TeamCityはKotlin DSLによるConfiguration as Codeを提供し、プロジェクト設定・CI/CDパイプラインをプログラム的に定義できる。ビルドチェーン機能では、複数のビルド構成を段階(フェーズ)として連結し、成果物のビルド・並列テスト・デプロイまでを一連の依存関係として管理できる。検証待ちKotlin DSLとビルドチェーン機能
JetBrains s.r.o.公式のofficial security advisory/bulletin blog post(https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/)は、TeamCityのセキュリティ体制に関する公的記録である。既存Referenceは機能・比較・価格を扱うが、セキュリティ脆弱性とその対応という運用上重要な情報は未収録であり、新規性がある。具体的には「A critical security vulnerability has been identified in TeamCity On-Premises. If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. ... All versions of TeamCity On-Premises are affected. ... Since our initial announcement on July 27, 2026, we have received reports of active exploitation, as well as attempted exploitation, targeting unpatched TeamCity servers. ... We strongly recommend that all users update their servers to one of the above versions [2025.11.7 or 2026.1.3].」といった記載がある。ただし、認証・準拠・体制の状況は更新されうるため、この内容は取得時点のものです。適用範囲がどこまでかは、このSourceだけでは確認できない場合があります。 これはJetBrains自身が公表する2026年7月27日付・8月7日更新の告知であり、独立した第三者機関による検証ではない。この脆弱性は取得時点(2026年8月23日)でも比較的新しく、今後さらに状況(悪用範囲・パッチ適用率等)が更新される可能性が高い。CVSSスコアはこの記事内には明記されていない。2026年08月24日に同Sourceを取得し、この内容を確認した。検証待ちTeamCityセキュリティ体制に関する公開情報