Pith. sign in

REVIEW 1 cited by

Security Support in Continuous Deployment Pipeline

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1703.04277 v1 pith:KUX36GX7 submitted 2017-03-13 cs.SE cs.CR

classification cs.SEcs.CR
keywords securitycomponentscontinuoustacticsdeploymentpipelinesecureanalysis
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Continuous Deployment (CD) has emerged as a new practice in the software industry to continuously and automatically deploy software changes into production. Continuous Deployment Pipeline (CDP) supports CD practice by transferring the changes from the repository to production. Since most of the CDP components run in an environment that has several interfaces to the Internet, these components are vulnerable to various kinds of malicious attacks. This paper reports our work aimed at designing secure CDP by utilizing security tactics. We have demonstrated the effectiveness of five security tactics in designing a secure pipeline by conducting an experiment on two CDPs - one incorporates security tactics while the other does not. Both CDPs have been analyzed qualitatively and quantitatively. We used assurance cases with goal-structured notations for qualitative analysis. For quantitative analysis, we used penetration tools. Our findings indicate that the applied tactics improve the security of the major components (i.e., repository, continuous integration server, main server) of a CDP by controlling access to the components and establishing secure connections.

Discussion (0). Sign in to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. A Systematic Literature Review on Continuous Integration and Deployment (CI/CD) for Secure Cloud Computing

    cs.SE 2025-06 conditional novelty 4.0 of 10

    The paper maps 62 existing tools, several proposed frameworks, and recurring security challenges across 66 reviewed papers in cloud-based CI/CD.

Pith tools