Jacob.Frericks
Staff DevOps Engineer · DevSecOps · Software supply chain

I build secure pipelines developers actually use.

13 years from Java developer to DevSecOps. Today I am tech lead of the team that runs GitHub and GitHub Actions at a Fortune 10 healthcare company, where we are building a SLSA Build Level 3 pipeline.

DrawingThe paved road, commit to cluster
Dwg no.JF-001
Rev0.4.0
Drawn byJ. Frericks
Since2013
StatusUnder construction
Section A

The chain

Six links between a developer's keyboard and production. Pick a link to see the risk, a real attack on it, and the work I have done to protect it.

Link 03 · Risk

Build

The build system changes the output and nobody sees it.

Real attack

SolarWinds (2020)

Malware planted in the build system was signed and shipped to about 18,000 customers.

My work

Controls

  • SLSA Build L3 pipeline (in progress)Tech lead · Fortune 10 healthcare company
  • Reusable security workflows for GitHub ActionsMain designer · Fortune 10 healthcare company
  • Security Orb for CircleCIFortune 10 healthcare company
Section B

SLSA ladder

SLSA is a public scale for build integrity. Each level adds a guarantee and stops a new kind of attack. My team is building toward the top one at work, and this site already ships at it.

L3Build

Hardened build platform

Builds run isolated. Signing keys never reach user code, so provenance cannot be forged.

Stops: tampering inside the build itself, by another build or a stolen credential. Example: SolarWinds (2020), where malware in the build system shipped inside signed updates.

✓ This site · v0.4.0◐ Enterprise pipeline · tech lead
L2Build

Signed provenance

A hosted builder signs a record of what it built and from which source.

Stops: an artifact swapped after the build, because the signature no longer matches. Example: Codecov (2021), where attackers changed a published script after it was built.

L1Build

Provenance exists

Each artifact ships with a record of how it was built.

Stops: mistakes, like a release built from the wrong branch or with the wrong steps.

L0Build

No guarantees

Where most build systems start.

Stops: nothing. You trust the artifact because of where you downloaded it.

Groundwork: from 2022 to 2024 I built a pipeline that attached signed SBOM attestations to every container with cosign. That proved what was inside an image. Provenance adds proof of how it was built.

Verify this site

Every release of this site is one signed bundle. Download the latest release and check it yourself.

  • SLSA Build L3 provenance on every releasePASS
  • Release bundle signed with SigstorePASS
  • Actions pinned by SHA, npm pinned by lockfilePASS
  • Secret, SAST, SCA, and workflow scans on every PRPASS
  • OpenSSF Scorecard publishedPASS
  • Content Security PolicyNEXT
  • SBOM published with each releaseNEXT
Run it yourself
$ gh release download --repo JacobFrericks/jacobfrericks.com --pattern 'site.*'
$ slsa-verifier verify-artifact site.tar \
    --provenance-path site.intoto.jsonl \
    --source-uri github.com/JacobFrericks/jacobfrericks.com

Verified build using builder "https://github.com/slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@refs/tags/v2.1.0"
Verifying artifact site.tar: PASSED

PASSED: SLSA verification passed
Section C

Projects

Each card is tagged with the chain link it protects. Filter by link.

Link 03 · Build◐ in progress

SLSA Build L3 pipeline

Fortune 10 healthcare company · 2026 – now · Tech lead
Problem
Builds could not prove where an artifact came from or that nothing changed it on the way.
Fix
Leading a new GitHub Actions build pipeline that produces signed provenance on an isolated builder.
Result
In progress. Target: SLSA Build Level 3.
GitHub ActionsSigstoreSLSA
Link 01 · Source● shipped

GitHub & Actions platform

Fortune 10 healthcare company · 2026 – now · Tech lead
Problem
Source control and CI for the whole company need one owner and one set of rules.
Fix
Lead the team that administers GitHub Enterprise (EMU) and GitHub Actions.
Result
One managed home for code and pipelines, with accounts tied to company identity.
GitHub EMUGitHub Actions
Link 03 · Build● shipped

Security workflows for GitHub Actions

Fortune 10 healthcare company · 2024 – now · Main designer
Problem
Each team wired up security scanners on its own, or not at all.
Fix
Designed and built most of the reusable workflows that run security tools and attest the results.
Result
Security scanning is part of the default path, not extra work.
GitHub ActionsPython
Link 03 · Build● shipped

Security Orb

Fortune 10 healthcare company · 2022 – 2024 · Creator
Problem
Teams on CircleCI had no shared way to run security tools and keep the results.
Fix
Built the Security Orb: reusable Python code that connects security tools and attests their results.
Result
CircleCI teams got the secure path without writing glue code.
CircleCIPython
Link 04 · Artifact● shipped

SBOM + cosign attestation

Fortune 10 healthcare company · 2022 – 2024
Problem
Nobody could prove what was inside a container or which checks it passed.
Fix
Built a pipeline that generates an SBOM and attaches signed attestations to each image with cosign.
Result
Any image can be checked for its contents and scan results before deploy.
cosignSBOMDocker
Link 02 · Deps● shipped

Distroless base images

Fortune 10 healthcare company · 2022 – 2024
Problem
Full OS base images ship shells and packages apps never use, and each one brings CVEs.
Fix
Built and maintained distroless base images as the standard base for every developer in the company.
Result
Smaller images, a smaller attack surface, and one place to patch.
DistrolessDocker
Link 05 · Deploy● shipped

Reusable CD to Argo CD

Fortune 10 healthcare company · 2024 – 2026
Problem
Every team built its own path to Kubernetes.
Fix
Helped build and maintain reusable GitHub Actions CD workflows that hand off to Argo CD clusters on GKE.
Result
Deploys flow through git and one reviewed path.
GitHub ActionsArgo CDGKE
Link 06 · Runtime● shipped

Service account rotation + IAP

Principal Financial Group · 2017 – 2020
Problem
Long-lived service account keys, and apps protected only by network location.
Fix
Built a pipeline that rotates service accounts automatically and put Identity-Aware Proxy in front of apps.
Result
Keys expire on a schedule, and access checks who you are, not where you are.
GCPIAPCircleCI
Link 04 · Artifact● personal

My home server

Personal · ongoing
Problem
Even a home server pulls new code from the internet every week.
Fix
k3s with Argo CD GitOps. Every image pinned by digest with a CI gate. Weekly Renovate and Trivy PRs. Cilium networking. Offsite backups.
Result
Nothing runs unless it is pinned, reviewed, and in git. Restore from offsite is tested.
k3sArgo CDRenovateTrivyCilium