Investigate and manage CI/CD instance assets
Investigate CI/CD instance security posture, remediate issues, and manage asset data.
The CI/CD instance inventory supports quick agentic queries and detailed side-panel investigation.
Select a CI/CD instance row to open its side panel. The side panel provides a consolidated workspace for reviewing platform security posture.
Ask the AppSec agentic assistant
From the CI/CD Instances table, select the Agentic Assistant icon. Then select Application Security to query instance-specific insights.
You can also select Ask AI in the side panel.
Explore the CI/CD instance context
Use these side-panel tabs to review platform context and prioritize remediation:
Overview tab: Displays provider type, instance URL, platform version, and the severity breakdown of CI/CD configuration risks.
Pipelines tab: Lists pipelines hosted by the instance. Select a pipeline to open its asset side panel.
Compliance tab: Displays posture against applicable industry frameworks and security benchmarks.
Investigate and remediate issues
From the Overview tab, select an issue or case associated with the instance. You can also investigate risks by category.
CI/CD Configuration
Displays instance-level configuration risks detected by the CI/CD scanner. Each finding includes its rule, description, severity, OWASP CI/CD Top 10 mapping, and evidence.
Selecting an issue opens an issue side card over the inventory. Review evidence and remediation guidance without leaving the asset inventory.
Execute asset actions
After reviewing instance health, use the side-panel Actions menu:
Open in Provider: Opens the CI/CD platform console at the instance URL.
View asset data: Displays raw instance data in
JSONor tree view for integrations, XQL queries, or API operations.
Manage CI/CD instance assets
Asset actions
Right-click an inventory asset. From Actions, select an action:
Open in new tab: Opens the asset description tab for detailed analysis.
View asset data: Opens data from the latest scan in JSON or tree view.
Copy text to clipboard: Copies selected text.
Copy entire row: Copies the selected row data.
Show/hide rows: Filters the inventory using the selected attribute.
Open in Cortex Assistant/Open in Cortex Agentic Assistant: Opens the asset in the assistant.
Export asset data: Select the download icon, labelled Export to file.
View Dashboard: Opens the Application Security dashboard.
Limitations
CI/CD integration required
Assets require an active CI/CD integration. Removed integrations no longer provide updated scan data.
Provider support scope
Discovery supports Jenkins, GitHub Actions, GitLab CI, Azure Pipelines, and CircleCI.
No Code-to-Cloud lineage
Code-to-Cloud lineage is tracked at the CI/CD pipeline level.
Instance URL availability
The URL appears only when the integration provides it.
Version data availability
Version data appears only when the provider exposes it.
Policy restrictions
CI/CD Configuration Scan policies support only the Periodic Scan trigger.
Security posture scope
Health profiles aggregate CI/CD configuration risks only. Other findings remain on repositories and pipelines.
Last updated
Was this helpful?
