devops-gitlab-ci
Warn
Audited by Socket on Aug 4, 2026
1 alert found:
SecuritySecurityreferences/gitlab-runners.md
MEDIUMSecurityMEDIUM
references/gitlab-runners.md
No explicit malicious code is present in this configuration fragment; however, it contains severe plaintext credentials (GitLab runner registration token and multiple cloud cache authentication secrets, including a private key). This is a critical supply-chain operational risk because leaked values can enable unauthorized access to runner registration and external cache backends, potentially facilitating runner impersonation, cache poisoning, and downstream CI/CD compromise. All exposed secrets should be treated as compromised and rotated immediately, and secrets should be removed from source-controlled configuration and stored in a dedicated secret manager with strict access controls.
Confidence: 78%Severity: 91%
Audit Metadata