M ManySignal

Integration Category

Code & CI/CD Integrations

GitHub, GitLab, CircleCI, Jenkins, Terraform Cloud — ManySignal monitors your software supply chain for compromised tokens, malicious commits, CI/CD pipeline abuse, and secrets exposure.

Supply chain threats ManySignal detects

Stolen GitHub / GitLab personal access tokens
Compromised CI/CD service account credentials
Secrets committed to repositories
Malicious GitHub Actions version changes
CI/CD pipeline abuse for secrets exfiltration
Unauthorised infrastructure changes via Terraform
Branch protection bypass on protected branches
Developer account takeover via phishing

Code and CI/CD integration FAQs

Why should security teams monitor code and CI/CD pipelines?

Software supply chain attacks are among the fastest-growing threat vectors. Compromised CI/CD pipelines, stolen GitHub tokens, malicious code commits, and secret exposure in repositories can give attackers persistent access to production environments. Code and CI/CD monitoring bridges the gap between development and security operations.

What GitHub events does ManySignal collect?

ManySignal ingests GitHub organisation audit log events: user additions/removals, repository access changes, branch protection changes, personal access token creation, OAuth application grants, Actions workflow runs, and secret scanning alerts.

Can ManySignal detect secrets committed to GitHub?

Yes. GitHub Secret Scanning alerts are ingested by ManySignal and correlated with subsequent anomalous API usage using matching credential formats — linking the exposure event to potential exploitation.

Does ManySignal monitor GitHub Actions for supply chain risks?

Yes. GitHub Actions workflow run events, including the specific action versions used, are ingested. ManySignal detects sudden action version changes, use of unverified third-party actions, and workflow runs that make unexpected outbound connections.

How does ManySignal monitor Terraform Cloud infrastructure changes?

ManySignal ingests Terraform Cloud workspace run events (plan, apply, destroy) and correlates them with the downstream cloud provider API calls generated by those runs. This enables detection of out-of-band infrastructure changes that bypass the Terraform workflow.

Does ManySignal cover ArgoCD for GitOps deployments?

Yes. ArgoCD deployment events, sync status changes, and access control modifications are ingested. ManySignal detects unexpected deployment sources, manual sync overrides, and unauthorised ArgoCD admin access.

Can ManySignal detect when a developer's GitHub token is stolen?

Yes. ManySignal detects anomalous GitHub personal access token usage: access from a new country, unexpected API calls (accessing private repos not normally accessed), or token usage from an IP outside the developer's known range.

Does this cover GitHub Copilot security risks?

ManySignal ingests GitHub Copilot usage telemetry. Anomalous patterns — Copilot suggestions including sensitive internal data, bulk code submission that may represent data exfiltration — are flagged based on the ManySignal AI attack surface coverage.

How does Jenkins monitoring work without a cloud API?

Jenkins is self-hosted, so ManySignal uses a log agent deployed on the Jenkins controller host to forward audit trail and system logs. No inbound network access to Jenkins is required.

Can ManySignal detect when a CI/CD pipeline is abused to access production secrets?

Yes. Pipeline steps that access secrets and then make outbound connections to unexpected endpoints are detected as suspicious. ManySignal correlates the pipeline actor identity, the secrets accessed, and the network connections made during the build.

Add software supply chain visibility to your SOC

Connect GitHub, GitLab, or your CI/CD platform to ManySignal in minutes.