A Stage-Aware Tool for Modelling and Verifying CI/CD Security Evidence
Abstract
Continuous integration and continuous deployment pipelines produce security-relevant records across source, build, test, package, deployment, and runtime environments. However, these records remain fragmented across logs, scanner findings, policy decisions, identity events, artefact metadata, and runtime alerts, limiting their usefulness during investigation. We present DevSecLogs, a stage-aware tool for modelling and verifying CI/CD security evidence. DevSecLogs normalises heterogeneous pipeline records into structured evidence objects that connect an observation to its pipeline stage, originating artefact or activity, security requirement, deterministic reason code, priority level, and verification status. The tool combines semantic triage and anomaly-oriented analysis with evidence-checkable explanations rather than presenting uninterpreted model outputs. Selected evidence bundles are hashed for consistency checking; the browser demonstration uses local anchors, while external anchoring remains experimental. Through an analyst-facing interface, users inspect runs, cross-stage findings, supporting evidence, and verification results. The demonstration illustrates an end-to-end investigation involving a skipped test gate, premature artefact publication, and an artefact-integrity inconsistency. DevSecLogs operationalises a requirements-to-evidence model that complements existing CI/CD scanners, policy engines, signing systems, and monitoring platforms.