Skip to content
Book Open access

A Stage-Aware Tool for Modelling and Verifying CI/CD Security Evidence

Oct 2026 · Proceedings of the ACM/IEEE 29th International Conference on Model Driven Engineering Languages and Systems · 0 citations · 14 references

Abstract

Continuous integration and continuous deployment pipelines produce security-relevant records across source, build, test, package, deployment, and runtime environments. However, these records remain fragmented across logs, scanner findings, policy decisions, identity events, artefact metadata, and runtime alerts, limiting their usefulness during investigation. We present DevSecLogs, a stage-aware tool for modelling and verifying CI/CD security evidence. DevSecLogs normalises heterogeneous pipeline records into structured evidence objects that connect an observation to its pipeline stage, originating artefact or activity, security requirement, deterministic reason code, priority level, and verification status. The tool combines semantic triage and anomaly-oriented analysis with evidence-checkable explanations rather than presenting uninterpreted model outputs. Selected evidence bundles are hashed for consistency checking; the browser demonstration uses local anchors, while external anchoring remains experimental. Through an analyst-facing interface, users inspect runs, cross-stage findings, supporting evidence, and verification results. The demonstration illustrates an end-to-end investigation involving a skipped test gate, premature artefact publication, and an artefact-integrity inconsistency. DevSecLogs operationalises a requirements-to-evidence model that complements existing CI/CD scanners, policy engines, signing systems, and monitoring platforms.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.