Join our Newsletter — 33% off our NHI Course

Secrets sprawl in CI/CD pipelines: what should teams fix first?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: CI/CD pipelines concentrate secrets because they gate production access, scale automation, and influence engineering practice, according to Defakto Security, while GitGuardian data shows leaked secrets rose by 23 million from 2023 to 2024 and 70% of 2022 leaks remained active in 2025. The real control problem is treating long-lived secrets as governable once pipelines become the access layer for everything else.

Editorial analysis by NHI Mgmt Group, based on content published by Defakto Security: “Want Control Over Secrets? Start with Your Strategic Control Point: CI/CD.”.

By the numbers:

  • The number of leaked secrets increased by 23 million from 2023 to 2024.
  • 70% of leaked secrets detected in 2022 remain active in 2025.

Key questions

Q: What breaks when CI/CD pipelines rely on static secrets?

A: Static secrets create a reusable attack path into production infrastructure.

Q: Why do CI/CD pipelines create secret governance risk?

A: Because they combine stored credentials, automated execution, and broad operational access in one place.

Q: How do teams know whether secret sprawl is getting better?

A: Look for fewer static credentials in pipelines, less secret reuse across jobs, and a shrinking set of exceptions that still require manual handling.

Practitioner guidance

  • Audit CI/CD secret dependencies Map every pipeline, runner, and deployment action that still depends on API keys, passwords, or shared tokens so you can see where static credentials remain part of the delivery path.
  • Replace reusable credentials with short-lived identities Move pipelines toward task-scoped identities and attested access so the pipeline requests what it needs at execution time instead of storing secrets for reuse.
  • Centralise pipeline identity governance Define one policy for how CI/CD identities are issued, scoped, reviewed, and revoked across teams so platform teams can roll out changes consistently.

Bottom line: CI/CD pipelines are where secrets concentrate because they connect code changes to production access and shared automation.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

CI/CD is the secrets governance choke point: Secrets sprawl becomes operationally material when pipelines are the place where access begins, not just where credentials are stored. That makes the pipeline the most efficient place to discover, constrain, and phase out long-lived secrets. For identity teams, the strategic question is not how to manage every leaked secret equally, but where a single control point can reshape the largest share of access behaviour.

A few things that frame the scale:

  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
  • 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.

A question worth separating out:

Q: Should organisations prioritise pipeline identity before broader secrets cleanup?

A: Yes, when CI/CD is the gateway to production, because changes there affect many downstream teams at once. Fixing pipeline identity first gives faster risk reduction than chasing individual leaked secrets one by one. That sequencing is especially useful where platform teams can enforce one pattern centrally.

👉 Read our full editorial: CI/CD pipelines as the control point for secrets sprawl


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.