Context
Jenkins is a CI/CD solution and as such, it is critical that the open source plugins that constitute an integral part of it don’t expose the systems they are used on to any security risks and vulnerabilities.
It is in that context that we worked as an audit/code review team to track and report such flaws and problematic practices.
We worked in collaboration with Jenkins Security...