Shameless plug for something I've been working on: <a href="https://github.com/ovotech/gitoops/" rel="nofollow">https://github.com/ovotech/gitoops/</a><p>I wrote GitOops to map attack paths through GitHub and CI/CD systems, at scale.<p>As an ex-pentester, for most companies I got to work with, all you need to do is open a PR against the right repositories to take over sensitive production environments. I suspect for most companies, an attacker compromising a single employee/intern with GitHub/Lab access is enough to lead to a disaster scenario.