ciso.diy
GitHub / GitLab Security Posture Kit preview
Compliance GitHubGitLabCI/CDsupply chain

GitHub / GitLab Security Posture Kit

What a leaked CI/CD secret, a poisoned Action tag or an overprivileged pipeline token can actually reach, and whether you would know before your published packages did. The 2025–2026 supply-chain incidents needed no compromised identity at all, and this kit scores the workflow mechanics that let them through.

What this actually gives you

  • Nobody's password was stolen. The 2025–2026 supply-chain incidents reached production through a mutable Action tag, an elevated-context trigger or a poisoned cache — one of them publishing malicious packages with valid signed provenance. This kit scores the workflow mechanics, not the credentials.
  • One thread ties three of the four headline incidents together: a workflow that runs contributor-controlled code with the repository's secrets and write token. File 03 surfaces it as the single highest-leverage finding.
  • Since the April 2025 unbundling, private-repo secret scanning is a paid per-committer add-on. "GitHub has security built in" is often wrong, and file 06 makes it the headline.
  • Push protection never scans backwards. File 05 has a section no other kit in the series has, for secrets already sitting in repository history.
  • File 07 is dual-audience — plain language for leadership, and the repos, workflows and token types for the engineering team — because this kit's buyer is DevSecOps as much as vCISO.

Nobody's password was stolen. The supply-chain incidents that defined 2025–2026 — a compromised tag on a widely used changed-files Action reaching over twenty thousand repositories; a campaign that pulled thousands of secrets from hundreds of accounts; a self-replicating worm across tens of thousands of repositories and npm package versions; a poisoned build cache that lifted OIDC tokens from runner memory and published dozens of malicious packages with valid signed provenance — reached production through workflow mechanics, not credentials. The entry point was a mutable Action tag, an elevated-context trigger, or a cache. The other four posture kits ask what a compromised account can reach. This one asks what a pipeline will do with untrusted code and trusted permissions.

One thread ties three of the four headline incidents together. A workflow triggered by pull_request_target or an equivalent elevated-context event runs contributor-controlled code with the repository's secrets and write token. File 03 surfaces that as the single highest-leverage finding in the tool rather than treating each incident as its own pattern, and weights third-party Actions and workflow triggers above every other surface.

A different buyer, and the kit is shaped for them. This is a DevSecOps and platform-engineering tool as much as a vCISO one. File 07 is dual-audience: a plain-language section for leadership and a technical-detail section naming the repos, workflows and token types affected, so the engineering lead can start remediation without re-running the assessment. It is the one place in the series where the template shape changed for the reader, not just the content.

Both platforms have a real CIS benchmark, and file 04 cites them. Unlike Okta and Salesforce, GitHub and GitLab each have a dedicated, maintained CIS Foundations Benchmark, so the hardening checklist maps to real references with platform applicability noted per row.

The detection finding is a licensing surprise. Since the April 2025 unbundling of Advanced Security into Secret Protection and Code Security, private-repository secret scanning is a paid per-committer add-on. Organisations that assume "GitHub has security built in" are often wrong, and file 06 makes it the headline. And push protection never scans backwards: file 05 has a section no other kit in the series has, for secrets already sitting in repository history.

What you get

01 Assessment Methodology (DOCX) — why the buyer and the risk model differ, the five modules, GitHub-first with GitLab equivalents per control, run order, cross-links and assumptions.

02 Identity & Access Review Workbook (XLSX) — Org-Level Access (2FA/SSO enforcement, owner count, outside collaborators, domain verification), Token Strategy (classic PATs to fine-grained, OIDC federation for cloud auth, GitHub App scopes, maximum token lifetime), Team & Repo Permissions (team-based access, CODEOWNERS) and Self-Hosted Runner Hygiene (isolation, ephemerality, registration, exclusion from fork-triggered workflows) — 16 weighted controls rolling into one score.

03 Blast Radius Scoring Tool (XLSX) — the flagship module. Select plan and Advanced Security licensing, inventory org-level secrets and active Actions first, answer the control questions across secrets & tokens, third-party Actions, workflow triggers and detection — default GITHUB_TOKEN scope, org-secret scoping, SHA pinning, allow-lists, elevated-context triggers — and get one score, a band on the same bands as the sibling kits, and a closure list ranked by risk-weighted points.

04 CIS-Aligned Hardening Checklist (XLSX) — Branch & Code Protection, CI-CD Hardening, Authentication & Token Management, Audit Logging & Backups, scored gap-to-target with a hardening percentage per family.

05 Data Governance Review (DOCX) — repository visibility process, branch protection and CODEOWNERS coverage, dependency and SBOM tracking, and secrets in repository history.

06 Detection Readiness Matrix (XLSX) — audit log, secret scanning by tier, Code Security, Dependabot and Actions run logs, each row stating whether it covers private repositories.

07 Executive Summary Template (DOCX) — dual-audience, as above.

vcs01.json — scoring bands, surfaces, plan components, the two CIS benchmarks and the module map.

A worked example throughout. Wrenfield Software Co., a fictional B2B SaaS company on GitHub Enterprise Cloud without Advanced Security, with self-hosted runners on a subset of pipelines and most workflows inheriting a read-write default token.

Where it sits. The fifth kit of the Cloud Identity Posture set with the M365, Google Workspace, Okta and Salesforce kits; the set of five is cheaper than buying them separately. If the pipeline moves data into a warehouse or feeds an AI pipeline from one, the Enterprise Data Warehouse & AI Pipeline Security Posture Kit assesses what it lands in. If the pipeline holds AWS credentials, the AWS Cloud Infrastructure Posture Kit assesses the account they reach. If the pipeline deploys to a cluster, the Docker & Kubernetes Security Posture Kit follows the chain from the image it builds to the cloud account behind the cluster. If the pipeline builds a mobile app, the Android and iOS posture kits assess what it ships. For a team whose app was built with an AI builder on Supabase, Vercel or Cloudflare, the Vibe-Coded App Security Posture Kit covers the app stack this pipeline ships, and the pair is cheaper than buying both. It is the posture-assessment layer in front of the build layer: Pillar 02 — the DevSecOps Risk Register and Bug-Hunter Automation are where the findings become work. The IR Runbook Library is the response layer — runbook 07 is a supply-chain compromise. Run it against a vendor's pipeline with the TPRM Program Kit; hand file 07's leadership section to the Director's Cyber Oversight Kit.

Written against GitHub Enterprise Cloud and GitLab terminology, plan names and pricing as of Q3 2026, and public incident reporting to the same date. Not a SAST or SCA replacement — it assesses the pipeline's configuration and permission posture, not the code inside it. Platform pricing is marked verify. Scores are a prioritisation aid, not a certification, an audit opinion or an insurance-underwriting determination. Not legal advice.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-09
Pages 7