13 years from Java developer to DevSecOps. Today I am tech lead of the team that runs GitHub and GitHub Actions at a Fortune 10 healthcare company, where we are building a SLSA Build Level 3 pipeline.
Six links between a developer's keyboard and production. Pick a link to see the risk, a real attack on it, and the work I have done to protect it.
Someone pushes code they should not. One stolen token is enough.
Attackers pushed backdoored commits to PHP's git server under the names of real maintainers.
You run code you did not write and did not read.
A trusted maintainer slipped a backdoor into a compression library that SSH depends on.
The build system changes the output and nobody sees it.
Malware planted in the build system was signed and shipped to about 18,000 customers.
The image you deploy is not the image you built.
A mutable tag like :latest gets repointed to a different image after review.
Someone changes what runs in the cluster by hand.
A direct kubectl edit skips review and leaves no trace in git.
One weak service or exposed app reaches everything else.
A container with a shell, root, and host access breaks out to the node.