Capability areas
Pipeline-as-code authoring and reuse (13)
Covers pipeline definitions kept in the repository, multi-stage and DAG structure, conditional and manual jobs, matrix builds, triggers (push, schedule, API, upstream pipeline), monorepo path filtering, cross-repository triggers, versioned shared templates, service scaffolding from approved templates, and how pipeline syntax changes are versioned and deprecated. Centrally enforced required steps are covered under governance.
Runners, execution and build performance (13)
Covers vendor-hosted, self-hosted and hybrid runners, operating system and CPU architecture coverage, autoscaling, job isolation and teardown, outbound-only runner connectivity, access to private networks, queue behavior at peak concurrency, dependency and build caching, retry rules, and running builds during a hosted-service outage. Hosting regions and tenancy of the platform itself belong to the deployment-hosting module.
Source control and code review integration (9)
Covers built-in Git hosting where offered or integration with external Git platforms, commit and merge request status reporting, branch protection with required checks, code owners, signed-commit verification, merge queues, large-file storage, mirroring and read replicas, and repository import with history and review data. Generic identity integration is out of scope.
Test automation and quality gates (9)
Covers test result reporting per test, failure display on the merge request, code coverage and coverage change, static analysis findings on the merge request, quality gates that block merges, and temporary review environments per merge request. Security scanning is covered in its own area.
Pipeline credentials and secrets (11)
Covers OpenID Connect federation to cloud providers in place of stored keys, the claims available for cloud trust policies, encrypted secret storage and configuration variables scoped by project, environment and branch, run-time retrieval from external secrets managers, log masking, buyer-managed encryption keys for secrets, the default scope of the pipeline job token, policy limits on personal access token and deploy-key scope and lifetime, and how pipelines triggered from forks or untrusted contributors are kept away from secrets. The vendor's own corporate security program belongs to the security module.
Security scanning in the pipeline (9)
Covers push-time secret detection and blocking, dependency and container image vulnerability scanning, license reporting against a deny list, dynamic testing of review environments, display of new findings on the merge request, finding triage, scanner database update frequency and sources, and scanners that run inside the buyer's network without internet access. Signing and provenance are covered under artifacts.
Artifacts, registries and build provenance (11)
Covers container image builds, built-in or connected container and package registries, retention rules that protect release artifacts, promotion of one built artifact across environments, SBOM generation per build, artifact and image signing, build provenance attestations, and verification of signatures and attestations before deployment. The vendor's own software supply chain belongs to the third-party module.
Deployment and release orchestration (14)
Covers deployment to the buyer's targets (Kubernetes, virtual machines, serverless), GitOps controller integration, approved single-action and automatic production releases, environment approvals, freeze windows, progressive rollouts, rollback, multi-service release ordering, feature flags, infrastructure-as-code plan and apply in pipelines, release records, per-environment deployment history, and behavior when the service fails mid-deployment.
Governance, policy and audit evidence (12)
Covers policy as code across projects, central required pipeline steps teams cannot remove, role-based access down to the environment level, separation of duties for merge and deployment, immutable audit logs with retention and SIEM streaming, retention of production deployment records for archived projects, timestamp integrity, change-record integration with IT service management tools, and release evidence export. Third-party certifications belong to the compliance module.
Pipeline observability, metrics and notifications (10)
Covers cross-project pipeline and deployment dashboards, delivery metrics (deployment frequency, lead time for changes, change failure rate, failed deployment recovery time), pipeline duration, queue time, failure and flakiness trends, job log search and retention, compute minutes and storage metering with caps, notifications, chat-based actions, monitoring-tool event links, and alert-triggered pipelines. Pricing terms belong to the commercial module.
Migration and pipeline conversion (9)
Covers conversion of pipeline definitions from the buyer's current CI tool, reporting of what could not be converted, running old and new pipelines in parallel by cohort, migration of runners, secrets and variables, and the written migration plan with duration and exclusions. Data export on exit belongs to the migration-exit module.
Ecosystem and extension security (8)
Covers the marketplace or plugin model for pipeline steps, pinning third-party steps to a fixed version or digest, administrator approval or blocking of third-party extensions, the permissions an extension receives, linking commits, merge requests and deployments to work items, shipped integrations with issue trackers and IDEs, webhooks for pipeline events, and the command-line tool for pipelines and deployments. The pipeline job token, personal access tokens and deploy keys belong to CRD; generic API coverage and rate limits belong to the integration module.