SecDocker: Hardening the Continuous Integration Workflow

  • Fernández González D
  • Rodríguez Lera F
  • Esteban G
  • et al.
N/ACitations
Citations of this article
17Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Current Continuous Integration (CI) processes face significant intrinsic cybersecurity challenges. The idea is not only to solve and test formal or regulatory security requirements of source code but also to adhere to the same principles to the CI pipeline itself. This paper presents an overview of current security issues in CI workflow. It designs, develops, and deploys a new tool for the secure deployment of a container-based CI pipeline flow without slowing down release cycles. The tool, called SecDocker for its Docker-based approach, is publicly available in GitHub. It implements a transparent application firewall based on a configuration mechanism avoiding issues in the CI workflow associated with intended or unintended container configurations. Integrated with other DevOps Engineers tools, it provides feedback from only those scenarios that match specific patterns, addressing future container security issues.

Cite

CITATION STYLE

APA

Fernández González, D., Rodríguez Lera, F. J., Esteban, G., & Fernández Llamas, C. (2022). SecDocker: Hardening the Continuous Integration Workflow. SN Computer Science, 3(1). https://doi.org/10.1007/s42979-021-00939-4

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free