Blogs

Securing CI/CD for an open source project: Locking down dependencies

Cncf

This is the second post in a three-part series on how Cilium hardens its CI/CD pipeline. Part 1 covered access control: who can trigger builds and what code CI is allowed to execute.

Visit Site

Blogs Cncf

BlogsSecuring CI/CD for an open source project: Controlling who runs whatCncf BlogsSecuring GitHub Actions CI dependencies: Recipe cardCncf BlogsInspektor Gadget: Results from the first security auditCncf BlogsFrom 40 seconds to under 10: rebuilding incident detection on OpenTelemetry, Apache Kafka, andCncf BlogsExploring AI, observability and community at OSS Summit Korea 2025Cncf BlogsHow to Get the Most Out of KubeCon + CloudNativeCon Europe 2026Cncf BlogsSecuring the Software Supply Chain: Atomist Joins DockerDocker BlogsDockerCon 2022 Registration Is Now OpenDocker ResearchVibe physics: The AI grad studentAnthropic NewsCNCF Backstage Documentary Highlights Project Evolution from Development to Global Open SourceCncf BlogsNetwork boundary for AI agents using NGINX and OpenTelemetryCncf Blogsetcd-operator joins Cozystack with a new v1alpha2 APICncf BlogsSelf-hosted human and machine identities in Keycloak 26.4Cncf Blogs10 Proven Ways to Get Clients in Real Estate TodayHeygen ResourcesSpeed Insights OverviewVercel BlogsSecuring data in your Next.js app with Okta and OpenFGAVercel ResourcesCreate a flag | Vercel REST APIVercel BlogsPromoting Open Source with Netlify Snippet InjectionNetlify Products & ServicesHow GitBook supported open source in 2025Gitbook Products & ServicesNew in GitBook: Free open source documentation that helps fund your projectGitbook