InvisiRisk Blog Posts
This blog features practical analysis from the InvisiRisk team on the issues shaping Build and CI/CD security. These articles go beyond timely vulnerability alerts to explain broader trends, attack techniques, architectural decisions, and security practices that matter inside the build environment, including dependency behavior, secrets protection, artifact integrity, pipeline hardening, and software supply chain risk at the last mile.
This page is designed for DevOps, DevSecOps, AppSec teams, and security leaders who want clear, practical guidance on how build-time threats are evolving and how to strengthen their CI/CD defenses.

Dependency Confusion Attacks: How They Work and How to Stop Them at Build Time
Your software build imports external packages based on the name of the package. When your package manager sees a dependency

Malicious Post-Install Scripts: npm and PyPI Attacks Explained
Installing a package isn’t a passive download. Both npm and PyPI can run code on your machine the moment a

What are Secrets Leaks in CI/CD Pipelines?
Almost every modern application is assembled by an automated pipeline, and that pipeline can’t do its job without credentials. The

Slopsquatting: How AI-Hallucinated Packages Threaten the Software Supply Chain
Slopsquatting is a software supply chain attack where criminals register malicious packages under the fake names that AI coding assistants

InvisRisk Expands Build Application Firewall with Real-Time CI/CD Enforcement Across AWS and GitLab
New release extends runtime policy enforcement, stopping software supply chain threats during build execution before release. Houston, TX – June

The Executive Guide to SBOM Security
By David Pulaski, CXO & Co-Founder, InvisiRiskPublished June 2026 TL;DR A Software Bill of Materials (SBOM) is a complete inventory

Healthcare Software Supply Chain Security Explained
By David Pulaski, CXO & Co-Founder, InvisiRiskPublished June 2026 TL;DR Healthcare software is assembled from open-source packages, third-party code, and

Open Source Vulnerability Management at Build Time
Open source vulnerability management at build time means inspecting and enforcing policy on every open source package the moment it

The Complete Application Security Stack Guide For 2026
A modern application security stack rests on four foundational categories (code security or SAST, dependency security or SCA, runtime security

What Is a Build Application Firewall?
TL;DR A Build Application Firewall (BAF) does for CI/CD pipelines what a WAF does for web applications: it sits inline,

What Is Build-Time Security for CI/CD Pipelines?
TL;DR A CI/CD pipeline is privileged, networked, and often executes third-party packages, scripts, actions, containers, or build tools as software

Build-Time Security: The Missing Layer in Application Security
TL;DR AppSec tools cover code (SAST), dependencies (SCA), and deployed applications (DAST), but most do not monitor and enforce policy
Stay in the loop
Be the first to know about our latest product updates and company news.
No spam. Just the good stuff! We also respect your privacy and keep your info safe.