Securing the Software Supply Chain in CI/CD Pipelines Using DevSecOps Controls

Nagoor Basha Shaik's: Research blog identifying the DevSecOps practice to strengthen software supply chain with the integration of automated security control in GitLab CI/CD pipelines with the use of open source technology

Introduction

Software development in the current timesis having dependency on CI/CD pipelines, cloud platforms, and open-sourcesoftware in order to create and provide applications which are easy to use andit also helps to make the process quicker. Although these technologies help toenhance development speed, but their use results in creating security relatedRisks into software supply chain. The main focus of this research is to analyzehow DevSecOps practices can help in the process of enhancing software securityby the addition of automated security controls to GitLab CC/ID pipeline (Patel2025). The complete analysis is focused on making use of open-source tools sothat it can able to reduce security risks which generally takes place withinthe complete process of software development.

Research Aim

The aim of this research is to analyze how DevSecOps of security controls can help in the process of enhancing software supply chain security in GitLab CI/CD pipelines. In this process the analysis is going to focus on creating and testing a secure pipeline by making use of open-source security tools. It is also going to analyze if these tools are capable of identifying security weaknesses or not. Then it is also going to check if they are capable of providing support for secure software delivery and making improvement within software integrity while keeping the complete software development process efficient.

Research Questions

The research questions given above helps in identifying the effectiveness of the proposed framework and implement a secured DevSecOps control. Different measurable performance indicators are used for evaluating the findings such as effectiveness of policy enforcement, false-positive rates, time of pipeline execution and vulnerability detection rate.


Research Methodology

This research is going to use the Design Science Research (DSR) method because it is focused to creating and testing a practical solution which will help to make improvement within software supply chain security (Solanke 2022). The complete research is going to make use of suitable measures which will help it identify the issues, designing a secure GitLab CI/CD pipeline, implementing DevSecOps security controls, and it is also going to help for checking the outcomes. Where it is also going to make use of open-source security tools which will be added to into pipeline so that it can able to find vulnerabilities and help in the process of enhancing software security. Dissolution which is being proposed will be assist bye its performance in terms of vulnerability detection, policy enforcement, Software integrity, and pipeline execution timeline.

Project Evaluation Plan

The DevSecOps which is being proposed will be checked by making use of a structured checking framework that is going to be helpful to check both security improvements and operational performance (Dhandapani 2025). The complete analysis focused on finding if the integrated security control can be able to effectively identify vulnerabilities, its performance in terms of preventing insecure deployments, and its capability to maintain an acceptable execution time for the CI/CD pipelines. In this process it should not be able to affect the complete software development process.

Research Tools & Techniques

The focus of this analysis is to combine multiple free and open-source security tools inside GitLab's automation pipeline with the motive to make software a lot safer and to build and deliver accordingly. Each of the tools handles a different part of building software, which helps in identifying any security-related issues and checking rules, as well as reviewing the outside code and keeping an eye out for any new type of race or challenge that may appear. All these tools are commonly used in the industry, and therefore they are capable of offering an affordable way to build software securely.
GitLab CI/CD: GitLab manages the code and tracks the entire changes as well as automatically runs and test and security checks, giving developers complete feedback (Chandramouli et al. 2024).
Gitleaks: Scans code for accidentally exposed passwords, keys, or login details, stopping them from leaking before the final release.
Grype: Checks the software building blocks which are known as dependencies against the known vulnerability list with the motive to spot any outdated or risky components (Singh 2025).
Trivy: Scans containers and system fields as well as app components for known security flaws before the software goes live completely.
Syft: Creates a full list of all the software parts used such as an ingredient list which helps in improving the overall transparency and any future risk tracking type of activities.
OPA/Conftest: Automatically checks that configurations follow security rules before the final deployment (Solanke 2022).
OWASP Dependency-Track: Keeps monitoring the software components after the final release and alerts teams to newly identified vulnerabilities.

Project Monitoring

Progress is actually tracked through different type of key milestones which include research, building, testing and writing with weekly reviews and Gitlabs version history recording all changes respectively. Risks like technical issues or slow pipelines are blocked and managed on a continuous basis.

Ethical, Legal & Professional Considerations

In order to be ethically correct, no real users or personal type of information were involved in the process and testing uses completely safe and isolated practice system. Open-source licenses are respected, and UK GDPR and Professional conduct standards are thoroughly followed.

Expected Outcomes

It is expected that the research would increase the security of Gitlab CI/CD pipeline and help in improving the software supply chain with the use of open source DevSecOps technology. The project is also expected to demonstrate the effectiveness of continuous vulnerability monitoring, software bill of materials, policy enforcement and security scanning for strengthening software deliveries.

Conclusion

From the above blog it can be concluded that software supply chain is one of the main challenges faced in today’s software development process. The organizations are using automated process for the adoption of CI/CD pipelines and open-source software and thus integration of security throughout the development process is not a option for them. With the implementation of opensource DevSecOps pipeline the blog discusses about the software supply chain that can be protected without hampering the development efficiency. The findings of the research would help the software engineers and researchers to become a guide supporting how it can help in adopting secured software development method.

References

Chandramouli, R., Chandramouli, R., Kautz, F. and Torres-Arias, S., 2024. Strategies for the integration of software supply chain security in DevSecOps CI/CD pipelines. US Department of Commerce, National Institute of Standards and Technology. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-204D.pdf?ref=tidalseries.com
Dhandapani, S., 2025. Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines. arXiv preprint arXiv:2506.06478. https://arxiv.org/pdf/2506.06478
Patel, D., 2025. Software Supply Chain Security: Implementing SLSA Compliance in CI/CD Pipelines. International Journal for Research Trends and Innovation10(7). https://www.researchgate.net/profile/Devashish-Patel-5/publication/393457635_Software_Supply_Chain_Security_Implementing_SLSA_Compliance_in_CICD_Pipelines/links/68e46634f3032e2b4be7098f/Software-Supply-Chain-Security-Implementing-SLSA-Compliance-in-CI-CD-Pipelines.pdf
Singh, B., 2025. Automating Security Testing in CI/CD Pipelines using DevSecOps Tools a Comprehensive Study. CD Pipelines using DevSecOps Tools a Comprehensive Study (May23, p.2025. https://www.academia.edu/download/122922388/Title_9_dec_2020.pdf
Solanke, A.A., 2022. Enterprise DevSecOps: Integrating security into CI/CD pipelines for regulated industries. World Journal of Advanced Research and Reviews13, pp.633-648. https://www.researchgate.net/profile/Adedamola-Solanke/publication/390541413_Enterprise_DevSecOps_Integrating_security_into_CICD_pipelines_for_regulated_industries/links/67f2dc1349e91c0feae4c67b/Enterprise-DevSecOps-Integrating-security-into-CI-CD-pipelines-for-regulated-industries.pdf

Scroll to Top