45
11
2
The table below lists code repositories and CI/CD platforms along with the NHIs they use.
The name of the code repository or CI/CD tool.
The type of platform, such as CI/CD or version control.
The type of NHI associated with the service. This includes API Tokens, Personal Access Tokens (PATs) and Access Keys used by automated processes. It is recommended to adopt federated roles and ephemeral credentials to reduce risks tied to static, long-lived credentials. Please refer to the Resources section to see where there’s an opportunity to transition to ephemeral-based credentials as part of using version control systems or CI/CD tools.
Key security features offered by the tool:
IP Denylist: Indicates if the service/app supports an IP deny list
IP Allowlist: Indicates if the service/app supports an IP allow list.
Set Expiry: Indicates if the service/app allows setting an expiry date for NHIs.