DevSecLogs

Sign in to access the workable DevSecLogs prototype for CI/CD log analysis, stage-aware triage, deterministic reason labels, and evidence-ledger verification.

1
Analyse CI/CD logs from source, build, test, package, deploy, and runtime stages.
2
Use reason codes to explain why a finding was promoted into the triage queue.
3
Verify evidence digests without storing raw logs on-chain.
Static prototype note: accounts are stored only in this browser through localStorage. A production version should use a backend identity provider, for example Auth0, Firebase Auth, or IBM App ID.
Signed in as demo analyst.
≡DevSecLogs
⌕

Dashboard

Overview of CI/CD runs, stage-aware risk, alerts, and evidence verification.
Risk by Stage (last 7 days)
Recent Events
View all events
TimestampStageReason CodeSeverityVerification
Recent Runs
View all runs
Run IDPipelineStatusStart TimeHigh RiskAlerts
Evidence Ledger Status
View ledger
76%verified
Top Evidence Types

Analyse Log

Ingest CI/CD logs or run bundles to detect risks, policy violations, and security findings.
1. Ingest Log Snippet
Paste raw CI/CD log text below to analyse.
1
2
3
4
5
6
0 characters
Topic model endpoint retained. Current HTML runs local demo analysis unless backend fetch is wired.
Run Analysis processes the pasted or sampled log bundle and populates the cockpit, findings, heatmap, diagrams, snippets, digest, and history.
2. Ingest Run Bundle
Upload .log or .txt files from a CI/CD run.
⇧
Drag and drop files here
or
Accepted file types: .log, .txt  |  Max file size: 200 MB
ⓘ Stages are inferred from log content: source, build, test, package, deploy, runtime.
Run bundle ingest (evidence pipeline v1)
Select multiple log files from a single CI or CD run. DevSecLogs normalises them into a stage-aware event stream, derives reason codes, computes a risk score, and anchors a digest.
-
-
-
-
No bundle ingested yet. Filename hint: include a stage token such as source, build, test, package, deploy, or runtime. IBM CD tokens such as cosign, gatekeeper, COS evidence locker, helm, and change-request map to deploy or evidence stages.
Security cockpit
Visual summary of risk, pathway families, affected CI/CD stages, and investigation guidance.
ClearNo signal found for this pathway or stage.
WatchAn early or isolated signal was found.
WarningA meaningful pathway signal was found.
CriticalStrong, severe, or multi-stage evidence was found.
Current run risk
Click Run Analysis to calculate the triage score.
-
-
-
-
Load logs and click Run Analysis to see the investigation summary.
Practical pathway interpretation
Warning tiles, stage map, and grouped investigation guidance.
No deterministic pathway reason has been triggered yet. Load real IBM CI/CD logs and click Run Analysis to see grouped pathway cards.
Pathway family tiles
Grouped investigation directions, not confirmed named incidents.
CI/CD stage warning map
Shows where warning signals appear across source, build, test, package, deploy, and runtime.
Dominant pathway bow-tie
Connects likely causes, triggered deterministic reasons, and possible security consequences.
Pathway × Stage Heatmap
Shows where vulnerability-pathway signals concentrate across the CI/CD lifecycle.
Security diagrams
Visual security views generated from the current run evidence.
Data-flow view
source → build → test → package → deploy → runtime logs → normalised evidence → reason codes → risk score
Attack-pathway view
Dominant pathway: no pathway yet Triggered reason codes: no reason code yet
Evidence-chain view
raw logs → evidence lines → digest digest → ledger verify → PASS / FAIL
Evidence snippets
No analysis yet.
Why this run is suspicious
Deterministic reason labels will appear after analysis.
Digest (anchor candidate)
-
Reason contributions
Topic mix
Evidence coverage
Analysis history
Last 10 local analyses.
TimeRunStageSevScore
Risk by Stage (last 7 days)
Recent Events
View all events
TimestampStageReason CodeSeverityVerification
Recent Runs
View all runs
Run IDPipelineStatusStart TimeHigh RiskAlerts
Evidence Ledger Status
View ledger
76%verified
Top Evidence Types

Runs

Browse CI/CD runs and open evidence-linked analysis details.
Run IDPipelineStatusStart TimeStagesReasonsSeverityScoreEvidence
Selected Run
Select a run.

Alerts

Triage deterministic, stage-aware findings with evidence snippets.
TimestampPipelineStageReason CodeSeverity
Selected Alert
Select an alert.

Evidence Ledger

Raw logs remain off-chain. Compact cryptographic commitments are verified here.
Run Verification
ⓘ The demo verifies recomputed digests against local ledger commitments.
Evidence Types
76%verified
Ledger Chain

Help / Policy

Reason and score policy for interpreting DevSecLogs findings, pathway families, and evidence-ledger verification.

Reason & Score Policy

DevSecLogs detects vulnerability pathways, not named incidents. Observable CI/CD log evidence is mapped to deterministic reason codes, score contributions, and investigation-oriented risk ratings.

Thesis-safe claim: the system does not claim to detect Log4j, SolarWinds, or CodeCov directly. It identifies evidence patterns that resemble known CI/CD vulnerability pathways.
Low
0.00-0.24
Weak or isolated signal. Minor evidence is present, but no strong CI/CD vulnerability pathway is visible.
Medium
0.25-0.49
Relevant but incomplete pathway. Evidence suggests security-relevant behaviour, but supporting signals are limited.
High
0.50-0.74
Strong suspicious pathway. Multiple evidence lines or reason codes indicate a plausible pathway.
Critical
0.75-1.00
Strong multi-stage pathway. Evidence spans stages or affects identity, integrity, policy, exfiltration, or provenance.
How to use this policy
  • Analyse Log normalises log lines into a stage-aware event stream.
  • Reason codes identify evidence-checkable security pathways.
  • Risk score ranks investigation priority, not proof of compromise.
  • Evidence Ledger verifies digest commitments while raw logs remain off-chain.
  • Simulate Tamper demonstrates PASS/FAIL evidence verification.
Stage inference and provenance
Stage tokens: source: source, scm, git build: build, compile, maven, gradle, npm, pip test: test, pytest, junit, mocha, cypress package: package, artifact, tar, zip, helm deploy: deploy, release, prod, staging, cosign, gatekeeper, opa runtime: runtime, cluster, k8s, pod, container Provenance: Raw logs remain off-chain. A normalised event stream is hashed, and the ledger anchors a last-hash for PASS/FAIL verification.
Deterministic reason-code catalogue v1
Each code is evidence-checkable and supports retrospective CI/CD investigation.
Reason codeStageVulnerability pathwayExample pattern familyBase score
Vulnerability pathway families
Recognisable incidents are used as motivating examples only. A pathway family is not a confirmed exploit; it is an evidence-backed direction for investigation.
Pathway familyObservable CI/CD evidenceExample reason codesExample patternsThesis interpretation
Direct CI/CD pathways
  • hardcoded CI tokens
  • unsafe YAML changes
  • malicious GitHub Actions
  • dependency confusion
  • unsigned artefact promotion
  • registry tampering
  • log tampering
Broader motivating incidents
Examples such as Log4j, SolarWinds, Apache Struts/Equifax, DDoS, ransomware, SQL injection, XSS, and ReDoS are used as pathway motivation, not as direct named detections.
Score formula v1
final_score = min(1.0, sum(unique reason weights) + cross_stage_bonus + integrity_bonus) cross_stage_bonus = 0.10 if evidence appears across two or more CI/CD stages integrity_bonus = 0.10 if checksum, signature, or evidence-chain failure appears The score is a triage signal, not proof of compromise. It is designed to be explainable and calibratable.
UI wording rule
Avoid
DevSecLogs detects Log4j, SolarWinds, or CodeCov.
Use
DevSecLogs identifies evidence patterns that resemble known CI/CD vulnerability pathways.

Settings

Configure the prototype and reset local client-side data.
Model Configuration
Demo Notes
Topics support grouping and prioritisation. Reason codes drive alert promotion. Ledger commitments verify integrity. Raw logs are not stored on-chain.
Notifications
High-risk deploy finding
POL-003 Unsigned Artifact needs verification.
Evidence verified
run-20260523-1042 passed digest verification.
Runtime warning
SEC-045 Excessive Permissions remains unverified.
Help
Analyse Log
Paste logs or upload .log/.txt files, then click Ingest Snippet.
Verify Run
Checks whether the local evidence digest matches the ledger commitment.
Simulate Tamper
Changes a ledger hash so verification fails.
Account