CNCF contributor Matteo Bisi threat-models unapproved AI tools and agents in cloud-native delivery paths, mapping risks around source code, secrets, CI/CD credentials, Kubernetes access, and governance to controls available through CNCF and other open-source projects.
Shadow AI in CI/CD: Threat-modeling the path from developer laptop to Kubernetes
CNCF contributor Matteo Bisi threat-models unapproved AI tools and agents in cloud-native delivery paths, mapping risks around source code, secrets, CI/CD credentials, Kubernetes access, and governance to controls available through CNCF and other open-source projects.
Source: CNCF