The real trick is owning someone's CI system via the code under test. And it's even more versatile because it works even for projects which keep their executor scripts checked in to source.
1) Check out and gain an understanding of the target's CI scripts
2) Create a pull request (or whatever) which makes some reasonable code change but also introduces a vulnerability into the build/test scripts themselves. For example, curl'ing a domain you control.
3) Kick off pre-commit runs of all the tests to see if your patch should be accepted.
4) Own all the devices testing your patch.