A Systematic Literature Review on Continuous Integration and Deployment (CI/CD) for Secure Cloud Computing

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Saleh, Sabbir M., Madhavji, Nazim, Steinbacher, John
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866910998125871104
author Saleh, Sabbir M.
Madhavji, Nazim
Steinbacher, John
author_facet Saleh, Sabbir M.
Madhavji, Nazim
Steinbacher, John
contents As cloud environments become widespread, cybersecurity has emerged as a top priority across areas such as networks, communication, data privacy, response times, and availability. Various sectors, including industries, healthcare, and government, have recently faced cyberattacks targeting their computing systems. Ensuring secure app deployment in cloud environments requires substantial effort. With the growing interest in cloud security, conducting a systematic literature review (SLR) is critical to identifying research gaps. Continuous Software Engineering, which includes continuous integration (CI), delivery (CDE), and deployment (CD), is essential for software development and deployment. In our SLR, we reviewed 66 papers, summarising tools, approaches, and challenges related to the security of CI/CD in the cloud. We addressed key aspects of cloud security and CI/CD and reported on tools such as Harbor, SonarQube, and GitHub Actions. Challenges such as image manipulation, unauthorised access, and weak authentication were highlighted. The review also uncovered research gaps in how tools and practices address these security issues in CI/CD pipelines, revealing a need for further study to improve cloud-based security solutions.
format Preprint
id arxiv_https___arxiv_org_abs_2506_08055
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A Systematic Literature Review on Continuous Integration and Deployment (CI/CD) for Secure Cloud Computing
Saleh, Sabbir M.
Madhavji, Nazim
Steinbacher, John
Software Engineering
Cryptography and Security
D.2.11
As cloud environments become widespread, cybersecurity has emerged as a top priority across areas such as networks, communication, data privacy, response times, and availability. Various sectors, including industries, healthcare, and government, have recently faced cyberattacks targeting their computing systems. Ensuring secure app deployment in cloud environments requires substantial effort. With the growing interest in cloud security, conducting a systematic literature review (SLR) is critical to identifying research gaps. Continuous Software Engineering, which includes continuous integration (CI), delivery (CDE), and deployment (CD), is essential for software development and deployment. In our SLR, we reviewed 66 papers, summarising tools, approaches, and challenges related to the security of CI/CD in the cloud. We addressed key aspects of cloud security and CI/CD and reported on tools such as Harbor, SonarQube, and GitHub Actions. Challenges such as image manipulation, unauthorised access, and weak authentication were highlighted. The review also uncovered research gaps in how tools and practices address these security issues in CI/CD pipelines, revealing a need for further study to improve cloud-based security solutions.
title A Systematic Literature Review on Continuous Integration and Deployment (CI/CD) for Secure Cloud Computing
topic Software Engineering
Cryptography and Security
D.2.11
url https://arxiv.org/abs/2506.08055