4 Matching Annotations
- Oct 2020
docs.gitlab.com docs.gitlab.com
Malicious code pushed to your .gitlab-ci.yml file could compromise your variables and send them to a third party server regardless of the masked setting. If the pipeline runs on a protected branch or protected tag, it could also compromise protected variables.
Here is a simplified example of a malicious .gitlab-ci.yml
- Jun 2020
- May 2020
docs.gitlab.com docs.gitlab.com
In this example