CI/CD Cybersecurity SIG

Embed cybersecurity into your CI/CD pipelines to establish robust industry-standard safeguards, ensuring fast and secure software updates.

CI/CD Cybersecurity SIG from The Continuous Delivery Foundation

This CI/CD Cybersecurity Guide was put together by the Continuous Delivery Foundation’s CI/CD Cybersecurity SIG, which plays a pivotal role in advancing CI/CD security and supporting organizations in meeting modern cybersecurity demands. The group focuses its efforts on integration frameworks, best practices, and emerging tooling, to address the critical need to embed security into every stage of the CI/CD pipeline, ensuring a resilient and secure software development lifecycle.

Three Cybersecurity Phases

CI/CD Cybersecurity Guide is segmented into three 3 major chapters:

  1. Code and Prebuild

Building security into Code and Prebuild steps of the CI/CD pipeline.

Read more

  1. Build and Deploy

Building security into the Build and Deploy steps of the CI/CD pipeline.

Read more

  1. Post Deploy

Building security into Post Deploy steps such as testing, SBOM generation, and continuous vulnerabiity management.

Read more

Contribute to the Guide

Join us and bring your knowledge to build cybersecurity into CI/CD workflows.

About the CD Foundation

Continuous Delivery Foundation (CDF) serves as the vendor-neutral home of many of the fastest-growing projects for continuous integration/continuous delivery (CI/CD). It fosters vendor-neutral collaboration between the industry’s top developers, end users and vendors to further CI/CD practices and industry specifications. Its mission is to grow and sustain projects that are part of the broad and growing continuous delivery ecosystem. The CDF is part of https://www.linuxfoundation.org/ home to both the CNCF and OpenSSF.