Configuration smells in continuous delivery pipelines: a linter and a six-month study on GitLab
Carmine Vassallo, Sebastian Proksch, Anna Jancso, Harald C. Gall, Massimiliano Di Penta
Abstract
An effective and efficient application of Continuous Integration (CI) and Delivery (CD) requires software projects to follow certain principles and good practices. Configuring such a CI/CD pipeline is challenging and error-prone. Therefore, automated linters have been proposed to detect errors in the pipeline. While existing linters identify syntactic errors, detect security vulnerabilities or misuse of the features provided by build servers, they do not support developers that want to prevent common misconfigurations of a CD pipeline that potentially violate CD principles (“CD smells”). To this end, we propose CD-Linter, a semantic linter that can automatically identify four different smells in pipeline configuration files. We have evaluated our approach through a large-scale and long-term study that consists of (i) monitoring 145 issues (opened in as many open-source projects) over a period of 6 months, (ii) manually validating the detection precision and recall on a representative sample of issues, and (iii) assessing the magnitude of the observed smells on 5,312 open-source projects on GitLab. Our results show that CD smells are accepted and fixed by most of the developers and our linter achieves a precision of 87% and a recall of 94%. Those smells can be frequently observed in the wild, as 31% of projects with long configurations are affected by at least one smell.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 68000197-48fc-465e-b698-fded8e490a25Cited by top-tier papers7
- Resource Usage and Optimization Opportunities in Workflows of GitHub ActionsIslem Bouzenia, Michael PradelICSE 2024 · 15 citations
- BuildSonic: Detecting and Repairing Performance-Related Configuration Smells for Continuous Integration BuildsChen Zhang, Bihuan Chen, Junhao Hu, Xin Peng et al.ASE 2022 · 11 citations
- Characterizing the Security of Github CI WorkflowsIgibek Koishybayev, Aleksandr Nahapetyan, Raima Zachariah, Siddharth Muralee et al.USENIX Security 2022
- Continuous Intrusion: Characterizing the Security of Continuous Integration ServicesYacong Gu, Lingyun Ying, Huajun Chai, Chu Qiao et al.S&P 2023
- ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and ActionsSiddharth Muralee, Igibek Koishybayev, Aleksandr Nahapetyan, Greg Tystahl et al.USENIX Security 2023
Related papers
- Your Build Scripts Stink: The State of Code Smells in Build ScriptsMahzabin Tamanna, Yash Chandrani, Matthew Burrows, Brandon Wroblewski et al.ASE 2025 · 1 citation
- Empirical Study of the Docker Smells Impact on the Image SizeThomas DurieuxICSE 2024 · 11 citations
- GLITCH: Automated Polyglot Security Smell Detection in Infrastructure as CodeNuno Saavedra, João F. FerreiraASE 2022 · 27 citations
- What Happened in This Pipeline? Diffing Build Logs with CiDiffNicolas Hubner, Jean-Rémy Falleri, Raluca Uricaru, Thomas Degueule et al.ISSTA 2025
- On Prescription or Off Prescription? An Empirical Study of Community-Prescribed Security Configurations for KubernetesShazibul Islam Shamim, Hanyang Hu, Akond RahmanICSE 2025 · 4 citations
