Dzone iconDzoneSep 9, 2026 ~1 min source read

Pipelines on Fire: Why Your CI/CD Tools Are the New Cyber Battlefield

When the platforms holding that much code accelerate their vulnerability disclosures quarter over quarter, that's not noise. Here's the number that should reorder every security roadmap for 2026: major DevOps platforms — GitHub, GitLab, Azure DevOps, and Atlassian's Jira and Bitbucket — patched 236 vulnerabilities in 2025, according to GitProtect's DevOps Threats Unwrapped report.

Pipelines on Fire: Why Your CI/CD Tools Are the New Cyber Battlefield

Share this story

Send the public story page.

Useful takeaways from this story.

Fifteen years in, and the conversation I have most often with security leads still starts the same way: how's your perimeter, how's your endpoint coverage, how's your SOC staffed?

Almost nobody opens with "how's your pipeline." That's the gap I want to talk about, because 2025 was the year the gap turned into a crater.

Of those, 59% were rated high or critical: 14 critical, 126 high, 75 medium, 21 low.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Fifteen years in, and the conversation I have most often with security leads still starts the same way: how's your perimeter, how's your endpoint coverage, how's your SOC staffed? Almost nobody opens with "how's your pipeline." That's the gap I want to talk about, because 2025 was the year the gap turned into a crater. Of those, 59% were rated high or critical: 14 critical, 126 high, 75 medium, 21 low.

How it works

  • November 2025 alone produced 36 patched vulnerabilities — 15% of the entire year's total in one month.
  • GitHub alone hosts more than 180 million developers across 630 million repositories.
  • When the platforms holding that much code accelerate their vulnerability disclosures quarter over quarter, that's not noise.

Details worth keeping

Here's the number that should reorder every security roadmap for 2026: major DevOps platforms — GitHub, GitLab, Azure DevOps, and Atlassian's Jira and Bitbucket — patched 236 vulnerabilities in 2025, according to GitProtect's DevOps Threats Unwrapped report. That's a trend with a direction (DevOps.com, SecurityBrief).

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app