International Journal of Multidisciplinary Research and Growth Evaluation  |  ISSN (Online): 2582-7138  |  Double-Blind Peer Review  |  Open Access  |  CC BY 4.0

Current Issues
     2026:7/3

International Journal of Multidisciplinary Research and Growth Evaluation

ISSN (Online): 2582-7138 | Open Access

Secure-by-Default CI/CD: Integrating Image Hardening and Build-Breaker Logic to Mandate Strict Security Headers (CSP/XFO/HSTS)

Full Text (PDF)

Open Access - Free to Download

Download Full Article (PDF)

Alternative download link

Abstract

As cyber threats evolve toward supply chain attacks, the “Shift Left” philoso-phy must transition from a recommendation to an enforced mechanical constraint. This paper presents a framework for a Secure-by-Default CI/CD pipeline utiliz-ing custom Golang-based admission controllers and Build-Breaker logic. I detail the automated integration of image hardening via distroless migrations and the mandatory enforcement of strict security headers—specifically Content Security Policy (CSP), X-Frame-Options (XFO), and HTTP Strict Transport Se-curity (HSTS). Through a high-fidelity simulation environment, I demonstrate that mechanical enforcement via build-breakers achieves 100% policy compliance while introducing manageable latency to the developer workflow.

How to Cite This Article

Anupam Ojha (2024). Secure-by-Default CI/CD: Integrating Image Hardening and Build-Breaker Logic to Mandate Strict Security Headers (CSP/XFO/HSTS) . International Journal of Multidisciplinary Research and Growth Evaluation (IJMRGE), 5(6), 1913-1915. DOI: https://doi.org/10.54660/.IJMRGE.2024.5.6.1913-1915

Export Citation:

BibTeX RIS EndNote

Share This Article: