You scan your application code. You scan your dependencies. You scan your containers.

You have never scanned the thing that has access to all of them.

Your CI pipeline holds your deploy keys. Your registry credentials. Your cloud tokens. Your signing secrets. It runs on every push, it runs third-party code you did not write, and it runs with more privilege than any developer on your team.

It is the most privileged machine you own. And for most projects, it is completely unreviewed.

Why Attackers Target The Pipeline