Dashboard
Overview of CI/CD runs, stage-aware risk, alerts, and evidence verification.
Risk by Stage (last 7 days)
Recent Events
View all events| Timestamp | Stage | Reason Code | Severity | Verification |
|---|
Recent Runs
View all runs| Run ID | Pipeline | Status | Start Time | High Risk | Alerts |
|---|
Evidence Ledger Status
View ledger76%verified
Top Evidence Types
Analyse Log
Ingest CI/CD logs or run bundles to detect risks, policy violations, and security findings.
1. Ingest Log Snippet
Paste raw CI/CD log text below to analyse.
1
2
3
4
5
6
2
3
4
5
6
0 characters
Topic model endpoint retained. Current HTML runs local demo analysis unless backend fetch is wired.
Run Analysis processes the pasted or sampled log bundle and populates the cockpit, findings, heatmap, diagrams, snippets, digest, and history.
2. Ingest Run Bundle
Upload .log or .txt files from a CI/CD run.
Drag and drop files here
or
Accepted file types: .log, .txt | Max file size: 200 MB
ⓘ Stages are inferred from log content: source, build, test, package, deploy, runtime.
Run bundle ingest (evidence pipeline v1)
Select multiple log files from a single CI or CD run. DevSecLogs normalises them into a stage-aware event stream, derives reason codes, computes a risk score, and anchors a digest.
-
-
-
-
No bundle ingested yet. Filename hint: include a stage token such as source, build, test, package, deploy, or runtime. IBM CD tokens such as cosign, gatekeeper, COS evidence locker, helm, and change-request map to deploy or evidence stages.
Security cockpit
Visual summary of risk, pathway families, affected CI/CD stages, and investigation guidance.
ClearNo signal found for this pathway or stage.
WatchAn early or isolated signal was found.
WarningA meaningful pathway signal was found.
CriticalStrong, severe, or multi-stage evidence was found.
Current run risk
Click Run Analysis to calculate the triage score.
-
-
-
-
Load logs and click Run Analysis to see the investigation summary.
Practical pathway interpretation
Warning tiles, stage map, and grouped investigation guidance.
No deterministic pathway reason has been triggered yet. Load real IBM CI/CD logs and click Run Analysis to see grouped pathway cards.
Pathway family tiles
Grouped investigation directions, not confirmed named incidents.
CI/CD stage warning map
Shows where warning signals appear across source, build, test, package, deploy, and runtime.
Dominant pathway bow-tie
Connects likely causes, triggered deterministic reasons, and possible security consequences.
Pathway × Stage Heatmap
Shows where vulnerability-pathway signals concentrate across the CI/CD lifecycle.
Security diagrams
Visual security views generated from the current run evidence.
Data-flow view
source → build → test → package → deploy → runtime
logs → normalised evidence → reason codes → risk score
Attack-pathway view
Dominant pathway: no pathway yet
Triggered reason codes: no reason code yet
Evidence-chain view
raw logs → evidence lines → digest
digest → ledger verify → PASS / FAIL
Evidence snippets
No analysis yet.
Why this run is suspicious
Deterministic reason labels will appear after analysis.
Digest (anchor candidate)
-
Reason contributions
Topic mix
Evidence coverage
Analysis history
Last 10 local analyses.
| Time | Run | Stage | Sev | Score |
|---|
Risk by Stage (last 7 days)
Recent Runs
View all runs| Run ID | Pipeline | Status | Start Time | High Risk | Alerts |
|---|
Evidence Ledger Status
View ledger76%verified
Top Evidence Types
Runs
Browse CI/CD runs and open evidence-linked analysis details.
| Run ID | Pipeline | Status | Start Time | Stages | Reasons | Severity | Score | Evidence |
|---|
Selected Run
Select a run.
Alerts
Triage deterministic, stage-aware findings with evidence snippets.
| Timestamp | Pipeline | Stage | Reason Code | Severity |
|---|
Selected Alert
Select an alert.
Evidence Ledger
Raw logs remain off-chain. Compact cryptographic commitments are verified here.
Run Verification
ⓘ The demo verifies recomputed digests against local ledger commitments.
Evidence Types
76%verified
Ledger Chain
Help / Policy
Reason and score policy for interpreting DevSecLogs findings, pathway families, and evidence-ledger verification.
Reason & Score Policy
DevSecLogs detects vulnerability pathways, not named incidents. Observable CI/CD log evidence is mapped to deterministic reason codes, score contributions, and investigation-oriented risk ratings.
Thesis-safe claim: the system does not claim to detect Log4j, SolarWinds, or CodeCov directly. It identifies evidence patterns that resemble known CI/CD vulnerability pathways.
Low
0.00-0.24
Weak or isolated signal. Minor evidence is present, but no strong CI/CD vulnerability pathway is visible.Medium
0.25-0.49
Relevant but incomplete pathway. Evidence suggests security-relevant behaviour, but supporting signals are limited.High
0.50-0.74
Strong suspicious pathway. Multiple evidence lines or reason codes indicate a plausible pathway.Critical
0.75-1.00
Strong multi-stage pathway. Evidence spans stages or affects identity, integrity, policy, exfiltration, or provenance.How to use this policy
- Analyse Log normalises log lines into a stage-aware event stream.
- Reason codes identify evidence-checkable security pathways.
- Risk score ranks investigation priority, not proof of compromise.
- Evidence Ledger verifies digest commitments while raw logs remain off-chain.
- Simulate Tamper demonstrates PASS/FAIL evidence verification.
Stage inference and provenance
Stage tokens:
source: source, scm, git
build: build, compile, maven, gradle, npm, pip
test: test, pytest, junit, mocha, cypress
package: package, artifact, tar, zip, helm
deploy: deploy, release, prod, staging, cosign, gatekeeper, opa
runtime: runtime, cluster, k8s, pod, container
Provenance:
Raw logs remain off-chain. A normalised event stream is hashed, and the ledger anchors a last-hash for PASS/FAIL verification.
Deterministic reason-code catalogue v1
Each code is evidence-checkable and supports retrospective CI/CD investigation.
| Reason code | Stage | Vulnerability pathway | Example pattern family | Base score |
|---|
Vulnerability pathway families
Recognisable incidents are used as motivating examples only. A pathway family is not a confirmed exploit; it is an evidence-backed direction for investigation.
| Pathway family | Observable CI/CD evidence | Example reason codes | Example patterns | Thesis interpretation |
|---|
Direct CI/CD pathways
- hardcoded CI tokens
- unsafe YAML changes
- malicious GitHub Actions
- dependency confusion
- unsigned artefact promotion
- registry tampering
- log tampering
Broader motivating incidents
Examples such as Log4j, SolarWinds, Apache Struts/Equifax, DDoS, ransomware, SQL injection, XSS, and ReDoS are used as pathway motivation, not as direct named detections.
Score formula v1
final_score = min(1.0, sum(unique reason weights) + cross_stage_bonus + integrity_bonus)
cross_stage_bonus = 0.10 if evidence appears across two or more CI/CD stages
integrity_bonus = 0.10 if checksum, signature, or evidence-chain failure appears
The score is a triage signal, not proof of compromise. It is designed to be explainable and calibratable.
UI wording rule
Avoid
DevSecLogs detects Log4j, SolarWinds, or CodeCov.
Use
DevSecLogs identifies evidence patterns that resemble known CI/CD vulnerability pathways.
Settings
Configure the prototype and reset local client-side data.
Model Configuration
Demo Notes
Topics support grouping and prioritisation.
Reason codes drive alert promotion.
Ledger commitments verify integrity.
Raw logs are not stored on-chain.