> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration.md).

# Pipeline Configuration

| Rule Name                                                                                                                                                | AppSec Rule ID    | Severity |
| -------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------- | -------- |
| [An archived GitHub action is used](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-343.md)                                              | APPSEC\_CICD\_343 | CRITICAL |
| [A GitHub workflow is using action with CRITICAL severity CVE](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-344.md)                   | APPSEC\_CICD\_344 | CRITICAL |
| [A pipeline is using rejected Supply Chain Tool](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-345.md)                                 | APPSEC\_CICD\_345 | CRITICAL |
| [A pipeline is using an unapproved Supply Chain Tool](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-346.md)                            | APPSEC\_CICD\_346 | LOW      |
| [Jenkins instance is using rejected plugin](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-347.md)                                      | APPSEC\_CICD\_347 | CRITICAL |
| [Jenkins instance is using an unapproved plugin](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-348.md)                                 | APPSEC\_CICD\_348 | LOW      |
| [A deprecated Jenkins plugin is used on a Jenkins Instance](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-349.md)                      | APPSEC\_CICD\_349 | CRITICAL |
| [A Jenkins plugin with CRITICAL severity CVE is installed on a Jenkins Instance](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-350.md) | APPSEC\_CICD\_350 | CRITICAL |
| [A pipeline is using a rejected tool within a Remote Script](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-351.md)                     | APPSEC\_CICD\_351 | CRITICAL |
| [A pipeline is using an unapproved tool within a Remote Script](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-352.md)                  | APPSEC\_CICD\_352 | LOW      |
| [A GitHub workflow is using action with HIGH severity CVE](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-355.md)                       | APPSEC\_CICD\_355 | HIGH     |
| [A Jenkins plugin with HIGH severity CVE is installed on a Jenkins Instance](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-356.md)     | APPSEC\_CICD\_356 | HIGH     |
| [Unverified MCP Server Vendor is detected in an SCM Repository](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-357.md)                  | APPSEC\_CICD\_357 | MEDIUM   |
| [Non-Containerized MCP Server is detected in an SCM Repository](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-358.md)                  | APPSEC\_CICD\_358 | HIGH     |
| [Unmaintained MCP Server is detected in an SCM Repository](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-359.md)                       | APPSEC\_CICD\_359 | HIGH     |
| [Archived or Deprecated MCP Server in use, detected in SCM repository](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-360.md)           | APPSEC\_CICD\_360 | CRITICAL |
| [MCP Server with Dangerous Capability Request is detected in SCM Repository](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-361.md)     | APPSEC\_CICD\_361 | HIGH     |
| [A Rejected MCP Server is in-use (recognized in SCM Repository config file)](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-362.md)     | APPSEC\_CICD\_362 | CRITICAL |
| [An Unapproved MCP Server is in-use (recognized in SCM Repository config file)](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-363.md)  | APPSEC\_CICD\_363 | LOW      |
| [Unverified MCP Server Vendor is detected in a Pipeline](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-364.md)                         | APPSEC\_CICD\_364 | MEDIUM   |
| [Non-Containerized MCP Server is detected in a Pipeline](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-365.md)                         | APPSEC\_CICD\_365 | HIGH     |
| [Unmaintained MCP Server is detected in a Pipeline](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-366.md)                              | APPSEC\_CICD\_366 | HIGH     |
| [Archived or Deprecated MCP Server is detected in a Pipeline](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-367.md)                    | APPSEC\_CICD\_367 | CRITICAL |
| [MCP Server with Dangerous Capability Request is detected in a Pipeline](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-368.md)         | APPSEC\_CICD\_368 | HIGH     |
| [Rejected MCP Server in Use in the Pipeline](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-369.md)                                     | APPSEC\_CICD\_369 | CRITICAL |
| [Unapproved MCP Server in Use in the Pipeline](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-370.md)                                   | APPSEC\_CICD\_370 | LOW      |
| [Unverified MCP Server Vendor is detected in IDE](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-371.md)                                | APPSEC\_CICD\_371 | MEDIUM   |
| [Non-Containerized MCP Server is detected in IDE](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-372.md)                                | APPSEC\_CICD\_372 | HIGH     |
| [Unmaintained MCP Server is detected in IDE](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-373.md)                                     | APPSEC\_CICD\_373 | HIGH     |
| [Archived or Deprecated MCP Server in Use is detected in IDE](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-374.md)                    | APPSEC\_CICD\_374 | CRITICAL |
| [MCP Server with Dangerous Capability Request is detected in IDE](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-375.md)                | APPSEC\_CICD\_375 | HIGH     |
| [Contributor is using Rejected MCP Server in their IDE](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-376.md)                          | APPSEC\_CICD\_376 | CRITICAL |
| [Contributor is using an Unapproved MCP Server in their IDE](/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-377.md)                     | APPSEC\_CICD\_377 | LOW      |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
