutable tag so you can pin them to a commit and stop inheriting whatever the maintainer pushes next.
Keep secrets out of logs
Secrets piped into curl, printed for debugging, or exposed through over-broad permissions get caught and ranked high, so the most dangerous handling of your credentials rises to the top of the list.
Prove the trend to auditors
Because findings persist as history rather than being deleted and recreated, you can show exactly when an issue appeared, when it was acknowledged, and when it was fixed. A clean audit trail without spreadsheets.

Lock down your pipelines today

Enable pipeline scanning on a repository and get a clear read on the misconfigurations hiding in your build files.

Have questions? Get in touch →