Osama Hamad
Baghdad, Iraq
CI/CD & Software Supply Chain Security Assessment
(0) Remote 2 weeks ago
1000 $
Security review of your source-control organization, CI/CD workflows, dependencies, build process and software supply chain.
I will review your software development and deployment pipeline for security weaknesses that could allow unauthorized code changes, credential exposure, build compromise or insecure deployment.
The assessment covers the security boundaries between developers, source control, CI/CD infrastructure, dependencies, cloud environments and production deployment.
Review can include:
GitHub organization security
Repository permissions
Branch protection
Pull-request controls
CI/CD workflow security
Workflow permissions
Secrets handling
CI/CD credentials
Third-party Actions/integrations
Dependency security
Build integrity
Artifact handling
Deployment permissions
Cloud authentication
Environment separation
Supply-chain security controls
You receive:
CI/CD security assessment
Prioritized weaknesses
Risk explanation
Recommended hardening
Configuration recommendations
Supply-chain security improvement plan
Scope note:
Price depends on the number of repositories, workflows, deployment environments and integrations included.
I will review your software development and deployment pipeline for security weaknesses that could allow unauthorized code changes, credential exposure, build compromise or insecure deployment.
The assessment covers the security boundaries between developers, source control, CI/CD infrastructure, dependencies, cloud environments and production deployment.
Review can include:
GitHub organization security
Repository permissions
Branch protection
Pull-request controls
CI/CD workflow security
Workflow permissions
Secrets handling
CI/CD credentials
Third-party Actions/integrations
Dependency security
Build integrity
Artifact handling
Deployment permissions
Cloud authentication
Environment separation
Supply-chain security controls
You receive:
CI/CD security assessment
Prioritized weaknesses
Risk explanation
Recommended hardening
Configuration recommendations
Supply-chain security improvement plan
Scope note:
Price depends on the number of repositories, workflows, deployment environments and integrations included.
Please sign in as a customer to give your feedback

