top of page
  • Writer's pictureAbhimanyu Dhamija

Launching KoalaLab: X-ray for Modern CI/CD

Updated: Mar 3



Launching KoalaLab


Tech executives Abhishek Anand and Abhimanyu Dhamija announce the launch of their new devsecops venture KoalaLab.


KoalaLab is building the most comprehensive security and observability solution for the devops pipeline.


Anand has spent over a decade in building and securing performant scalable tech systems, and got inspired to delve deeper into security of the devops process. Anand partnered with Dhamija, who has built profitable tech businesses in regulated industries and was excited to go back to his roots of hard-technology development.



State of software supply chain security: special focus CI/CD

Even before the KoalaLab journey began, founders understood 3 important trends in the software development processes:

  • Rapid adoption of devops processes where companies rely on SaaS providers like Github/Gitlab for their SCM.

  • Modern build processes have become complicated and rely more and more on 3rd-party code like actions in Github CI, Orbs in Circle CI, plugins for jenkins.(There are 22000+ unique github actions listed on github marketplace)

  • Open-source code is now a big part of all Software development, with as much 85% of enterprise codebases coming from open-source libraries.


Add to this, high-profile attacks like solarwinds(2020), codecov(2021) and issue like log4j(2021) have raised awareness around software supply chain security.

Further, US government’s executive order on cybersecurity risk in 2021 & special focus on CI/CD security from NIST has led the industry to start finding solutions.

Since then, industry has made quite a few strides in terms of:

  1. Google published their SLSA framework for securing CI/CD which explores the idea of adoption of reproducible builds.

  2. OWASP published their CI/CD top 10 in aug-2022 covering threat vectors around CI/CD.

  3. NSA and CISA published a paper to recommendations around securing CI/CD.


KoalaLab Vision

The founders of KoalaLab believe that the industry has made considerable progress on securing the components part of software supply chain(proprietary code and open-source dependencies). On CI/CD security(processes part of software supply chain) the guidelines and frameworks from government bodies and open-source communities is a great step forward but adoption is scarce and lot more depth needs to be built.

Securing CI/CD is hard challenge given the complexity and rapidly evolving landscape. CI/CD pipelines are the keys to the cloud kingdom and KoalaLab wants to bring the same rigour accorded to securing network and production systems to these pipelines. Many of the same paradigms used in securing production systems can be applied to securing build pipelines like

  • Observability and performance intelligence

  • Security Posture Management

  • Securing systems through egress filtering

KoalaLab is excited to unveil two open-source projects PINNY: Hash-pining of OSS dependencies & BOLT: Securing Github workflows through transparent egress filtering. These are parts of the KoalaLab software supply chain control plane platform.

The founders are excited to build technology to solve problems around CI/CD security and wish to provide more solutions in the coming time.


KoalaLab Founders

The founders of KoalaLab: Abhishek Anand (left) & Abhimanyu Dhamija (right)



For media enquiries, please get in touch:

Abhimanyu Dhamija

bottom of page